How do I publish my security.txt for the CRA?
CVD Portal generates your security.txt automatically and serves it at your portal's /.well-known/security.txt. To satisfy the CRA, add the generated reference or the compliance badge to your own website, then use Verify my website to confirm the channel is reachable.
Key takeaways
- CVD Portal builds an RFC 9116
security.txtfor you and keeps it current. You do not write it by hand. - The CRA requires the reporting channel to be publicly discoverable on your own website (Annex I Part II point 5).
- Publish either the generated
security.txtor the compliance badge on your domain, then verify. - Verification is the step most often skipped. A channel that exists but is not discoverable does not satisfy the obligation.
Steps
- Sign in and open CVD Readiness from the left navigation.
- Scroll to Publish Your Reporting Channel.
- Copy the generated
security.txt(step B) or the compliance badge (step A) and add it to your own website. The badge links to your live verification page. - Enter your website domain and select Verify my website. The check looks for a valid
security.txtor a public CVD policy on your domain. - Confirm the panel reports the channel as verified. Until it passes, your readiness cannot reach 100 percent.
Your generated file is always available at https://<your-slug>.cvdportal.com/.well-known/security.txt, and it names your contact address, policy, and CSAF advisories.
Related
- Full procedure: SOP-01, Setting Up Your CVD Portal
- Reference: Generating your security.txt
Last updated 17 September 2026.