← CRA Glossary
CRA Legal Terms

Secure by Default

Secure by default means that a product ships with security settings pre-configured to the most protective state - disabled features, closed ports, strong authentication - without requiring users to take action to enable security. It is an explicit essential requirement under Annex I of the EU Cyber Resilience Act.

Secure by default means that a product ships with security settings pre-configured to the most protective state - disabled features, closed ports, strong authentication - without requiring users to take action to enable security. It is an explicit essential requirement under Annex I of the EU Cyber Resilience Act.

CRA Legal Terms

What Does Secure by Default Mean?

A product is secure by default when it arrives in the hands of the user in a security-positive state that does not depend on the user making configuration changes. Practical examples include: unique per-device passwords rather than shared factory defaults; all non-essential network services disabled at first boot; automatic security update installation enabled unless explicitly opted out; closed firewall rules with explicit allow-listing rather than open-by-default policies; and no debug interfaces accessible without explicit authentication. The principle recognises that most users - particularly consumers - will not consult a manual or harden a device after purchase.

CRA reference:Annex I Part I(2)(e)

Secure by Default as a CRA Legal Requirement

Annex I Part I(2)(e) of the EU Cyber Resilience Act explicitly requires manufacturers to ensure that products with digital elements are placed on the market with a secure by default configuration. This requirement means that the default out-of-box state must satisfy the security baseline - it is not sufficient to provide a hardening guide. The requirement also prohibits shared default passwords: every device must use unique credentials or require the user to set a password before the device becomes functional. Non-compliance with Annex I essential requirements constitutes a basis for market surveillance authority enforcement action.

CRA reference:Annex I Part I(2)(e)

How Manufacturers Implement Secure by Default

Implementing secure by default requires design decisions embedded early in product development. Key practices include: generating unique, device-specific credentials at the factory or on first boot rather than using shared defaults; disabling all network services not required for the product's primary function; configuring automatic updates to be on by default with a clear opt-out mechanism (not opt-in); pre-configuring TLS with strong cipher suites rather than supporting deprecated protocols for backwards compatibility; and performing a pre-ship configuration audit against the intended secure baseline before each production run. The secure default configuration should be documented in technical documentation with justification for any enabled services.

CRA reference:Annex I Part I(2)(e), Article 13

Common Mistakes

The most common violation of secure by default is shipping a product with a shared factory password (e.g. 'admin'/'admin') that is documented in a manual or printed on the device. Even if users are prompted to change it, this does not satisfy the CRA's requirement for a secure default. Manufacturers also frequently enable services such as Telnet, FTP, or UPnP for ease of setup and rely on documentation to tell users to disable them. The CRA's requirement is explicit: if it is not necessary for the core function, it must be off by default - user documentation is not an acceptable substitute for proper configuration.

CRA reference:Annex I Part I(2)(e)

CVD Portal makes Secure by Default compliance straightforward.

Public CVD submission portal, acknowledgment tracking, Article 14 deadline alerts, and CSAF advisory generation. Receiving and tracking reports is free for all manufacturers placing products with digital elements on the EU market. Article 14 filing with the SRP-ready package is on Pro.

Start your free portal

Frequently asked

Does 'secure by default' mean manufacturers cannot ship any open network ports?+

No. Secure by default means that only the ports, services, and interfaces required for the product's intended function are open by default. A product that requires network connectivity to function will legitimately have some network services active. The requirement is that any service not necessary for the primary intended use must be disabled by default, and that any enabled service must use strong, unique credentials and current protocols.

Are shared default passwords prohibited by the CRA?+

Yes. The requirement for unique per-device credentials is a direct implication of the secure by default obligation in Annex I Part I(2)(e). Shared passwords - those that are the same across all devices of a product line, whether factory-set or printed in documentation - do not satisfy this requirement. Each device must either ship with a unique factory-generated credential or require the user to set a password before any network functionality is accessible.

Is enabling automatic updates required for secure by default compliance?+

The CRA requires manufacturers to make security updates available and to make it easy for users to apply them. Enabling automatic updates by default is the most straightforward way to satisfy this obligation for consumer products. For industrial and enterprise products where updates require change control processes, manufacturers may implement notification mechanisms rather than silent auto-update, but the default should facilitate, not obstruct, the timely application of security patches.

Related terms

Secure by DesignSecure by design means that security is built into a product's architecture and development process from the earliest design stage, rather than added as an afterthought after development is complete. The EU Cyber Resilience Act's essential requirements in Annex I mandate a secure-by-design approach for all products with digital elements.Essential Cybersecurity RequirementsThe essential cybersecurity requirements are the mandatory security properties and vulnerability handling obligations set out in Annex I of the CRA that all products with digital elements must satisfy before being placed on the EU market. They are the substantive compliance test at the heart of the CRA.Attack SurfaceThe attack surface of a product is the totality of different points - interfaces, APIs, protocols, hardware ports, and user inputs - through which an attacker could attempt to enter or extract data from a system. Reducing attack surface is a core principle of the CRA's essential cybersecurity requirements.Annex I Essential RequirementsAnnex I of the EU Cyber Resilience Act sets out the mandatory cybersecurity requirements that all products with digital elements must meet. It is divided into two parts: Part I covers secure product properties, and Part II covers manufacturer vulnerability handling obligations.Defence in DepthDefence in depth is a security strategy that employs multiple overlapping layers of security controls so that if one layer fails, others continue to protect the system. It is a core principle behind the CRA's essential requirements, which take a holistic view of product security rather than relying on any single mechanism.Principle of Least PrivilegeThe Principle of Least Privilege states that every component, process, or user should operate with the minimum permissions necessary to perform its function. It is a fundamental secure design principle required by the CRA's Annex I essential requirements and limits the damage an attacker can cause if any component is compromised.

Sector checklists covering Secure by Default

Smart Home DevicesSmart home devices - thermostats, smart speakers, lighting controllers, home security cameras - are among the most common products with digital elements in scope for the CRA. Most will fall into the Default class requiring self-assessment, but devices with gateway functionality may be classified as Important Class I.Consumer Routers & ModemsConsumer routers and modems are high-value targets for attackers and face specific CRA requirements around default credentials, remote management security, and firmware update integrity. Routers marketed for home use are Default class; those marketed for industrial or critical infrastructure use may be Annex III Class II.IoT Sensors & Connected DevicesIoT sensors - temperature, humidity, pressure, flow, and motion sensors - are the backbone of industrial and building automation. Most fall into the Default CRA class, but their constrained hardware often makes meeting Annex I security requirements challenging. Manufacturers must plan for secure update mechanisms even on resource-constrained devices.Wearable Devices & Fitness TrackersWearable devices - fitness trackers, smartwatches, and health monitors - collect sensitive biometric and health data and are in scope for the CRA as products with digital elements. Unlike medical devices regulated under MDR, general fitness wearables are not excluded from the CRA and must comply with all Annex I security requirements, including data minimisation, encrypted transmission, and secure update mechanisms.

Browse the full CRA Compliance Checklist

See how Secure by Default fits into your complete CRA compliance programme.

View checklists →