Twenty-four hours to answer for firmware you didn't write.
What the CRA asks of you
24 hours
Early warning
Within 24 hours of becoming aware of an actively exploited vulnerability, notify the CSIRT designated as coordinator and ENISA via the single reporting platform, including the member states where the product is available.
72 hours
Vulnerability notification
Within 72 hours, unless already provided, a notification with general information about the product, the nature of the exploit and the vulnerability, and corrective or mitigating measures taken or that users can take.
14 days
Final report
No later than 14 days after a corrective or mitigating measure is available, a final report describing the vulnerability, its severity and impact, any known malicious actor, and the security update or other measures made available.
The trigger is awareness: the clock starts when the manufacturer becomes aware of an actively exploited vulnerability in its product. Reports go through the single reporting platform run by ENISA, to the CSIRT designated as coordinator in the member state of your main establishment, and to ENISA. Severe incidents that affect the security of your product follow the same 24-hour and 72-hour pattern.
And it isn't only for new products. Reporting applies to everything in scope that's already on the market, years before the rest of the CRA's obligations arrive in December 2027.
Your logo on the box makes you the manufacturer.
That's the normal model for most European consumer and prosumer electronics. A brand in Amsterdam or Munich specifies the product, the ODM in Shenzhen or Dongguan supplies a design built on a chipset vendor's SDK or a platform like Tuya, and the firmware is maintained by the factory's R&D team.
The brand owns the CRA duty. The factory owns the knowledge. Nothing in between connects the two at the speed the law now expects.
Product categories where this bites hardest
- Smart-home cameras
- Door and window sensors
- Kids' smartwatches
- Pet and GPS trackers
- Android TV boxes
- 5G CPE and routers
- Wearables
- Smart plugs and lighting
The supply-chain blind spot
- SKUs hide shared firmware
- Five products with five names can run one firmware family. When a CVE lands, you need to know that in minutes, not discover it from the factory a week later.
- Shared platforms multiply exposure
- A vulnerability in a popular chipset SDK or IoT platform touches every brand built on it at once. Your exposure is set by decisions made two or three suppliers upstream.
- Contacts are commercial, not technical
- The person you buy from is in sales. The person who knows whether the vulnerable function is compiled in sits in R&D, and has never heard of you.
- Records live in inboxes
- Which firmware shipped in which batch, and what the factory said about the last vulnerability, is scattered across email threads, chat apps and spreadsheets.
The ODM flood
sales@factory-example.cn
23 unread
Brand in Amsterdam
09:12 CET
Are our cameras affected by the new Wi-Fi chipset CVE? Legal needs an answer today.
Brand in Lyon
09:40 CET
Please fill in the attached spreadsheet for every SKU you supply to us.
Importer in Munich
10:05 CET
Which firmware versions are we running? Is there a patch date?
Brand in Madrid
11:30 CET
Re: Re: Fwd: urgent security question, see thread below
Brand in Warsaw
13:15 CET
Our CRA consultant says we must report within 24 hours. Please confirm status.
Brand in Milan
16:50 CET
Following up again. Is anyone on your side handling this?
同一个问题,二十三种格式。工厂在深圳时间晚上才看到。The same question in twenty-three formats. The factory sees it in the Shenzhen evening.
A mid-sized ODM may supply dozens of European brands from a handful of firmware families. Each customer sends its own spreadsheet, its own wording, its own deadline. Some write in English, some through a sourcing agent, some through a chat app. Most arrive overnight, Shenzhen time.
The factory's engineers end up answering the same question dozens of times, and sales becomes a relay desk. Every hour spent reformatting the same answer is an hour not spent on the fix.
Factories that handle this well will win European business. Factories that don't will be quietly replaced by ones that can show a working CRA response process.
The cost of silence
- Regulatory exposureCRA penalties
- For breaches of the essential requirements and manufacturer obligations, including reporting, fines can reach €15 million or 2.5% of total worldwide annual turnover, whichever is higher.
- Market accessMarket surveillance
- Authorities can require corrective action, restrict a product or have it withdrawn from the market. For a product line built around one ODM, that can hit a whole range at once.
- Retail and procurementCommercial
- Retailers, marketplaces and public buyers increasingly ask how you handle vulnerabilities in products you don't manufacture yourself. 'We emailed the factory' isn't an answer that wins listings or tenders.
- Wasted time on both sidesOperational
- Compliance teams chase. Factory engineers repeat themselves. Consultants spend billable hours on email follow-ups instead of the advice their clients pay for.
The CRA dates that matter
The CRA enters into force
Regulation (EU) 2024/2847 is published and the transition clock starts for every product with digital elements sold in the EU.
Conformity assessment bodies
Rules for notifying conformity assessment bodies apply, so Notified Bodies can be designated ahead of the main obligations.
in force now
Reporting obligations apply
Manufacturers must report actively exploited vulnerabilities and severe incidents through the single reporting platform: an early warning within 24 hours, a notification within 72 hours, then a final report. This covers products already on the market.
Main obligations apply
Essential cybersecurity requirements, vulnerability handling, technical documentation, SBOMs, conformity assessment and CE marking all become mandatory for products placed on the EU market.
The fix is a channel, not more email.
The answer already exists once, inside the factory. What's missing is a route that gets it to every brand that needs it, in a form each brand can report from, and a record that proves it happened. That's what VexRoute is.
Be ready before the next advisory lands.
Map your SKUs, connect your factories and have a working CRA response channel in place. Talk to us about your range and we'll show you VexRoute on your own products.
Or write to menachem@vexroute.com.

