The ENISA Secure by Design and Default Playbook provides practical guidance for SMEs on integrating cybersecurity into the entire product development lifecycle. It presents clear principles, actionable recommendations, and repeatable practices for implementing secure-by-design and secure-by-default approaches throughout engineering, development, testing, release, and maintenance processes. The playbook helps organisations strengthen product security, reduce vulnerabilities, and support compliance with the Cyber Resilience Act (CRA).
Repositories
Access a wealth of resources including articles, whitepapers, tools, and guides to support your learning.
- Application Security
Secure-by-Design System Development with UML
- Published date:
- Author: MERIT Project Consortium
This self-paced MOOC introduces system security from a design-oriented perspective, helping learners integrate security requirements during the early stages of system development. The course covers secure system architecture, security-focused requirements engineering, UML-based modelling, vulnerability identification, and secure-by-design methodologies. Through video lectures, practical modelling exercises, and assignments, participants learn how to build more robust and resilient systems before implementation begins.
- Network Security
Foundations of Zero Trust Cybersecurity
- Published date:
- Author: European Union Agency for Cybersecurity (ENISA)
The Zero Trust Cybersecurity Foundation course introduces the principles of Zero Trust (ZT) and Zero Trust Architecture (ZTA), providing learners with the knowledge required to design and implement modern security architectures based on the “never trust, always verify” approach. Following the guidance of NIST SP 800-207, the course covers Zero Trust concepts, implementation strategies, architecture options, planning considerations, and practical use cases to help organisations strengthen their cyber resilience and reduce the risk of data breaches and cyberattacks.
- Risk Management
ENISA Cybersecurity Maturity Assessment for SMEs
- Published date:
- Author: European Union Agency for Cybersecurity (ENISA)
The ENISA Cybersecurity Maturity Assessment for SMEs is an online self-assessment tool that helps small and medium-sized enterprises evaluate their cybersecurity maturity across people, technology, and organisational processes. Based on the assessment results, the tool provides a tailored action plan with practical recommendations to improve cyber resilience, strengthen security practices, and support the management of cybersecurity risks.
- AI Security
EU Action Plan on Cybersecurity and Artificial Intelligence
- Published date:
- Author: European Commission
The EU Action Plan on Cybersecurity and Artificial Intelligence outlines the European Commission’s strategy for promoting the safe and responsible use of AI while strengthening Europe’s cybersecurity and resilience. The Action Plan focuses on secure AI deployment, AI-assisted cyber defence, resilience of critical infrastructure, implementation of the AI Act, NIS2 Directive, and Cyber Resilience Act, and the development of European AI capabilities for cybersecurity through research, innovation, and secure testing environments.
- Endpoint Security
European Union Vulnerability Database (EUVD)
- Published date:
- Author: European Union Agency for Cybersecurity (ENISA)
The European Union Vulnerability Database (EUVD) is the official EU platform for collecting and publishing information on publicly disclosed cybersecurity vulnerabilities. Managed by ENISA under the NIS2 Directive, the database provides information on security flaws affecting software and hardware products, assigns EUVD identifiers, references CVE entries where applicable, and supports vulnerability management, risk assessment, and timely remediation for organisations across Europe.
- Introductory Courses to Cybersecurity
The Fundamentals of Cybersecurity (NERO)
- Published date:
- Author: NERO project
The Fundamentals of Cybersecurity (NERO) is a free, self-paced training module that introduces the core principles of cybersecurity for SMEs. The course covers cybersecurity domains, risk assessment, security frameworks, standards, compliance, threat landscapes, and emerging technologies, while promoting practical security hygiene and cybersecurity awareness through lectures, demonstrations, quizzes, and real-world examples. It equips learners with the knowledge needed to identify common cyber risks, apply fundamental security practices, and contribute to a stronger organisational security culture.
- Introductory Courses to Cybersecurity
CYRUS Cybersecurity Training Catalogue
- Published date:
- Author: CYRUS - Enhanced Cybersecurity Skills project
The CYRUS Cybersecurity Training Catalogue provides free online cybersecurity training courses covering topics such as cybersecurity fundamentals, incident response, phishing awareness, social engineering, password security, cybersecurity culture, and human behaviour. Designed for professionals across different sectors and skill levels, the platform offers self-paced e-learning resources that help learners improve their ability to identify, prevent, and respond to cyber threats in the workplace.
- Application Security
File Inclusion Vulnerabilities: Hands-on Web Application Security Module
- Published date:
- Author: Hack The Box Academy
This module introduces file inclusion vulnerabilities in web applications, including Local File Inclusion, Remote File Inclusion, path traversal, PHP filters and wrappers, log poisoning, malicious file uploads, and exploitation paths leading to remote code execution. Through practical exercises and a skills assessment, learners develop hands-on offensive security skills while also learning prevention techniques. The module is designed for learners with basic knowledge of Linux, networking, web requests, and information security fundamentals.
- Compliance Standards
Technical Competence Requirements for Cyber Resilience Act (CRA) Notified Bodies
- Published date:
- Author: European Union Agency for Cybersecurity (ENISA)
This ENISA publication outlines the high-level technical competence requirements for Conformity Assessment Bodies (CABs) seeking designation as Notified Bodies under the EU Cyber Resilience Act (CRA). The document focuses on the knowledge, experience, training, and auditing capabilities required for personnel involved in evaluating the cybersecurity conformity of products. It provides guidance for developing qualified assessment teams and supports the consistent implementation of CRA certification and conformity assessment processes across the European Union.