TRA Studio
All example documents

Fictitious example. ACME Embedded GmbH, its products, records and document IDs are invented for illustration. Use this as a structural model, not as a template to adopt unchanged — and not as legal advice.

SDL-CHK-030 — Secure-by-Design / Secure-by-Default Release Checklist

Document IDSDL-CHK-030, rev. 1.2
Applies atSecurity release gate (SDL-POL-001, Phase 5)
ReferenceCRA Annex I Part I, esp. I(2)(3): product minimises attack surface without end-user configuration
Completed forProduct: Gateway G50 · Firmware: 1.0.0 · Date: 2026-06-24
Completed byQA Engineer (Verification Lead)
Approved byProduct Security Lead

Rule: the checklist is completed against the factory-default configuration as shipped, on a production-fused unit — not a development build. Every "No" requires either a fix before release or a documented, PSL-approved risk acceptance.


A. Attack surface — as shipped

#CheckResultEvidence
A1Attack Surface Document (ports, services, radio interfaces, physical interfaces) updated for this releaseYesASD-G50 rev. 1.0
A2Only services required for intended use are enabled by default (nmap scan of factory-default unit matches ASD)YesScan report REL-DOS-2026-007/scan.txt
A3JTAG/SWD debug access disabled or locked on production fusesYesFuse config report, sample of 3 units
A4UART console: no unauthenticated shell in production imageYesBoot log capture
A5Unused radio protocols disabled (e.g. BLE advertising off unless commissioning)YesRF test protocol

B. Credentials and access — as shipped

#CheckResultEvidence
B1No universal default password: first-boot forces per-device credential setup, or per-device unique credential printed on labelYesFirst-boot flow test video
B2No hard-coded credentials or keys in firmware image (binary scan)YesScan report
B3Web UI/API sessions: authentication required for all non-commissioning endpointsYesAPI test suite run
B4Account lockout / rate limiting active by defaultYesTest case TC-SEC-14

C. Communication and data — default configuration

#CheckResultEvidence
C1TLS enabled by default for cloud/companion communication; plaintext fallback not silently acceptedYesWireshark capture
C2Certificate validation on by default (no verify=off in shipped config)YesConfig diff
C3Data minimisation: only data required for intended function transmitted by default; telemetry opt-inYesData-flow sheet

D. Updates and recovery — default configuration

#CheckResultEvidence
D1Secure update mechanism enabled by default (signed images, rollback protection)YesUpdate test protocol
D2Automatic security updates on by default, with documented opt-outNo
D3Device recoverable to a secure state after failed updateYesPower-cut update test
D4Factory reset removes user data and credentialsYesTC-SEC-22

D2 deviation record: Automatic updates are opt-in for G50 1.0.0 because target installations (industrial commissioning environments) require controlled maintenance windows; unattended reboots create availability risk for the intended use. Mitigation: prominent update notification in UI and via companion app; risk acceptance RA-2026-004 approved by PSL 2026-06-24; re-evaluate for FW 1.1.

E. Sign-off

The factory-default configuration of the product as shipped provides the security properties above without requiring configuration by the end user, with the documented deviation D2.

Verification Lead: (signed) — Product Security Lead: (signed) — Date: 2026-06-24

Completed checklist is filed in the release conformity dossier (REL-DOS-2026-007) and referenced by the Release Gate Record.