Accredited recipients must implement the information-security controls in Schedule 2 of the CDR Rules (governance, access, monitoring, encryption, testing) and report assurance.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.