Skip to main content

How do I publish my security.txt for the CRA?

CVD Portal generates your security.txt automatically and serves it at your portal's /.well-known/security.txt. To satisfy the CRA, add the generated reference or the compliance badge to your own website, then use Verify my website to confirm the channel is reachable.

Key takeaways

  • CVD Portal builds an RFC 9116 security.txt for you and keeps it current. You do not write it by hand.
  • The CRA requires the reporting channel to be publicly discoverable on your own website (Annex I Part II point 5).
  • Publish either the generated security.txt or the compliance badge on your domain, then verify.
  • Verification is the step most often skipped. A channel that exists but is not discoverable does not satisfy the obligation.
Silent walkthrough. Follow the numbered steps below for the full text.

Steps

  1. Sign in and open CVD Readiness from the left navigation.
  2. Scroll to Publish Your Reporting Channel.
  3. Copy the generated security.txt (step B) or the compliance badge (step A) and add it to your own website. The badge links to your live verification page.
  4. Enter your website domain and select Verify my website. The check looks for a valid security.txt or a public CVD policy on your domain.
  5. Confirm the panel reports the channel as verified. Until it passes, your readiness cannot reach 100 percent.

Your generated file is always available at https://<your-slug>.cvdportal.com/.well-known/security.txt, and it names your contact address, policy, and CSAF advisories.

Last updated 17 September 2026.