ISO/IEC 30111:2019
What is ISO/IEC 30111:2019?
ISO/IEC 30111 provides guidelines for the internal handling of reported potential vulnerabilities in products and online services. It covers the processes a vendor should follow from receiving a vulnerability report through remediation and advisory publication. It comprises 34 controls organised across 22 domains, published by ISO/IEC, and applies in International.
How ISO/IEC 30111:2019 maps to other frameworks
All 34 controls, each one mapped to the equivalent requirement in other standards, with the evidence that carries across and the mappings that were judged and rejected shown alongside. No account needed to look.
See the control mappings →The 22 domains ISO/IEC 30111:2019 groups its controls into
Where ISO/IEC 30111:2019 overlaps with the standards you already hold
What ISO/IEC 30111:2019 means in your sector
What ISO/IEC 30111:2019 means for your job
Questions people ask about ISO/IEC 30111:2019
What is ISO/IEC 30111:2019?
How many controls does ISO/IEC 30111:2019 have?
Where does ISO/IEC 30111:2019 apply?
What frameworks does ISO/IEC 30111:2019 map to?
How do I get started with ISO/IEC 30111:2019 compliance?
Query ISO/IEC 30111:2019 programmatically
ISO/IEC 30111:2019, its 34 controls and every mapping into other standards are available over a REST endpoint and an MCP server, so an agent can read them directly. The free tier is 10 calls a day and needs no signup.
ISO/IEC 30111:2019 API reference and MCP config →How ready are you for ISO/IEC 30111:2019?
Answer 25 questions and get a professional readiness report with gap analysis, maturity scores, and prioritised action items. Results in 5 minutes.