CII operators must conduct, at least annually, a security inspection and risk assessment of their networks (themselves or via a service body) and report results to the relevant authority.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.