A vendor should set up, and make public, a way for outside parties to send it vulnerability reports, usually one dedicated email address or web form acting as the single point of entry, easy to locate and named in the disclosure policy. The UK PSTI regulations make publishing how to reach this mechanism, in English, free of charge, without prior request and without asking for personal data, part of a deemed-compliance route for consumer connectable products; the CRA harmonized-standard draft treats the clause as its capability-to-receive-reports requirement, and ISO/IEC 30111 6.5.3.3 gives the PSIRT the job of building that entry point.
This control maps to 2 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.