A covered entity may use a third party (incident response firm, insurer, service provider, ISAO or law firm) to submit a required report, but this does not relieve the entity of its duty to comply; a third party that knowingly makes a ransom payment on the entity's behalf must advise the entity of its reporting responsibilities.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.