A networked hardware or software product engineered to meet the mandatory security requirements of the EU Cyber Resilience Act (CRA) before the December 2027 deadline. To be considered defensible: a product must feature a secure by design architecture that includes an authenticated transport layer for control data and management. Key components of a defensible product include a maintained Software Bill of Materials (SBOM): a documented risk assessment: and a verified process for reporting exploited vulnerabilities to ENISA within 24 hours. For manufacturers in the entertainment lighting sector: transitioning from unencrypted protocols to secure frameworks like Sig-Net is a critical step in creating a product that is legally defensible under EU law. QubiCast helps manufacturers reach this status through the QubiCore library: providing a secure stack that simplifies the documentation and technical requirements of the CRA.
QubiCast Glossary
CRA-defensible product
CRA-defensible product
Glossary
Related terms
Sig-Net
Sig-Net is a royalty-free secure communication framework designed to succeed Art-Net and sACN.
Security by Design / Default
Security by Design and Security by Default are CRA requirements that embed cybersecurity into development and ship products in the most secure configuration.
Related articles
Further reading selected in Strapi for this glossary entry

