ENISA Secure by Design and Default Playbook

Back to all publications

Publication date:July 30, 2026

A Practical Guide to Secure by Design and Default Principles for SMEs

Modern products with digital elements are increasingly expected to be secure by design and secure by default. However, many organisations, in particular small and medium-sized enterprises, may face distinct challenges in applying these concepts consistently, requiring targeted solutions.

This report puts forward a set of principles and tangible guidance on the application of secure by design and default requirements throughout the life cycle of a product. In particular, the report focuses on explaining these principles in clear, repeatable actions that can be applied to existing engineering, product and release processes.

Additional material

A GitHub repository with all 22 Secure by Design and Secure by Default playbooks in an easy-to-navigate format is available here: https://github.com/enisaeu/enisa-sbd-playbook/