What does the CRA's secure-by-default requirement mean?
The CRA requires products with digital elements to be made available on the market with a secure-by-default configuration, unless the tailor-made product exception applies. The requirement sits in Annex I Part I point (2)(b) and includes the possibility for the user to reset the product to its original state.
The default state must be tied to the manufacturer's cybersecurity risk assessment. Article 13 requires the assessment to consider the product's intended purpose, reasonably foreseeable use, conditions of use such as the operational environment and assets to be protected, and the expected time in use.
Annex I Part I points (1) and (2)(b), Article 13(2)-(4), and Annex VII require risk-based design, secure defaults, reset capability, and technical documentation of applicability.
Sections 4.1.3, 4.1.4, and 4.2.4 explain that secure defaults are based on the product risk assessment, intended purpose, and reasonably foreseeable use.