A covered entity must promptly submit an update or supplement to a previously submitted covered cyber incident report when substantial new or different information becomes available, or if it makes a ransom payment after the initial report, until it notifies CISA the incident has concluded and is fully mitigated and resolved.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.