Skip to main content

Clause 5.4 — Secure by default product

Subclause 5.4 establishes the secure by default principle in FprEN 40000-1-2:2026. The default configuration of a product placed on the market must be secure without requiring user action.

What Clause 5.4 requires

Manufacturers should implement secure default configurations appropriate for the product context, such as:

  • Enabling security features out of the box.
  • Disabling non-essential network services and remote administration by default.
  • Updating products to the latest secure version upon initial setup.
  • Enforcing opt-in mechanisms for telemetry and analytics data collection.
  • Providing a straightforward "reset to secure defaults" mechanism.
  • Preventing unauthorized installation of older, vulnerable firmware or software (anti-rollback).

How CVD Portal supports compliance

CVD Portal helps you implement, verify, and document secure default practices:

  • Security.txt generator: CVD Portal automatically generates and hosts compliant security.txt files (RFC 9116) with secure defaults, PGP key advertising, and canonical URLs.
  • Portal configuration default safeguards: Public researcher portals and submission endpoints ship with rate limiting, input sanitization, and PGP encryption pre-enabled by default.
  • Verification evidence tracking: You can document secure default testing results, anti-rollback checks, and reset-mechanism validation inside the V&V technical file.
  • Automated configuration monitoring: Daily platform health checks verify that customer security policies, domain monitoring, and contact endpoints remain active and secure.