Generate your checklist based on the previous steps. Indicate which items apply and add notes where needed.
Check which policy components and processes you have or plan to implement.
Build security in from the start: apply secure-by-design and secure-by-default principles across the product life cycle — secure defaults, a minimal attack surface, timely security updates and structured vulnerability handling. See ENISA's Secure by Design and Default Playbook for practical guidance. These principles underpin the CRA essential requirements (Annex I).