Clause 5.4 — Secure by default product
Subclause 5.4 establishes the secure by default principle in FprEN 40000-1-2:2026. The default configuration of a product placed on the market must be secure without requiring user action.
What Clause 5.4 requires
Manufacturers should implement secure default configurations appropriate for the product context, such as:
- Enabling security features out of the box.
- Disabling non-essential network services and remote administration by default.
- Updating products to the latest secure version upon initial setup.
- Enforcing opt-in mechanisms for telemetry and analytics data collection.
- Providing a straightforward "reset to secure defaults" mechanism.
- Preventing unauthorized installation of older, vulnerable firmware or software (anti-rollback).
How CVD Portal supports compliance
CVD Portal helps you implement, verify, and document secure default practices:
- Security.txt generator: CVD Portal automatically generates and hosts compliant
security.txtfiles (RFC 9116) with secure defaults, PGP key advertising, and canonical URLs. - Portal configuration default safeguards: Public researcher portals and submission endpoints ship with rate limiting, input sanitization, and PGP encryption pre-enabled by default.
- Verification evidence tracking: You can document secure default testing results, anti-rollback checks, and reset-mechanism validation inside the V&V technical file.
- Automated configuration monitoring: Daily platform health checks verify that customer security policies, domain monitoring, and contact endpoints remain active and secure.