You sell it. Under the CRA, you made it.
What changes once you're on VexRoute
- You know which firmware every SKU runs, and who maintains it
- A new CVE becomes one question to the factory, not twenty threads
- You can meet the 24-hour early warning with real information
- Retailers, tenders and auditors get evidence, not promises
Three teams, one source of truth
Compliance and legal
Needs to know, fast, whether to report.
- Affected SKUs and versions, straight from the factory
- A visible CRA clock from awareness
- A pre-filled packet for the 24 h and 72 h reports
- A trail to show auditors what happened
Product and engineering
Needs to know what runs where.
- A map of SKUs to firmware families and ODMs
- Release history per family
- Support end dates that match what the factory maintains
- VEX statuses and SBOM links per family
Purchasing and sourcing
Needs suppliers that can keep up.
- One channel to every factory, not one inbox per buyer
- A view of how responsive each ODM has been
- CRA response as part of supplier conversations
- Evidence for retailer and tender questionnaires
When a vulnerability hits your range
- Hour zero
- An advisory for a chipset, SDK or platform appears. VexRoute shows which of your firmware families might be exposed, and which factories maintain them.
- Within hours
- Each factory gets one bilingual question. Their R&D team answers per firmware family, and the answer lands against your SKUs, alongside every other brand on that family.
- Before 24 hours
- If a product is affected and the vulnerability is actively exploited, your early-warning packet is already drafted with the factory's details. You review and submit.
- By 72 hours and after
- The factory's updates flow into the notification draft and the final report. The full sequence is kept as evidence.
And every other week of the year
Supplier changes, firmware releases and end-of-support dates are recorded as they happen. When a retailer sends a security questionnaire or a tender asks how you manage vulnerabilities in outsourced products, you export the answer instead of assembling it.
How brands get started
Step 1: A 20-minute call
We learn your product range, your factories and where CRA work sits in your organisation today.Step 2: Map a first slice
Pick a product line. We map its SKUs to firmware families and ODMs with you, from whatever data you already have.Step 3: Invite your factories
We help introduce VexRoute to your ODMs in Chinese and English, and explain what's in it for them.Step 4: Run a real question
Send a first vulnerability question through the channel, see the answer routed back, and decide what to expand next.
Already working with a CRA consultant?
Good. Keep them. VexRoute is built to sit underneath consultants: they own the advice, the risk assessment and audit readiness, and VexRoute supplies the factory channel and the evidence they need to do that work well. Bring them to the first call.
Questions brands ask
We don't make the firmware. Does the CRA still apply to us?
Usually, yes. If you place a product with digital elements on the EU market under your own name or trademark, the CRA treats you as the manufacturer, even if an ODM designed and built it. Importers and distributors have their own obligations too. Your CRA consultant or legal counsel should confirm your role for each product line.
Does reporting apply to products we already sell?
Yes. The reporting obligations apply to products with digital elements in scope that were placed on the market before 11 December 2027, not only to new ones. That's why the ODM channel matters now, for the catalogue you already have on shelves.
Does VexRoute file the report to ENISA for us?
No. You stay the manufacturer and you submit the report. VexRoute starts the CRA clock when the factory's answer arrives and gives you a pre-filled packet for the 24-hour early warning and the 72-hour notification, with the affected SKUs, firmware versions and the factory's mitigation details already in place. You review it, adjust it and submit it.
Can one brand see another brand's products?
No. The factory answers once per firmware family, but each brand only sees its own SKUs, its own questions and its own evidence. The factory sees which of its customers are linked to a family so it can answer with confidence.
Do we need an SBOM to start?
No. You can start by mapping SKUs to firmware families and suppliers. Where an SBOM exists, VexRoute links it to the firmware family so statuses can be tied to components. SBOMs become a CRA requirement from December 2027, so the trail you build now carries straight into that work.
Be ready before the next advisory lands.
Map your SKUs, connect your factories and have a working CRA response channel in place. Talk to us about your range and we'll show you VexRoute on your own products.
Or write to menachem@vexroute.com.

