Fictitious example. ACME Embedded GmbH, its products, records and document IDs are invented for illustration. Use this as a structural model, not as a template to adopt unchanged — and not as legal advice.
SDL-CHK-030 — Secure-by-Design / Secure-by-Default Release Checklist
| Document ID | SDL-CHK-030, rev. 1.2 |
| Applies at | Security release gate (SDL-POL-001, Phase 5) |
| Reference | CRA Annex I Part I, esp. I(2)(3): product minimises attack surface without end-user configuration |
| Completed for | Product: Gateway G50 · Firmware: 1.0.0 · Date: 2026-06-24 |
| Completed by | QA Engineer (Verification Lead) |
| Approved by | Product Security Lead |
Rule: the checklist is completed against the factory-default configuration as shipped, on a production-fused unit — not a development build. Every "No" requires either a fix before release or a documented, PSL-approved risk acceptance.
A. Attack surface — as shipped
| # | Check | Result | Evidence |
|---|---|---|---|
| A1 | Attack Surface Document (ports, services, radio interfaces, physical interfaces) updated for this release | Yes | ASD-G50 rev. 1.0 |
| A2 | Only services required for intended use are enabled by default (nmap scan of factory-default unit matches ASD) | Yes | Scan report REL-DOS-2026-007/scan.txt |
| A3 | JTAG/SWD debug access disabled or locked on production fuses | Yes | Fuse config report, sample of 3 units |
| A4 | UART console: no unauthenticated shell in production image | Yes | Boot log capture |
| A5 | Unused radio protocols disabled (e.g. BLE advertising off unless commissioning) | Yes | RF test protocol |
B. Credentials and access — as shipped
| # | Check | Result | Evidence |
|---|---|---|---|
| B1 | No universal default password: first-boot forces per-device credential setup, or per-device unique credential printed on label | Yes | First-boot flow test video |
| B2 | No hard-coded credentials or keys in firmware image (binary scan) | Yes | Scan report |
| B3 | Web UI/API sessions: authentication required for all non-commissioning endpoints | Yes | API test suite run |
| B4 | Account lockout / rate limiting active by default | Yes | Test case TC-SEC-14 |
C. Communication and data — default configuration
| # | Check | Result | Evidence |
|---|---|---|---|
| C1 | TLS enabled by default for cloud/companion communication; plaintext fallback not silently accepted | Yes | Wireshark capture |
| C2 | Certificate validation on by default (no verify=off in shipped config) | Yes | Config diff |
| C3 | Data minimisation: only data required for intended function transmitted by default; telemetry opt-in | Yes | Data-flow sheet |
D. Updates and recovery — default configuration
| # | Check | Result | Evidence |
|---|---|---|---|
| D1 | Secure update mechanism enabled by default (signed images, rollback protection) | Yes | Update test protocol |
| D2 | Automatic security updates on by default, with documented opt-out | No | — |
| D3 | Device recoverable to a secure state after failed update | Yes | Power-cut update test |
| D4 | Factory reset removes user data and credentials | Yes | TC-SEC-22 |
D2 deviation record: Automatic updates are opt-in for G50 1.0.0 because target installations (industrial commissioning environments) require controlled maintenance windows; unattended reboots create availability risk for the intended use. Mitigation: prominent update notification in UI and via companion app; risk acceptance RA-2026-004 approved by PSL 2026-06-24; re-evaluate for FW 1.1.
E. Sign-off
The factory-default configuration of the product as shipped provides the security properties above without requiring configuration by the end user, with the documented deviation D2.
Verification Lead: (signed) — Product Security Lead: (signed) — Date: 2026-06-24
Completed checklist is filed in the release conformity dossier (REL-DOS-2026-007) and referenced by the Release Gate Record.
