Skip to content

You sell it. Under the CRA, you made it.

If your name is on a connected product sold in the EU, the Cyber Resilience Act treats you as the manufacturer, even if an ODM in Shenzhen designed it and maintains its firmware. VexRoute gives you the factory channel that responsibility needs.

What changes once you're on VexRoute

  • You know which firmware every SKU runs, and who maintains it
  • A new CVE becomes one question to the factory, not twenty threads
  • You can meet the 24-hour early warning with real information
  • Retailers, tenders and auditors get evidence, not promises

Three teams, one source of truth

CRA work lands on several desks at once. VexRoute gives each of them the view they need from the same underlying record.

Compliance and legal

Needs to know, fast, whether to report.

  • Affected SKUs and versions, straight from the factory
  • A visible CRA clock from awareness
  • A pre-filled packet for the 24 h and 72 h reports
  • A trail to show auditors what happened

Product and engineering

Needs to know what runs where.

  • A map of SKUs to firmware families and ODMs
  • Release history per family
  • Support end dates that match what the factory maintains
  • VEX statuses and SBOM links per family

Purchasing and sourcing

Needs suppliers that can keep up.

  • One channel to every factory, not one inbox per buyer
  • A view of how responsive each ODM has been
  • CRA response as part of supplier conversations
  • Evidence for retailer and tender questionnaires

When a vulnerability hits your range

Without a channel, the first day goes on finding out who to ask. With VexRoute, it goes on deciding what to report.
Hour zero
An advisory for a chipset, SDK or platform appears. VexRoute shows which of your firmware families might be exposed, and which factories maintain them.
Within hours
Each factory gets one bilingual question. Their R&D team answers per firmware family, and the answer lands against your SKUs, alongside every other brand on that family.
Before 24 hours
If a product is affected and the vulnerability is actively exploited, your early-warning packet is already drafted with the factory's details. You review and submit.
By 72 hours and after
The factory's updates flow into the notification draft and the final report. The full sequence is kept as evidence.

And every other week of the year

Most of the time, VexRoute is quietly keeping the record that makes CRA look handled.

Supplier changes, firmware releases and end-of-support dates are recorded as they happen. When a retailer sends a security questionnaire or a tender asks how you manage vulnerabilities in outsourced products, you export the answer instead of assembling it.

See everything VexRoute covers between incidents

How brands get started

We keep onboarding light. A spreadsheet of SKUs and suppliers is enough to begin.
  1. Step 1: A 20-minute call

    We learn your product range, your factories and where CRA work sits in your organisation today.
  2. Step 2: Map a first slice

    Pick a product line. We map its SKUs to firmware families and ODMs with you, from whatever data you already have.
  3. Step 3: Invite your factories

    We help introduce VexRoute to your ODMs in Chinese and English, and explain what's in it for them.
  4. Step 4: Run a real question

    Send a first vulnerability question through the channel, see the answer routed back, and decide what to expand next.

Already working with a CRA consultant?

Good. Keep them. VexRoute is built to sit underneath consultants: they own the advice, the risk assessment and audit readiness, and VexRoute supplies the factory channel and the evidence they need to do that work well. Bring them to the first call.

How we work with consultants

Questions brands ask

We don't make the firmware. Does the CRA still apply to us?

Usually, yes. If you place a product with digital elements on the EU market under your own name or trademark, the CRA treats you as the manufacturer, even if an ODM designed and built it. Importers and distributors have their own obligations too. Your CRA consultant or legal counsel should confirm your role for each product line.

Does reporting apply to products we already sell?

Yes. The reporting obligations apply to products with digital elements in scope that were placed on the market before 11 December 2027, not only to new ones. That's why the ODM channel matters now, for the catalogue you already have on shelves.

Does VexRoute file the report to ENISA for us?

No. You stay the manufacturer and you submit the report. VexRoute starts the CRA clock when the factory's answer arrives and gives you a pre-filled packet for the 24-hour early warning and the 72-hour notification, with the affected SKUs, firmware versions and the factory's mitigation details already in place. You review it, adjust it and submit it.

Can one brand see another brand's products?

No. The factory answers once per firmware family, but each brand only sees its own SKUs, its own questions and its own evidence. The factory sees which of its customers are linked to a family so it can answer with confidence.

Do we need an SBOM to start?

No. You can start by mapping SKUs to firmware families and suppliers. Where an SBOM exists, VexRoute links it to the firmware family so statuses can be tied to components. SBOMs become a CRA requirement from December 2027, so the trail you build now carries straight into that work.

Be ready before the next advisory lands.

Map your SKUs, connect your factories and have a working CRA response channel in place. Talk to us about your range and we'll show you VexRoute on your own products.

Or write to menachem@vexroute.com.