EU Regulation 2024/2847
Cyber Resilience Act for Networked Lighting Equipment
A practical CRA briefing for lighting equipment manufacturers, system integrators, and technicians working with IP-based control networks.
What the CRA changes for lighting
The Cyber Resilience Act is binding EU law for products with digital elements. For the lighting industry, that means networked consoles, gateways, nodes, fixtures, drivers, wireless DMX devices, media servers, and architectural controllers need documented cybersecurity design, vulnerability handling, and conformity evidence.
The three CRA deadlines
The September 2026 reporting deadline arrives before the full December 2027 product compliance date, so manufacturers need operational processes before every product redesign is finished.
11 December 2027
Full CRA application
New products with digital elements placed on the EU market must meet CRA requirements. Stamping "CE" on a product from this date onwards means you've cared about cybersecurity, and have conformity evidence.
New products placed on the EU market
Which lighting products are in scope?
In practical lighting terms, a product is likely in scope when it has a direct or indirect logical or physical data connection to another device or network. Purely analogue products and DMX 5-pin only products with no other data connection are usually outside this scope.
What manufacturers and technicians need to know
Product categories and assessment routes
The CRA uses four tiers. Most entertainment lighting products are expected to fall into Default or Important Class I, but the route depends on product functionality and whether harmonised standards are fully applied.
| Tier | Assessment route | What it means | Likely lighting examples |
|---|---|---|---|
| Default | Self-assessment under Module A. | Manufacturer prepares the technical file, Declaration of Conformity, and CE marking evidence internally. | Most standalone fixtures, basic Ethernet-enabled drivers, simple nodes. |
| Important - Class I | Self-assessment is possible only when relevant harmonised standards are fully applied; otherwise a notified body is required. | More documentation discipline and a stronger standards position are needed. | Consoles and more complex gateways may land here depending on features. |
| Important - Class II | Mandatory third-party conformity assessment. | Plan notified body availability, cost, and review time early. Prices for products belonging to this tier will rise. | Unknown as of now. |
| Critical | Mandatory third-party assessment under a stricter regime. | Products belonging to this tier are expected to become a lot more costly. | Unknown as of now. We do not expect any lighting equipment will fall under this tier. |
Vulnerability reporting starts first
From 11 September 2026, manufacturers must report actively exploited vulnerabilities and severe incidents through the ENISA Single Reporting Platform and the relevant national authority.
| Step | Trigger | Deadline | Content required |
|---|---|---|---|
| Early warning | Actively exploited vulnerability | Within 24 hours after the manufacturer becomes aware | Basic notice that exploitation is occurring. |
| Detailed notification | Same actively exploited vulnerability | Within 72 hours | Technical details of the vulnerability. |
| Final vulnerability report | Patch or mitigation available | Within 14 days after the patch or mitigation | Full report including remediation. |
| Severe incident final report | Incident with significant impact on product security | Early warning within 24 hours; final report within 30 days | Incident report through the same reporting route. |
Core technical obligations
Why Art-Net, sACN, and RDM need special attention
Art-Net, sACN, and RDM were designed for trusted lighting networks. The CRA does not ban these protocols, but manufacturers need a documented risk assessment explaining why their implementation is appropriate for the product's intended deployment and threat model.
Sig-Net and the industry's response
Sig-Net is an emerging authentication and integrity framework for lighting networks. It can be relevant evidence in a CRA risk assessment, but it is not a certification by itself. Manufacturers still need product-specific documentation and conformity evidence.
QubiCore implements Sig-Net, giving lighting manufacturers a concrete implementation path for authentication and message integrity in networked lighting products.
Penalties and market access
Non-compliance with essential cybersecurity requirements can lead to fines of up to EUR 15,000,000 or 2.5% of total global annual turnover, whichever is higher. Market surveillance authorities can also restrict, withdraw, or recall products from the EU market.
CRA questions for lighting teams
Short answers to the questions manufacturers and lighting technicians are already asking.
No. The CRA does not name or prohibit these protocols. The issue is whether the manufacturer can document why the implementation is secure enough for the product's intended deployment and threat model.
No. The full application date applies to products newly placed on the EU market after 11 December 2027. Products sold before that date do not need to comply to CRA unless they get a software update that is changing the security implications of the product.
Start with a product inventory, identify every product with a data connection, document the intended deployment context, and establish vulnerability handling before the September 2026 reporting obligations begin.
Technicians themselves are not affected by CRA directly. However, they can expect more emphasis by manufacturers on updateable equipment, credentials, network segmentation, support lifetime, and clear instructions for secure installation and operation. Due to the overhead caused by CRA, prices for equipment may rise.
Read more about networked lighting
Related articles that explain the protocols affected by CRA risk assessments.
Building CRA-ready lighting products?
QubiCast builds networking tools for professional lighting systems and helps manufacturers think through protocol behavior, monitoring, and lifecycle requirements.
Contact QubiCastThis page is technical orientation for lighting teams and is not legal advice.



