Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

You can publish a basic security.txt file in minutes if your organization already has a monitored vulnerability-reporting contact and an approved policy. The file helps researchers find your disclosure process; it is not itself a Cyber Resilience Act (CRA) requirement or proof of compliance.

What security.txt does—and does not do

RFC 9116 defines security.txt as a machine-readable file intended to help security researchers disclose vulnerabilities. It provides a public route to your organization’s process; it does not receive, triage, investigate, or remediate reports on its own. The standard says the file is intended to help researchers disclose security vulnerabilities. Read RFC 9116.

That distinction matters for the CRA. Annex I, Part II requires manufacturers to have coordinated vulnerability disclosure policies and procedures. A security.txt file can direct researchers to that process, but the regulation does not expressly require the file itself. Publishing a pointer does not establish that the underlying policy, staffing, or procedures satisfy the Act. Consult the CRA text.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Publish a basic file

This is a quick publishing task only if you have already chosen an accountable owner, a working reporting channel, and an approved disclosure policy. Do not invent contact details, scope, dates, or response promises to fill out a file.

#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
  1. Set the host and scope. Decide which exact hostname the file covers. Under RFC 9116, the file applies to the host from which it is retrieved; a file on a main domain does not automatically cover its subdomains. Create a file for each separately covered host.
  2. Choose a monitored contact. Use a vulnerability-reporting email address, phone number, or web page that someone responsible checks and can act on. The RFC’s required Contact field identifies the method researchers should use to report vulnerabilities.
  3. Link the disclosure policy. Add a Policy field pointing to a clear policy that explains scope and how reports are handled. RFC 9116 recommends using this directive to provide more detail about the disclosure process.
  4. Set an expiry and renewal owner. An unsigned file must contain exactly one Expires field under the RFC’s grammar. Use a real expiration timestamp and assign someone to renew it before it lapses.
  5. Publish at the standard path. Serve the file over HTTPS at https://your-domain.example/.well-known/security.txt as UTF-8 encoded text/plain. The legacy top-level path may redirect, but the well-known path is the standard location; if both exist, use the well-known path.
  6. Verify the live endpoint. Retrieve the published URL and check that it responds as intended, serves plain text with UTF-8 encoding, has the correct host-specific content, and contains valid field values, an unexpired date, and working destinations. This is a practical verification step, not a substitute for operating the process behind the contact.

A file’s actual contents depend on your organization. RFC 9116 and the IANA Security.txt Fields registry describe additional optional fields, including Canonical, Encryption, Preferred-Languages, and Acknowledgments. Include only fields whose values are accurate and useful.

What the CRA requires beyond a contact pointer

The CRA’s coordinated vulnerability disclosure requirement concerns an operating policy and procedure, not just discoverability. Manufacturers need defined ownership for receiving and handling reports, assessing vulnerabilities, coordinating disclosure, and pursuing remediation. The file can help a researcher find the right route, but it does not create those capabilities.

Rank #2
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

The Act’s Article 14 reporting duties are a separate track. They concern manufacturers’ notifications of actively exploited vulnerabilities and severe incidents affecting product security, through the single reporting platform. Notifications go to the CSIRT designated as coordinator for the Member State where the manufacturer has its main establishment in the EU, and are simultaneously accessible to ENISA. A public security.txt contact does not replace that platform or the manufacturer’s statutory reporting responsibilities. See Article 14 of the CRA.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Actively exploited vulnerabilities

For an actively exploited vulnerability, the manufacturer must submit an early warning without undue delay and within 24 hours of becoming aware of it. A vulnerability notification is due within 72 hours, followed by a final report within 14 days after the vulnerability notification.

Rank #3
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Severe incidents

For a severe incident affecting product security, the early warning is due within 24 hours, the incident notification within 72 hours, and the final report within one month after the incident notification. These are distinct reporting tracks, not one generic CRA deadline.

After becoming aware of an actively exploited vulnerability or severe incident, manufacturers must also inform impacted users and, where appropriate, all users, including relevant mitigation or corrective measures. The Act provides for coordinating-CSIRT helpdesk support for Article 14 reporting, with particular attention to microenterprises and small and medium-sized enterprises.

Rank #4
FIDO2 U2F Security Key Passkey Two-Factor Authentication (2FA) USB Key PIN+Touch (Non-Biometric) USB-A Type TrustKey T110
  • Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T110. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
  • Certified with the new FIDO2 standard, T110 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
  • Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
  • Fits USB-A port : Insert the T110 security key into the USB-A port of each service and log in conveniently with one touch
  • For the driver download and user guide, please visit TrustKey Solutions Home support page.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

CRA dates to keep in view

Article 14 has applied since 11 September 2026. The CRA applies generally from 11 December 2027, while Chapter IV applies from 11 June 2026. According to the European Commission’s summary, products placed on the market before 11 December 2027 are generally subject to the CRA only if they undergo a substantial modification from that date. Application to an individual product depends on the facts and operative legal text; consult the regulation and current Commission guidance. Read the Commission’s CRA summary and implementation information.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Thetis FIDO2 Security Key (USB-A, 2-Pack) - Hardware MFA & Passkey Access for Business, School ERP & Employee Accounts | Compatible with Windows, Google Workspace, Apple ID, Coinbase, Salesforce
  • FIDO2 & Passkey Ready: Business-ready and FIDO2 L1 certified. This key is supported by major management suites and is ideal for both individual and enterprise deployment. Works seamlessly with Gmail, Facebook, GitHub, Dropbox, Coinbase, and more.
  • Universal Connectivity (USB-A ): Features a built-in USB-A connector—simply unfold the key and plug it into your compatible PC or laptop for seamless authentication on the go.
  • Dedicated Manager App: Use the Thetis Manager App for the initial hardware PIN setup. Setting the PIN on the device first ensures a smooth registration process. Once the PIN is configured, you can begin registering the key across your favorite FIDO2-compatible online services.
  • Ultra-Durable & Portable: Featuring a rotating metal cover, this key is water, crush, and tamper-resistant. It fits easily on a keychain and requires no batteries or network connectivity.
  • Check FIDO2 compatibility before purchase - Known limitations: ID Austria is not supported (requires FIDO2 Level 2). Windows Hello login only works with Windows Enterprise editions that support Entra ID, and NFC is NOT supported.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.