In line with the PG's recommendations, what should be the minimum requirements for a secure Arch Linux installation?

It was listed as a DIY distribution, primarily because of Reproducible Builds as a way to reduce the risk of supply chain based attacks, for that reason NixOS is listed also.

For desktop, the main reason we recommend Fedora, is because it’s fairly secure by default, and comes with some default policies. Of course no distribution has extensively hardened policies, although there is an aim to improve that with the ConfinedUsers SIG.