The CRA doesn't only happen on bad days.
Who asks, what they ask, and what you'll have ready
Retailers and marketplaces
“List every connected product you sell us, its firmware version, and your vulnerability handling process.”
Ready in VexRoute
An export of SKUs, current firmware families and versions, linked suppliers and your answer history, filtered to the products that retailer stocks.
Public and enterprise tenders
“Describe how you obtain vulnerability information from your manufacturing partners, with evidence.”
Ready in VexRoute
A live record of the channel itself: which ODMs are connected, how quickly they've answered, and the trail behind recent questions.
Auditors and market surveillance
“Show us what you knew about this vulnerability, when you knew it, and what you did.”
Ready in VexRoute
A timestamped sequence for every incident: question raised, factory answer, versions affected, packet prepared, fix released.
Notified Bodies
“Provide evidence of your vulnerability handling for products assessed under the CRA.”
Ready in VexRoute
Per-product evidence tied to firmware families, VEX statements and SBOM links, ready to support your technical documentation for important and critical product classes.
Your own leadership and insurers
“Where are we exposed if one of our factories has a bad month?”
Ready in VexRoute
A view of how much of your range depends on each ODM and each firmware family, and how responsive each supplier has been.
The issues that happen between incidents
- Supplier changes
- A factory swaps a Wi-Fi module, moves a product to a new chipset, or you move production to a second ODM. VexRoute records the change against the SKU and firmware family, so the next question goes to the right factory about the right code.
- Firmware updates
- New versions ship constantly. Factories log releases per family, with what they fix, so you can prove which version was in the field on any given date and which vulnerabilities each one closed.
- End-of-support periods
- The CRA expects a support period that reflects how long the product is expected to be used, generally at least five years. VexRoute keeps the support end date for each family visible, and flags SKUs approaching it, so commitments to customers match what the factory will actually maintain.
- New SKUs on old firmware
- A new product launched on an existing family inherits its history immediately: every past question, answer and VEX statement, from day one.
- Contacts who leave
- The engineer who answered last time moves on. The channel doesn't depend on one person's inbox. The factory's workspace, history and obligations stay where they are.
- Agents in the middle
- When a sourcing agent sits between you and the factory, they can be part of the route rather than a place where questions disappear.
One record, always current
| SKU | Firmware family | Supplier | VEX status | Latest answer |
|---|---|---|---|---|
| CAM-210Indoor camera | IPC-T31 v4.2 | ODM A, Shenzhen | Fixed | Firmware 4.2.7 shipped |
| CAM-220Doorbell camera | IPC-T31 v4.2 | ODM A, Shenzhen | Fixed | Same family, same answer |
| SEN-04Door sensor | ZB-Lite 2.x | ODM B, Dongguan | Not affected | Chipset not used |
| PLG-11Smart plug | WB3S-Plug 1.9 | ODM C, Zhongshan | Under investigation | Answer due in 6 h |
| HUB-01Home hub | Linux-GW 5.1 | ODM A, Shenzhen | Affected | Mitigation published |
Getting ready for December 2027
What the trail gives you now
A tested channel to every factory, a product-to-firmware map, and a record of how vulnerabilities were handled across your range. These are the raw materials for vulnerability handling and technical documentation.
What it doesn't replace
Your risk assessment, your secure-by-design work, and your consultant's advice on conformity. VexRoute feeds that work with supplier evidence. It doesn't do it for you.
Make CRA look handled before anyone asks.
Map your SKUs and factories with us, and your evidence trail starts building from day one.
Or write to menachem@vexroute.com.

