Skip to content

The CRA doesn't only happen on bad days.

A vulnerability incident might come once or twice a year. Questions about how you handle them come every month: from retailers, buyers, auditors and your own board. VexRoute keeps the answer ready, because the evidence builds up as your factories respond.
An illustrative CRA yearTwelve months on a line. Only one stop is a vulnerability incident. The others are questionnaires, tenders, supplier changes, firmware releases and audits, each needing the same evidence.JanFebMarAprMayJunJulAugSepOctNovDecRetailer questionnairePublic tenderODM swaps a chipsetFirmware 4.3 shipsChipset CVENotified Body review

Who asks, what they ask, and what you'll have ready

The same underlying record answers very different questions. You stop rebuilding it from inboxes each time someone asks.

Retailers and marketplaces

“List every connected product you sell us, its firmware version, and your vulnerability handling process.”

Ready in VexRoute

An export of SKUs, current firmware families and versions, linked suppliers and your answer history, filtered to the products that retailer stocks.

Public and enterprise tenders

“Describe how you obtain vulnerability information from your manufacturing partners, with evidence.”

Ready in VexRoute

A live record of the channel itself: which ODMs are connected, how quickly they've answered, and the trail behind recent questions.

Auditors and market surveillance

“Show us what you knew about this vulnerability, when you knew it, and what you did.”

Ready in VexRoute

A timestamped sequence for every incident: question raised, factory answer, versions affected, packet prepared, fix released.

Notified Bodies

“Provide evidence of your vulnerability handling for products assessed under the CRA.”

Ready in VexRoute

Per-product evidence tied to firmware families, VEX statements and SBOM links, ready to support your technical documentation for important and critical product classes.

Your own leadership and insurers

“Where are we exposed if one of our factories has a bad month?”

Ready in VexRoute

A view of how much of your range depends on each ODM and each firmware family, and how responsive each supplier has been.

The issues that happen between incidents

Supply chains move. These are the changes that quietly break a CRA evidence trail, and how VexRoute keeps it intact.
Supplier changes
A factory swaps a Wi-Fi module, moves a product to a new chipset, or you move production to a second ODM. VexRoute records the change against the SKU and firmware family, so the next question goes to the right factory about the right code.
Firmware updates
New versions ship constantly. Factories log releases per family, with what they fix, so you can prove which version was in the field on any given date and which vulnerabilities each one closed.
End-of-support periods
The CRA expects a support period that reflects how long the product is expected to be used, generally at least five years. VexRoute keeps the support end date for each family visible, and flags SKUs approaching it, so commitments to customers match what the factory will actually maintain.
New SKUs on old firmware
A new product launched on an existing family inherits its history immediately: every past question, answer and VEX statement, from day one.
Contacts who leave
The engineer who answered last time moves on. The channel doesn't depend on one person's inbox. The factory's workspace, history and obligations stay where they are.
Agents in the middle
When a sourcing agent sits between you and the factory, they can be part of the route rather than a place where questions disappear.

One record, always current

This is what the trail looks like when you open it. Every row links back to the questions and answers behind it.
Illustrative evidence trail: each SKU linked to a firmware family, its ODM, and the latest VEX status
SKUFirmware familySupplierVEX statusLatest answer
CAM-210Indoor cameraIPC-T31 v4.2ODM A, ShenzhenFixedFirmware 4.2.7 shipped
CAM-220Doorbell cameraIPC-T31 v4.2ODM A, ShenzhenFixedSame family, same answer
SEN-04Door sensorZB-Lite 2.xODM B, DongguanNot affectedChipset not used
PLG-11Smart plugWB3S-Plug 1.9ODM C, ZhongshanUnder investigationAnswer due in 6 h
HUB-01Home hubLinux-GW 5.1ODM A, ShenzhenAffectedMitigation published
Illustrative data. Two cameras share one firmware family, so one factory answer covers both.

Getting ready for December 2027

From 11 December 2027 the CRA's main obligations apply: essential requirements, vulnerability handling processes, SBOMs, technical documentation and conformity assessment.

What the trail gives you now

A tested channel to every factory, a product-to-firmware map, and a record of how vulnerabilities were handled across your range. These are the raw materials for vulnerability handling and technical documentation.

What it doesn't replace

Your risk assessment, your secure-by-design work, and your consultant's advice on conformity. VexRoute feeds that work with supplier evidence. It doesn't do it for you.

Make CRA look handled before anyone asks.

Map your SKUs and factories with us, and your evidence trail starts building from day one.

Or write to menachem@vexroute.com.