Table A.1 defines every data element with its source, format, length, device channel, message category and inclusion (required: the sender includes it and the recipient checks presence and validates; conditional: included when its condition is met; optional: validated when present, and absent rather than empty when there is nothing to send). A required field that is absent or empty draws an Error Message with Error Code 03; a value failing its edit criteria draws Error Code 05; no validation beyond those listed may be used to reject a message. Only Device Information is encrypted, by the SDK as one JWE object for the DS, which places it decrypted in the AReq to the ACS. A.5 fixes the device, browser, 3DS Method, CReq/CRes POST, error, invalid request, excluded currency and country and card range values. Message extensions travel in a JSON array, each with a name, a unique identifier, a criticality indicator that must be sent even when false, and data (up to 8,192 characters in v2.0.0); a component other than the DS that does not recognise a critical extension treats the message as invalid, non-critical extensions it cannot process pass unaltered, and all critical extensions are assigned by EMVCo.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.