Secure by Default
Secure by default means a product ships with protective security settings pre-configured. Features are disabled, ports are closed, and strong authentication is active without user action. Annex I of the EU Cyber Resilience Act makes this a mandatory requirement.
Secure by default means a product ships with protective security settings pre-configured. Features are disabled, ports are closed, and strong authentication is active without user action. Annex I of the EU Cyber Resilience Act makes this a mandatory requirement.
CRA Legal TermsLast updated 7 August 2026
What Does Secure by Default Mean?
A product is secure by default when it arrives in a secure state that does not require configuration changes by the user.
Examples include unique per-device passwords, disabled non-essential network services at first boot, and automatic security updates enabled by default. Firewall rules use closed default settings. Debug interfaces require explicit authentication. Most users do not change default settings or harden devices after purchase.
Secure by Default as a CRA Legal Requirement
Annex I Part I(2)(b) of the EU Cyber Resilience Act requires manufacturers to ensure products are placed on the market with a secure default configuration. The default state must satisfy the security baseline. Providing a hardening guide is not enough.
The requirement prohibits shared default passwords. Every device must use unique credentials or prompt the user to set a password before operation.
The configuration must also allow users to reset the product to its original secure state. For custom business products, manufacturers and business users may agree to adapt these default settings. Failure to meet Annex I requirements can lead to enforcement action by market surveillance authorities.
How Manufacturers Implement Secure by Default
Manufacturers must embed secure defaults early in product development.
Key practices include generating unique credentials at the factory, disabling unnecessary network services, and enabling automatic updates by default. Manufacturers should configure TLS with modern cipher suites and audit configurations before production. Document the secure baseline and justify any enabled services in the technical documentation.
Common Mistakes
A frequent violation is shipping products with shared factory passwords such as 'admin' or 'admin'. Prompting users to change a shared password does not meet the standard.
Manufacturers also enable services like Telnet, FTP, or UPnP for easy setup and tell users to turn them off later. If a service is not necessary for core function, the manufacturer must disable it by default.
CVD Portal makes Secure by Default compliance straightforward.
Public CVD submission portal, acknowledgment tracking, Article 14 deadline alerts, and CSAF advisory generation. Receiving and tracking reports is free for all manufacturers placing products with digital elements on the EU market. Article 14 filing with the SRP-ready package is on Pro.
Start your free portalFrequently asked
Does 'secure by default' mean manufacturers cannot ship any open network ports?+
No. Secure by default means only the ports, services, and interfaces required for intended functions are open. Products that require connectivity keep necessary services active. All other services remain closed. Enabled interfaces must use strong credentials and current protocols.
Are shared default passwords prohibited by the CRA?+
Yes. Annex I Part I(2)(b) requires unique per-device credentials. Shared passwords across a product line do not satisfy this rule. Each device must ship with a unique factory password or require the user to set a password during initial setup.
Is enabling automatic updates required for secure by default compliance?+
The CRA requires manufacturers to deliver security updates easily. Enabling automatic updates by default is the standard method for consumer devices. For industrial equipment requiring strict change management, clear update notifications can be used instead.
Sector checklists covering Secure by Default
This definition is part of the EU Cyber Resilience Act guide, which explains Regulation (EU) 2024/2847 article by article.
Browse the full CRA Compliance Checklist
See how Secure by Default fits into your complete CRA compliance programme.