The ACS keeps the state of every transaction answered with status C so the CReq can be processed and timeouts enforced (Req 5.35); after an ARes with status C it allows 30 seconds for the initial CReq and on expiry sends an RReq with status N and reason 13 and clears the ephemeral key, answering any later CReq for that transaction with IReq 13 (Req 5.36 to 5.38). In the app channel, after each CRes that needs a further CReq it allows 10 minutes, on expiry sending an RReq with status N, reason 13 and Challenge Cancelation Indicator 4, clearing the ephemeral key and answering a late CReq with IReq 13 (Req 5.39 to 5.41); in the browser channel it allows 10 minutes after each challenge interface is sent and on expiry sends an RReq with status N and reason 14, then posts a CRes with status N to the notification URL (Req 5.42, 5.43).
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.