Improving security for connected devices
Cyberattacks on connected products and industrial systems are increasingly bringing their security levels into focus. With the Cyber Resilience Act and the new Machinery Regulation, the EU is making cybersecurity a mandatory product feature.
However, implementing 'Secure by Design' and 'Secure by Default' poses a particular challenge for manufacturers and SMEs. A new practical guide from ENISA shows how the requirements can be systematically integrated into development and operation.
Modern connected products are expected to be secure from the ground up. This includes ensuring they meet current security standards and adhere to established security practices. 'Security by Design' and 'Secure by Default' are the terms used to describe these requirements.
In the past, everyday devices and machines were frequently supplied with serious security flaws that made them easy to attack or even allowed them to be hijacked using a default password found online. DSL and fibre-optic routers were long notorious for such flaws.
This meant that home IT systems could quickly be repurposed as spying tools or integrated into a botnet and used for further attacks.
When it comes to industrial components, such flaws can disrupt production. Vulnerabilities present in the out-of-the-box state have therefore long been a thorn in the side of security experts.
Against the backdrop of an escalating cyber threat landscape and recurring security flaws in connected products, the European Commission, the European Parliament and the Member States have adopted comprehensive regulations that oblige manufacturers to implement, amongst other things, 'security by design', vulnerability management and long-term security updates.
Industrial plants and production systems are subject to particular requirements here — more on the topic page OT Security.
New EU requirements increase the pressure on manufacturers
Two sets of EU regulations are fundamentally changing the security landscape for new devices. Foremost among these is the Cyber Resilience Act (CRA). This EU regulation sets out minimum cybersecurity requirements for all connected products placed on the market in the European Union. This applies not only to consumer devices but also to industrial machinery.
New devices must be designed to be secure from the factory. This includes both encrypted data transmissions and long-term availability of updates. Security must be taken into account right from the design stage of a device and guaranteed throughout the product's entire life cycle.
Manufacturers are required to address vulnerabilities throughout the entire product life cycle. Essentially, the CRA makes cybersecurity a fundamental product characteristic and a mandatory requirement for the CE mark.
Furthermore, for the first time, manufacturers are subject to reporting obligations, for example in cases involving actively exploited vulnerabilities. These have been in force since mid-September.
What manufacturers specifically need to prepare is covered by the session Cyber Resilience Act from December 2027: What manufacturers need to know NOW! at it-sa EXPO & Congress 2025.
The Machinery Regulation forms the second EU-wide regulatory framework. It extends the safety requirements for all types of machinery to include cybersecurity and even covers lawnmowers and drills.
In future, all safety-related functions of a system must incorporate safeguards against digital manipulation. The Regulation applies not only to manufacturers but also to retailers and distributors, and covers virtually all sectors of the economy and products across all industries.
Here, too, there is not much time left to prepare, as the Machinery Regulation comes into force on 20 January 2027.
An overview of how the CRA and the Machinery Regulation fit into the wider EU regulatory landscape is provided by the topic page IT Regulation.
A particular challenge for SMEs
The 'Secure by Design' approach represents not only a fundamental shift in product safety, but often in production as well. Protective measures must be integrated right from the design stage and cannot be retrofitted after development.
This can present particular challenges for small and medium-sized enterprises (SMEs) in the manufacturing sector. Here, the new requirements usually come up against lean production processes, which are characterised by constraints in terms of time, budget and security expertise.
Budget constraints limit the financial resources available for investment in security. Specialists with security expertise are often not available in the SME sector. Furthermore, security competes with the priorities of the core business.
SMEs are already increasingly in the crosshairs of cybercriminals, as the article SMEs in the crosshairs of cybercrime shows.
Manufacturers of products with digital elements – such as embedded software, IoT devices and networked systems – as well as hardware and software developers, are particularly affected by these constraints.
This is why ENISA is supporting manufacturers with implementation
For this reason, the European Union Agency for Cybersecurity (ENISA) has decided to publish a practical guide tailored to the needs of small and medium-sized enterprises. It contains a series of concrete guidelines for implementing the 'Secure by Design' and 'Secure by Default' requirements throughout a product's entire lifecycle.
To this end, it maps key security principles to the phases of development, deployment, operation, maintenance and decommissioning, thereby establishing a link to the requirements of the Cyber Resilience Act.
ENISA divides the security measures into two categories: design and development principles, and operational integrity, which can be summarised as follows:
- "Secure by Design" deals with how the system is designed, implemented and built.
- "Secure by Default" focuses on how the system is operated. The latter also includes maintenance measures such as updates.
The basis of this approach is that security requirements do not begin only during testing or in operation, but at an early stage during requirements definition, architectural design and technology selection. For manufacturers, however, this means that they must fundamentally realign their development processes.
The checklists for developers contained in the individual guides are designed to assist with this. This is in line with the guide's aim of presenting the principles in the form of clear, repeatable measures so that they can be more easily integrated into development and production processes.
Focus on supply chains, SBOMs and vulnerability management
In future, secure default configurations and continuous vulnerability management will be essential. For example, unused network ports or administrative support services should be systematically disabled in the default configuration to minimise the attack surface.
These measures are supplemented by requirements for monitoring, incident management, so-called incident response, and recovery procedures that enable restoration following security incidents.
A 'Machine-Readable Security Manifest' (MRSM) can be regarded as an innovative development. It is intended to enable structured, machine-readable documentation of security measures whilst also providing evidence of them.
This can help to make complex compliance processes automatable and scalable.
In addition to technical measures, the ENISA concept therefore also includes organisational security measures, including those designed to secure supply chains. Among other things, security is to be documented via a 'Software Bill of Materials' (SBOM).
Essentially, this is a structured list of all software components, libraries and modules contained within a software application. You can think of it as being similar to the list of ingredients on a food packet. It shows exactly which software components have been used, which versions are being used, and how they are linked together.
Following the supply chain attacks of recent years -- such as the SolarWinds incident -- SBOMs are becoming increasingly important, as modern software is rarely written entirely in-house. SBOMs are almost always generated automatically by specialised software tools.
How manufacturers can use SBOMs in practice to meet CRA requirements is shown by the session EU CRA and SBOMs at it-sa EXPO & Congress 2025.
The German Federal Office for Information Security (BSI) is also providing support for the implementation of the CRA. Various new publications, particularly from the TR-03183 series, are intended to serve as an 'introduction to the Cyber Resilience Act'.
They cover individual aspects such as reporting obligations and SBOMs. A selection of cybersecurity measures is also available in a machine-readable format.
How these requirements fit into the wider EU regulatory landscape for 2026 is covered by the article IT Regulations: Which IT laws should you be aware of in 2026?.
Want to connect directly with manufacturers, testing bodies and security experts on Secure by Design and the Cyber Resilience Act? At the it-sa EXPO & Congress you can expect live talks, hands-on use cases and direct exchange with exhibitors on product security and regulation. Register as a visitor now!
Sources:
- ENISA: Secure by Design and Default Playbook
- Cyber-Regulierung.de: ENISA publishes Secure by Design and Default Playbook
- Maschinenbau-Journal: Practical guide to 'Security by Design and Default' for small and medium-sized enterprises
- CRA Evidence: ENISA's 'Secure by Design' Playbook: A CRA Guide
- IHK: New EU Machinery Regulation to come into force in 2027: Prepare for the transition in the long term
- BSI: Cyber Resilience Act
- BSI: Technical Guideline TR-03183-1 published in version 1.0.0
- BSI: BSI TR-03183 Cyber Resilience Requirements

