TL;DR: Teleport argues that the EU Cyber Resilience Act and ENISA’s secure-by-design playbook push infrastructure away from static credentials, standing privilege, and after-the-fact auditing toward cryptographic identity, deny-by-default access, and lifecycle governance for human, machine, and AI workloads. The compliance shift is that identity must be proven in architecture, not reconstructed after the fact, because review-based models no longer match how modern infrastructure operates.
Editorial analysis by NHI Mgmt Group, based on content published by Teleport: “How Teleport Operationalizes the EU Cyber Resilience Act's Secure-by-Design Mandate”.
Key questions
Q: What breaks when CRA infrastructure still relies on static credentials?
A: Static credentials undermine the CRA because they can be reused across systems long after the original task ends.
Q: Why do standing privileges create a higher access management risk?
A: Standing privileges increase risk because they remain available outside the task that justified them.
Q: How do teams know whether identity controls are actually CRA-ready?
A: Identity controls are CRA-ready when the system can show who or what accessed a resource, under what grant, for how long, and with what approval or policy basis.
Practitioner guidance
- Replace reusable credentials with short-lived identity Inventory SSH keys, API tokens, database passwords, and service secrets that still outlive a single task or session, then migrate the highest-risk paths to short-lived certificates or workload identities first.
- Enforce deny-first access for privileged paths Require explicit approval and resource scoping for all elevated access, and make denial the default for users, services, and processes that lack a current grant.
- Make access expiry automatic Set time-bounded access for administrative and operational tasks so the privilege disappears when the task ends, not when someone remembers to revoke it.
Bottom line: The article frames CRA compliance as an architecture problem where identity, privilege, and auditability must be enforced by the system itself.
What's in the full article
Teleport's full article covers the operational detail this post intentionally leaves for the source:
- Per-control mapping between CRA requirements and specific ENISA playbook principles
- Detailed examples of short-lived certificate issuance for SSH, Kubernetes, databases, and AI workloads
- Session recording and audit export mechanics for compliance evidence
- How access lists, SCIM, and lifecycle governance are structured across the stack
👉 Read Teleport's analysis of CRA identity controls for AI workloads →
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
CRA compliance is becoming an identity architecture test, not a documentation exercise. The article shows that the EU Cyber Resilience Act and ENISA guidance both assume security is built into defaults, not asserted in policy decks. That shifts the centre of gravity from audit narratives to enforceable access mechanics, which is exactly where IAM, PAM, and NHI governance converge. Practitioners should treat CRA readiness as a design question about how identity is issued, constrained, and revoked.
A few things that frame the scale:
- 67% of organisations still rely heavily on static credentials despite the risks they pose to agentic AI deployments, according to the 2026 Infrastructure Identity Survey.
- Organisations that rely heavily on static credentials reported a 20-percentage-point increase in security incidents compared with those with low reliance, according to the 2026 Infrastructure Identity Survey.
A question worth separating out:
Q: How should security teams govern AI and workload identities at runtime?
A: Security teams should govern runtime identities by combining least privilege, continuous telemetry, and approval-gated containment. The goal is not just to issue credentials safely, but to detect when those credentials are being used in ways that increase blast radius. Runtime governance should include scoped permissions, event correlation, and clear escalation thresholds.
👉 Read our full editorial: CRA secure-by-design demands new identity controls for AI workloads