CII operators must, beyond Art. 21, establish a specialised security management body and responsible person, conduct background checks, provide security training, back up critical data, and have an incident response plan.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.