What CRA Means by "Secure by Default"
CRA Annex I, §2: products must be delivered in most restrictive, secure configuration without user action.
Checklist
- No shared default passwords
- Debug mode disabled by default
- Remote admin interfaces disabled
- Unnecessary ports closed
- TLS/HTTPS enforced
- MFA enabled or prompted
- Strict CSP headers
- Telemetry opt-in, not opt-out
- Auto security updates enabled
- Session timeouts configured
- Least-privilege access defaults
- Verbose errors suppressed in production
Get the CRA deadline calendar
A one-page PDF showing every CRA date that matters for your product team. Free — no spam, unsubscribe anytime.
Related articles
Ready to Take Action?
Start your CRA compliance journey with our free assessment tool.