The security.txt standard, defined in RFC 9116, lets organizations publish a machine-readable vulnerability-reporting contact at /.well-known/security.txt. Dutch authorities and the Digital Trust Center (DTC) promoted the low-cost standard to route responsible-disclosure reports directly to the correct team, reducing the time needed to identify owners of vulnerable systems. Internet.nl added a test for both the presence and validity of the file, and the Netherlands made security.txt a “Pas toe of leg uit” requirement for central and local government bodies and related public organizations.
Adoption has grown but remains inconsistent. More than 77,000 Dutch domains deployed security.txt after the DTC’s 2022 campaign, and an early-2023 measurement found implementation on nearly 20% of assessed government sites; however, only 2.2% of .nl web domains reportedly had a valid file by 2024. SIDN consequently planned to reward registrars with scorecard-related financial discounts for .nl domains carrying usable security.txt files, alongside platform support in DirectAdmin, cPanel, Plesk, and WordPress tooling that can sign files and warn of expiration.

See the reporting duties and controls this puts on the clock.
11 events from the most recent confirmed update back to the earliest known activity.
Forum Standaardisatie added security.txt to the Dutch “Pas toe of leg uit” list, requiring its use by municipalities, provinces, central-government bodies, water authorities, and implementing organizations.
Forum Standaardisatie held a public consultation on whether security.txt should be added to the Dutch “Pas toe of leg uit” list.
An Internet.nl measurement found that nearly 20% of assessed Dutch government websites had implemented a security.txt file.
The Digital Trust Center and numerous ambassadors called on companies and IT service providers to publish security.txt files.
The Digital Trust Center began warning Dutch companies when it identified serious security vulnerabilities, an activity for which it later used security.txt contact details to speed notification.
The IETF began work on a universal standard for reporting security vulnerabilities, work that later produced the security.txt protocol specified in RFC 9116.
The Digital Trust Center became part of the Dutch National Cyber Security Centre.
SIDN announced plans to include security.txt availability and validity in its Registrar Scorecard incentive program, offering a financial discount for .nl domains with usable files. SIDN worked with the Vereniging van Registrars to increase adoption among Dutch domain and hosting providers.
Following the October 2022 adoption appeal, more than 88,000 Dutch domain names had deployed a security.txt file.
An expert assessment commissioned by Forum Standaardisatie concluded that security.txt offered clear value, had a low technical implementation threshold, and should be added to the Dutch “Pas toe of leg uit” list.
Internet.nl added a security.txt test to its website-testing service in collaboration with the Digital Trust Center. The test checks for the presence of a file and whether it conforms to the required format.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
6 references tracked. Mallory keeps watching after this page renders.
ncsc.nl
Open sourcencsc.nl
Open sourcencsc.nl
Open sourcencsc.nl
Open sourcencsc.nl
Open sourcerfc-editor.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.