← CRA Glossary
CRA Legal Terms

Secure by Default

Secure by default means a product ships with protective security settings pre-configured. Features are disabled, ports are closed, and strong authentication is active without user action. Annex I of the EU Cyber Resilience Act makes this a mandatory requirement.

Secure by default means a product ships with protective security settings pre-configured. Features are disabled, ports are closed, and strong authentication is active without user action. Annex I of the EU Cyber Resilience Act makes this a mandatory requirement.

CRA Legal Terms

Last updated 7 August 2026

What Does Secure by Default Mean?

A product is secure by default when it arrives in a secure state that does not require configuration changes by the user.

Examples include unique per-device passwords, disabled non-essential network services at first boot, and automatic security updates enabled by default. Firewall rules use closed default settings. Debug interfaces require explicit authentication. Most users do not change default settings or harden devices after purchase.

CRA reference:Annex I Part I(2)(b)

How Manufacturers Implement Secure by Default

Manufacturers must embed secure defaults early in product development.

Key practices include generating unique credentials at the factory, disabling unnecessary network services, and enabling automatic updates by default. Manufacturers should configure TLS with modern cipher suites and audit configurations before production. Document the secure baseline and justify any enabled services in the technical documentation.

CRA reference:Annex I Part I(2)(b), Article 13

Common Mistakes

A frequent violation is shipping products with shared factory passwords such as 'admin' or 'admin'. Prompting users to change a shared password does not meet the standard.

Manufacturers also enable services like Telnet, FTP, or UPnP for easy setup and tell users to turn them off later. If a service is not necessary for core function, the manufacturer must disable it by default.

CRA reference:Annex I Part I(2)(b)

CVD Portal makes Secure by Default compliance straightforward.

Public CVD submission portal, acknowledgment tracking, Article 14 deadline alerts, and CSAF advisory generation. Receiving and tracking reports is free for all manufacturers placing products with digital elements on the EU market. Article 14 filing with the SRP-ready package is on Pro.

Start your free portal

Frequently asked

Does 'secure by default' mean manufacturers cannot ship any open network ports?+

No. Secure by default means only the ports, services, and interfaces required for intended functions are open. Products that require connectivity keep necessary services active. All other services remain closed. Enabled interfaces must use strong credentials and current protocols.

Are shared default passwords prohibited by the CRA?+

Yes. Annex I Part I(2)(b) requires unique per-device credentials. Shared passwords across a product line do not satisfy this rule. Each device must ship with a unique factory password or require the user to set a password during initial setup.

Is enabling automatic updates required for secure by default compliance?+

The CRA requires manufacturers to deliver security updates easily. Enabling automatic updates by default is the standard method for consumer devices. For industrial equipment requiring strict change management, clear update notifications can be used instead.

Sector checklists covering Secure by Default

Smart Home DevicesSmart home devices - thermostats, smart speakers, lighting controllers, home security cameras - are among the most common products with digital elements in scope for the CRA. Most will fall into the Default class requiring self-assessment, but devices with gateway functionality may be classified as Important Class I.Consumer Routers & ModemsConsumer routers and modems are high-value targets for attackers and face specific CRA requirements around default credentials, remote management security, and firmware update integrity. Routers marketed for home use are Default class; those marketed for industrial or critical infrastructure use may be Annex III Class II.IoT Sensors & Connected DevicesIoT sensors - temperature, humidity, pressure, flow, and motion sensors - are the backbone of industrial and building automation. Most fall into the Default CRA class, but their constrained hardware often makes meeting Annex I security requirements challenging. Manufacturers must plan for secure update mechanisms even on resource-constrained devices.Wearable Devices & Fitness TrackersWearable devices collect sensitive biometric and health data and are in scope for the CRA as products with digital elements. The category covers fitness trackers, smartwatches, and health monitors. Unlike medical devices regulated under MDR, general fitness wearables are not excluded from the CRA. They must comply with all Annex I security requirements, including data minimisation, encrypted transmission, and secure update mechanisms.

This definition is part of the EU Cyber Resilience Act guide, which explains Regulation (EU) 2024/2847 article by article.

Browse the full CRA Compliance Checklist

See how Secure by Default fits into your complete CRA compliance programme.

View checklists →