InsideCRA
InsideCRA › Topics › Secure by design and default

Topic

Secure by design and default

The Part I properties, and the configuration duty behind the slogan.

The slogan has specific content. Products ship without known exploitable vulnerabilities and with a secure-by-default configuration F-040; consumer products install security updates automatically by default with a clear opt-out F-041; and the rest of the Part I properties — access control, data protection, minimisation, resilience — apply on the basis of the risk assessment F-017.

The honest reading of "where applicable"

The risk assessment indicates whether and how each item applies, and Article 13(4) asks for a clear justification in the technical documentation for any essential requirement treated as not applicable — a written reason, not vibes.

Verified facts this page relies on

Facts are maintained and human-verified in the CEMarque Facts Table (v2026.09.4, verified 2026-09-10).

Editorial review: Claude (AI reviewer, delegated by the editor), 2026-10-08. Methodology and correction process: how this site works.

Related in the reference

Ready to work through your obligations? Get your CE readiness verdict on CEMarque.