Cybersicherheit Laptop mit Schloss am Serverschrank

security.txt: A small text file to protect your business

If you want to close security vulnerabilities quickly, you need to be reachable. A simple file on your website makes this possible and will also become mandatory with the Cyber Resilience Act.

Vulnerabilities in digital products and services are often discovered by external security researchers. To ensure that such information reaches the appropriate contacts in the company promptly, the Federal Office for Information Security (BSI) recommends using a security.txt.

What's behind it?

The security.txt is a standardised text file that companies place on their website under the fixed path https://[your-domain]/.well-known/security.txt. It contains contact information for reporting vulnerabilities – such as an email address or a link to a policy on handling such reports. The format follows the international standard RFC 9116 and is readable by both humans and automated systems.

The security.txt does not replace existing communication channels or security processes; it complements them meaningfully.

What information is required?

Mandatory information is limited to two fields: a contact and an expiry date for the file. Optional additional information can be included, such as references to public encryption keys for confidential communication. Free support for creating the file is offered by the generator at securitytxt.org.

Relevance through the Cyber Resilience Act

The text file also helps in the implementation of regulatory developments: The Cyber Resilience Act (CRA) establishes binding requirements for the cybersecurity of connected products from 11 December 2027. For actively exploited vulnerabilities and serious security incidents, reporting obligations for manufacturers of connected products already apply from 11 September 2026. The security.txt helps companies receive external information on these more easily.

BSI recommendation and further information

The BSI explicitly recommends the security.txt and provides a concise overview of its purpose, benefits, and implementation through the Alliance for Cyber Security (ACS). (only available in German)

Relevant in topic:

Contact

Katrin, Sobania_quad

Dr. Katrin Sobania

Director Information and Communication Technology | E-Government | Postal Services | IT Security