Where encryption is used to render data unclassified or to lower its classification level, the solution needs additional approval under CNSSP 7, Policy on the Use of Commercial Solutions to Protect National Security Systems (9 December 2015); CNSA 2.0 compliance alone does not authorise it. The note cites CNSSP 7 as reference q, which Annex A assigns to FIPS 202; CNSSP 7 is reference r.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.