News

Home
About Dahua

...

News

Dahua Technology Achieves ISO/IEC 29147 and ISO/IEC 30111 Certifications for Vulnerability Management

Dahua Technology Achieves ISO/IEC 29147 and ISO/IEC 30111 Certifications for Vulnerability Management

2026-09-18
Favourite

September 18, 2026 / Hangzhou, China. Dahua Technology, a world-leading video-centric AIoT solution and service provider, has recently achieved ISO/IEC 29147:2018 and ISO/IEC 30111:2019 certifications issued by BSI, marking international recognition of the company’s vulnerability disclosure and vulnerability handling practices.



The certifications demonstrate that Dahua has established a standardized, comprehensive, and effective vulnerability management and handling mechanism aligned with internationally recognized standards. They also reflect Dahua’s strong commitment to product security and responsible vulnerability management.


Internationally Recognized Standards for Vulnerability Management


ISO/IEC 29147:2018 and ISO/IEC 30111:2019 are cybersecurity-related standards jointly published by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC).


ISO/IEC 29147 focuses on vulnerability disclosure, providing guidance on how organizations receive vulnerability reports and communicate necessary information to relevant stakeholders. ISO/IEC 30111 focuses on vulnerability handling processes, covering key activities such as vulnerability verification, risk assessment, remediation, coordination, and continuous improvement.


Enhancing Vulnerability Management Capabilities


Focusing on product lifecycle security, Dahua upholds the vulnerability management principle of “proactive management and need-to-know disclosure”. The company has established a closed-loop vulnerability management mechanism covering vulnerability discovery, verification, remediation, disclosure, and continuous improvement.


Dahua Product Security Incident Response Team, known as Dahua PSIRT, is responsible for receiving, coordinating, handling, and disclosing security vulnerabilities related to Dahua products and solutions. Working closely with R&D, testing, product, delivery, and service teams, Dahua PSIRT helps ensure timely response and closed-loop resolution of potential security risks.


Dahua's Vulnerability Management and Response Process


Aligning with Global Regulatory Trends and Supporting Product Lifecycle Security


This achievement comes at a time when global cybersecurity regulatory requirements are continuing to evolve. The EU Cyber Resilience Act (CRA) introduces higher cybersecurity requirements for hardware and software products with digital elements, emphasizing security throughout the product lifecycle and requiring effective capabilities for vulnerability discovery, handling, remediation, disclosure, and security updates.


By achieving ISO/IEC 29147 and ISO/IEC 30111 certifications, Dahua has demonstrated that it has established a vulnerability management system aligned with international standards. This provides a solid foundation for the company to further enhance product security governance, improve vulnerability response efficiency, and support evolving international cybersecurity compliance requirements.


Looking Ahead


Security and trust are essential foundations for the long-term development of AIoT. Dahua will continue to strengthen its cybersecurity and privacy protection capabilities, integrate security requirements throughout the product lifecycle, and provide more secure and trustworthy products and services for users and the sustainable development of the AIoT industry.

More news