Skip to content

Twenty-four hours to answer for firmware you didn't write.

The EU Cyber Resilience Act made vulnerability reporting a legal duty with a stopwatch attached. For European brands selling connected electronics built by ODMs in China, the information needed to start that stopwatch sits in someone else's factory, in someone else's language, eight time zones away.
Seven brands sending the same question to one factory inboxone inbox

What the CRA asks of you

Regulation (EU) 2024/2847 covers almost every product with digital elements sold in the EU: anything with firmware, a radio, an app or a cloud connection. Its reporting rules have applied since 11 September 2026.

24 hours

Early warning

Within 24 hours of becoming aware of an actively exploited vulnerability, notify the CSIRT designated as coordinator and ENISA via the single reporting platform, including the member states where the product is available.

72 hours

Vulnerability notification

Within 72 hours, unless already provided, a notification with general information about the product, the nature of the exploit and the vulnerability, and corrective or mitigating measures taken or that users can take.

14 days

Final report

No later than 14 days after a corrective or mitigating measure is available, a final report describing the vulnerability, its severity and impact, any known malicious actor, and the security update or other measures made available.

The trigger is awareness: the clock starts when the manufacturer becomes aware of an actively exploited vulnerability in its product. Reports go through the single reporting platform run by ENISA, to the CSIRT designated as coordinator in the member state of your main establishment, and to ENISA. Severe incidents that affect the security of your product follow the same 24-hour and 72-hour pattern.

And it isn't only for new products. Reporting applies to everything in scope that's already on the market, years before the rest of the CRA's obligations arrive in December 2027.

Your logo on the box makes you the manufacturer.

Under the CRA, a company that places a product on the market under its own name or trademark carries the manufacturer's obligations, even if an ODM designed, built and maintains it.

That's the normal model for most European consumer and prosumer electronics. A brand in Amsterdam or Munich specifies the product, the ODM in Shenzhen or Dongguan supplies a design built on a chipset vendor's SDK or a platform like Tuya, and the firmware is maintained by the factory's R&D team.

The brand owns the CRA duty. The factory owns the knowledge. Nothing in between connects the two at the speed the law now expects.

Product categories where this bites hardest

  • Smart-home cameras
  • Door and window sensors
  • Kids' smartwatches
  • Pet and GPS trackers
  • Android TV boxes
  • 5G CPE and routers
  • Wearables
  • Smart plugs and lighting

The supply-chain blind spot

Ask a typical EU brand which firmware family each SKU runs, which chipset SDK sits underneath it, and which factory engineer can answer for it. Most can't say quickly. Not because they're careless, but because nothing ever required them to.
SKUs hide shared firmware
Five products with five names can run one firmware family. When a CVE lands, you need to know that in minutes, not discover it from the factory a week later.
Shared platforms multiply exposure
A vulnerability in a popular chipset SDK or IoT platform touches every brand built on it at once. Your exposure is set by decisions made two or three suppliers upstream.
Contacts are commercial, not technical
The person you buy from is in sales. The person who knows whether the vulnerable function is compiled in sits in R&D, and has never heard of you.
Records live in inboxes
Which firmware shipped in which batch, and what the factory said about the last vulnerability, is scattered across email threads, chat apps and spreadsheets.

The ODM flood

Now look at it from the factory's side. One advisory lands. Within hours, every customer asks the same question, each in its own format.

sales@factory-example.cn

23 unread

  • Brand in Amsterdam

    09:12 CET

    Are our cameras affected by the new Wi-Fi chipset CVE? Legal needs an answer today.

  • Brand in Lyon

    09:40 CET

    Please fill in the attached spreadsheet for every SKU you supply to us.

  • Importer in Munich

    10:05 CET

    Which firmware versions are we running? Is there a patch date?

  • Brand in Madrid

    11:30 CET

    Re: Re: Fwd: urgent security question, see thread below

  • Brand in Warsaw

    13:15 CET

    Our CRA consultant says we must report within 24 hours. Please confirm status.

  • Brand in Milan

    16:50 CET

    Following up again. Is anyone on your side handling this?

同一个问题,二十三种格式。工厂在深圳时间晚上才看到。The same question in twenty-three formats. The factory sees it in the Shenzhen evening.

Illustrative: one chipset advisory, one factory, every brand asking at once.

A mid-sized ODM may supply dozens of European brands from a handful of firmware families. Each customer sends its own spreadsheet, its own wording, its own deadline. Some write in English, some through a sourcing agent, some through a chat app. Most arrive overnight, Shenzhen time.

The factory's engineers end up answering the same question dozens of times, and sales becomes a relay desk. Every hour spent reformatting the same answer is an hour not spent on the fix.

Factories that handle this well will win European business. Factories that don't will be quietly replaced by ones that can show a working CRA response process.

The cost of silence

When the answer doesn't come, the brand is left with three bad options: report blind, report late, or don't report.
Regulatory exposureCRA penalties
For breaches of the essential requirements and manufacturer obligations, including reporting, fines can reach €15 million or 2.5% of total worldwide annual turnover, whichever is higher.
Market accessMarket surveillance
Authorities can require corrective action, restrict a product or have it withdrawn from the market. For a product line built around one ODM, that can hit a whole range at once.
Retail and procurementCommercial
Retailers, marketplaces and public buyers increasingly ask how you handle vulnerabilities in products you don't manufacture yourself. 'We emailed the factory' isn't an answer that wins listings or tenders.
Wasted time on both sidesOperational
Compliance teams chase. Factory engineers repeat themselves. Consultants spend billable hours on email follow-ups instead of the advice their clients pay for.

The CRA dates that matter

Reporting is already in force. Use the time before December 2027 to build the supply-chain evidence the rest of the regulation will demand.
  1. The CRA enters into force

    Regulation (EU) 2024/2847 is published and the transition clock starts for every product with digital elements sold in the EU.

  2. Conformity assessment bodies

    Rules for notifying conformity assessment bodies apply, so Notified Bodies can be designated ahead of the main obligations.

  3. in force now

    Reporting obligations apply

    Manufacturers must report actively exploited vulnerabilities and severe incidents through the single reporting platform: an early warning within 24 hours, a notification within 72 hours, then a final report. This covers products already on the market.

  4. Main obligations apply

    Essential cybersecurity requirements, vulnerability handling, technical documentation, SBOMs, conformity assessment and CE marking all become mandatory for products placed on the EU market.

The fix is a channel, not more email.

The answer already exists once, inside the factory. What's missing is a route that gets it to every brand that needs it, in a form each brand can report from, and a record that proves it happened. That's what VexRoute is.

Be ready before the next advisory lands.

Map your SKUs, connect your factories and have a working CRA response channel in place. Talk to us about your range and we'll show you VexRoute on your own products.

Or write to menachem@vexroute.com.