To access ATO APIs and digital services a DSP registers in Online services for DSPs (with a myID credential and a RAM link), determines its category, completes the DSP OSF Security Questionnaire (one per product, or one for like products on the same infrastructure with a full product list mapped to the controls) and submits it with evidence for each control requirement; redacted evidence must still show the control is met; where a control does not apply the DSP explains why. A DSP applying the OSF across several products clearly states the differences between them, including different supply chain interactions, and gives supplementary evidence for known gaps. The DSP accepts the terms and conditions before whitelisting and receives a letter of confirmation once compliant; commercial products are listed on the ATO product register.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.