Checklist

Secure by Default Checklist for CRA Compliance

CRA requires products to ship with the most restrictive secure defaults. Use this checklist to audit your product's default configuration.

March 2026 · 6 min read

What CRA Means by "Secure by Default"

CRA Annex I, §2: products must be delivered in most restrictive, secure configuration without user action.

Checklist

  • No shared default passwords
  • Debug mode disabled by default
  • Remote admin interfaces disabled
  • Unnecessary ports closed
  • TLS/HTTPS enforced
  • MFA enabled or prompted
  • Strict CSP headers
  • Telemetry opt-in, not opt-out
  • Auto security updates enabled
  • Session timeouts configured
  • Least-privilege access defaults
  • Verbose errors suppressed in production

Get the CRA deadline calendar

A one-page PDF showing every CRA date that matters for your product team. Free — no spam, unsubscribe anytime.

Related articles

Ready to Take Action?

Start your CRA compliance journey with our free assessment tool.