Skip to content

Questions, answered plainly.

The CRA, the factory channel and how VexRoute fits between them. If your question isn't here, email menachem@vexroute.com.

The Cyber Resilience Act

We don't make the firmware. Does the CRA still apply to us?

Usually, yes. If you place a product with digital elements on the EU market under your own name or trademark, the CRA treats you as the manufacturer, even if an ODM designed and built it. Importers and distributors have their own obligations too. Your CRA consultant or legal counsel should confirm your role for each product line.

What exactly has to happen within 24 hours?

From 11 September 2026, once a manufacturer becomes aware of an actively exploited vulnerability in its product, it must send an early warning within 24 hours to the CSIRT designated as coordinator and to ENISA, through the single reporting platform. A fuller vulnerability notification follows within 72 hours, and a final report no later than 14 days after a fix or mitigation is available. Severe incidents follow a similar 24-hour and 72-hour pattern, with a final report within one month.

Does reporting apply to products we already sell?

Yes. The reporting obligations apply to products with digital elements in scope that were placed on the market before 11 December 2027, not only to new ones. That's why the ODM channel matters now, for the catalogue you already have on shelves.

What are the penalties?

For breaches of the essential requirements and the manufacturer obligations, including reporting, fines can reach €15 million or 2.5% of total worldwide annual turnover, whichever is higher. Market surveillance authorities can also restrict or withdraw products.

How VexRoute works

What is VEX?

VEX stands for Vulnerability Exploitability eXchange. It's a structured statement saying whether a product is affected by a specific vulnerability: not affected, affected, fixed or under investigation, with a justification. VexRoute collects these statements from the factory once per firmware family and routes them to every brand that ships that firmware.

Does VexRoute file the report to ENISA for us?

No. You stay the manufacturer and you submit the report. VexRoute starts the CRA clock when the factory's answer arrives and gives you a pre-filled packet for the 24-hour early warning and the 72-hour notification, with the affected SKUs, firmware versions and the factory's mitigation details already in place. You review it, adjust it and submit it.

Can one brand see another brand's products?

No. The factory answers once per firmware family, but each brand only sees its own SKUs, its own questions and its own evidence. The factory sees which of its customers are linked to a family so it can answer with confidence.

Do we need an SBOM to start?

No. You can start by mapping SKUs to firmware families and suppliers. Where an SBOM exists, VexRoute links it to the firmware family so statuses can be tied to components. SBOMs become a CRA requirement from December 2027, so the trail you build now carries straight into that work.

Is VexRoute a replacement for our CRA consultant?

No, and it's not designed to be. Consultants own the advice, the risk assessment, the processes and audit readiness. VexRoute owns the ODM channel and the evidence pipe underneath. That makes VexRoute easy for consultants to bring to their clients.

For factories

Why would a factory use VexRoute?

Because it replaces dozens of duplicate questions with one. Instead of answering every customer's spreadsheet and email thread, the factory answers once per firmware family in Chinese or English. The answer reaches every linked brand automatically, and the factory can show EU customers a CRA-ready response process.

Does the factory have to share its customer list or source code?

No. The factory only answers questions about firmware families it already supplies. Brands link themselves to the families they buy. No source code is required, and customers never see each other.

Pricing and onboarding

How is VexRoute priced?

By the number of firmware families you track and the supplier connections you need, never per incident. A bad week of CVEs shouldn't cost you more.

How does onboarding work?

Our team runs it with you. We map your SKUs to firmware families and factories from the data you already have, usually a spreadsheet, bring your ODMs into their bilingual workspace, and run a first question end to end before you go live.

This page explains the CRA in general terms. It isn't legal advice. Confirm your obligations with your CRA consultant or legal counsel.

Be ready before the next advisory lands.

Map your SKUs, connect your factories and have a working CRA response channel in place. Talk to us about your range and we'll show you VexRoute on your own products.

Or write to menachem@vexroute.com.