Reporting vulnerabilities correctly: How CRA, CVD, RFC 9116, and security.txt are interconnected – and how to implement key requirements in practice.
Do you already have a security.txt file?
Is there a file named “security.txt” on your web space? Have you looked into the Cyber Resilience Act (CRA) yet? If you answered “no” to both questions, now is a good time to look into both topics.
The CRA went into effect in December 2024. However, its provisions will be phased in gradually. For example, there is an important deadline on September 11. Starting on that date, the reporting requirements under Article 14 will apply.
This means that, starting September 11, 2026, manufacturers of products with digital elements must report certain vulnerabilities that have come to their attention and are being actively exploited, as well as serious security incidents, via ENISA’s CRA Single Reporting Platform.
Why is the security.txt file so important?
When users, security researchers, CERTs, or others discover a vulnerability, they need a clear way to contact the affected organization. The contact information is stored in the security.txt file, which must be located at https://domain.tld/.well-known/security.txt.
Interesting fact: According to the BSI, as of August 2026, only 1.8 percent of all German website operators currently use the security.txt file. That’s not enough! Especially in light of the upcoming CRA reporting requirements, it’s worth establishing effective processes for handling incoming vulnerability reports.
How do you implement a security.txt file?
Implementation is quite simple. For one thing, there is some information available online. For example, securitytxt.org provides an online tool for creating custom security.txt files.
In addition to the plain text file, it makes sense to set up a few landing pages on your website. These include, for example, a page for reporting vulnerabilities to your organization and one for the CVD policy (Coordinated Vulnerability Disclosure).
How we handle reporting requirements
As a developer and provider of hardening tools such as AuditTAP and Enforce Administrator, FB Pro GmbH is subject to the Cyber Resilience Act. Our process for handling vulnerabilities is a key component of this. We have implemented this part of the requirements in the following ways, among others:
➡ The security.txt file is available at https://www.fb-pro.com/.well-known/security.txt
➡ The vulnerability report can be found at https://www.fb-pro.com/security/report/
➡ Our CVD policy can be found at https://www.fb-pro.com/policy/
FYI: Currently, we offer the landing pages only in German. In the near future, we will also offer English versions.
Would you like to report a vulnerability to us?
If so, you have two options: Either submit a report directly through our online form—you’re welcome to do so anonymously—or send us an encrypted email.
Do you have other suggestions or requests? For example, are you looking for a solution to harden your IT infrastructure? Feel free to contact us with no obligation.
______
Note: The information provided in this blog post is for general informational purposes only and does not constitute legal or tax advice. If you need legal or tax advice, please contact a tax firm or law firm.
Images: Magnific AI, BSI

