Secure by design describes how a system is built: threats are modelled early, and architecture patterns, vetted cryptography and systematic vulnerability management are embedded in the development process rather than retrofitted. Secure by default describes how the product arrives at the customer: shipped in the most secure configuration reasonably possible, with no expert knowledge required – protective measures are active, and weakening them takes a deliberate decision. The playbook organises the 14 design principles into Architectural Foundations and Operational Integrity, and the 8 default principles into Default Hardening and Guided Protection.
The ENISA Secure by Design & Default Playbook
A deep dive into ENISA's free implementation guide of 30 July 2026: 22 principles as one-page playbooks with checklists, minimum evidence and release gates – including machine-processable attestation and an indicative CRA mapping.
22Principles as one-page playbooks
14 + 8Secure by design + secure by default
~80Pages — CC BY 4.0, also on GitHub
28Consultation contributions — incl. OWASP, BSI, ANSSI
On 30 July 2026, the EU Agency for Cybersecurity (ENISA) published the Secure by Design and Default Playbook (version 1.0) – a hands-on guide that translates secure-by-design and secure-by-default principles into repeatable engineering routines. The document is written explicitly for small and medium-sized manufacturers of products with digital elements: teams with tight budgets, little dedicated security staff and short release cycles. Across roughly 80 pages, ENISA distils established frameworks – its own IoT and SDLC guidance, NIST and OWASP material – into 22 principles, each elaborated as a one-page playbook with objective, checklist, minimum evidence and a release gate. The final version follows a public consultation in spring 2026 that drew 28 contributions, including from OWASP, BSI, ANSSI, Red Hat and the Eclipse Foundation. The playbook is licensed under CC BY 4.0 and also available as a GitHub repository – ENISA frames it as a practical starting point, not a compliance manual or legal advice.
From draft to CRA practice
How the playbook came to be — and which deadlines it feeds into. Tap a milestone.
Spring 2026
Public consultation
The consultation draft gathers 28 contributions — including from OWASP, BSI, ANSSI, Red Hat and the Eclipse Foundation. The feedback shapes the final version.
30 Jul 2026
Playbook v1.0 released
ENISA publishes version 1.0: around 80 pages, 22 principles as one-page playbooks with checklists, minimum evidence and release gates — CC BY 4.0, also available as a GitHub repository.
11 Sep 2026
CRA reporting duties start
From this date, manufacturers report actively exploited vulnerabilities and severe incidents. The operational playbooks — vulnerability and patch management, logging, incident response — feed directly into these capabilities.
11 Dec 2027
CRA main obligations + CE
The remaining CRA obligations apply. Annex C of the playbook maps all 22 principles indicatively to the essential requirements in CRA Annex I — but does not replace conformity assessment.
The Essentials at a Glance
Six topic blocks — tap to expand.
The four principle families
22 principles in four groups — from architecture to secure delivery.
- Threats are modelled early; architecture patterns and vetted cryptography are embedded in the development process rather than retrofitted.
Trust boundaries & threat modellingLeast privilegeIdentity & authentication architectureAttack surface minimisationDefence in depthOpen design
- Day-to-day engineering practice — from secure coding and logging to supply-chain controls. The core of ENISA's recommended adoption baseline comes from this group — complemented by the product-relevant default playbooks.
Life-cycle managementUser-centric designSecure coding & verificationLogging & monitoringConfiguration & change managementIncident responseVulnerability & patch managementSupply-chain controls incl. SBOM
- The most secure configuration reasonably possible out of the box — protective measures are active, with no expert knowledge required.
Minimisation of default servicesRestrictive initial accessSecure communication by defaultUnique device identities
- Security across usage: weakening protections takes a deliberate decision — and the security posture stays transparent.
Mandatory security onboardingAutomated updatesTransparent security postureSecure recovery & ownership transfer
Standards & Sources
The content on this page is based on the following publicly available guides and studies.
ENISA Secure by Design and Default Playbook
Version 1.0 of 30 July 2026 (TLP:CLEAR, CC BY 4.0); basis for all statements on principles, playbook format, threat modelling, attestation and Annexes B/C.
enisa-sbd-playbook (GitHub repository)
All 22 playbooks as Markdown under CC BY 4.0 – fork them into your own wiki or repo.
Regulation (EU) 2024/2847 (Cyber Resilience Act)
Legally binding full text; reference for the essential requirements from Annex I mirrored in Annexes B/C of the playbook.
Threat Modeling Manifesto
Values and principles guiding the playbook's threat-modelling section; basis of Shostack's four key questions.
Secure by Design
US initiative with guidance and a voluntary manufacturer pledge; conceptual groundwork the ENISA playbook builds on.
Related Services
Anchoring secure by design in your product?
Whether a CRA gap analysis, a threat-modelling workshop or introducing the playbooks to your engineering team – we translate the ENISA playbook to your product together. Get in touch.