An authenticated vulnerability scan is performed by the assessor on a representative sample of in-scope EUDs and servers. Any high or critical CVE older than 14 days fails.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.