For software and firmware signing, use the stateful hash-based signature schemes LMS or XMSS (NIST SP 800-208) at the CNSA 2.0 parameter levels (or ML-DSA); these are approved first because signing is an early-priority use case.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.