802.1X authentication with EAP-TLS, using X.509 certificates, is used for mutual authentication; with all other EAP methods disabled on supplicants and authentication servers.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.