Book an Appointment

The ENISA Secure by Design & Default Playbook

A deep dive into ENISA's free implementation guide of 30 July 2026: 22 principles as one-page playbooks with checklists, minimum evidence and release gates – including machine-processable attestation and an indicative CRA mapping.

Last updated: August 2026 · Valeri Milke, ISO 27001 & ISO 42001 Lead Auditor

22Principles as one-page playbooks
14 + 8Secure by design + secure by default
~80Pages — CC BY 4.0, also on GitHub
28Consultation contributions — incl. OWASP, BSI, ANSSI

On 30 July 2026, the EU Agency for Cybersecurity (ENISA) published the Secure by Design and Default Playbook (version 1.0) – a hands-on guide that translates secure-by-design and secure-by-default principles into repeatable engineering routines. The document is written explicitly for small and medium-sized manufacturers of products with digital elements: teams with tight budgets, little dedicated security staff and short release cycles. Across roughly 80 pages, ENISA distils established frameworks – its own IoT and SDLC guidance, NIST and OWASP material – into 22 principles, each elaborated as a one-page playbook with objective, checklist, minimum evidence and a release gate. The final version follows a public consultation in spring 2026 that drew 28 contributions, including from OWASP, BSI, ANSSI, Red Hat and the Eclipse Foundation. The playbook is licensed under CC BY 4.0 and also available as a GitHub repository – ENISA frames it as a practical starting point, not a compliance manual or legal advice.

From draft to CRA practice

How the playbook came to be — and which deadlines it feeds into. Tap a milestone.

The Essentials at a Glance

Six topic blocks — tap to expand.

The four principle families

22 principles in four groups — from architecture to secure delivery.

6 principles · secure by design
  • Threats are modelled early; architecture patterns and vetted cryptography are embedded in the development process rather than retrofitted.
Trust boundaries & threat modellingLeast privilegeIdentity & authentication architectureAttack surface minimisationDefence in depthOpen design

Standards & Sources

The content on this page is based on the following publicly available guides and studies.

ENISA · 2026

ENISA Secure by Design and Default Playbook

Version 1.0 of 30 July 2026 (TLP:CLEAR, CC BY 4.0); basis for all statements on principles, playbook format, threat modelling, attestation and Annexes B/C.

ENISA · 2026

enisa-sbd-playbook (GitHub repository)

All 22 playbooks as Markdown under CC BY 4.0 – fork them into your own wiki or repo.

Official Journal of the EU / EUR-Lex · 2024

Regulation (EU) 2024/2847 (Cyber Resilience Act)

Legally binding full text; reference for the essential requirements from Annex I mirrored in Annexes B/C of the playbook.

Threat Modeling Manifesto Working Group · 2020

Threat Modeling Manifesto

Values and principles guiding the playbook's threat-modelling section; basis of Shostack's four key questions.

CISA · 2026

Secure by Design

US initiative with guidance and a voluntary manufacturer pledge; conceptual groundwork the ENISA playbook builds on.

Anchoring secure by design in your product?

Whether a CRA gap analysis, a threat-modelling workshop or introducing the playbooks to your engineering team – we translate the ENISA playbook to your product together. Get in touch.