Aim: software that is analysable, testable, verifiable and maintainable, with component testing done in this phase. The Implementer writes the source code (which includes models or other inputs that generate executable code) from the component design; its size and complexity are balanced, a reader can follow and test it, and it is under configuration control before documented testing begins. Where Table A.1 requires, the Tester writes a component test report per the generic report rules, stating the results, whether each component meets its design specification, and a coverage statement showing the required coverage was reached for every required criterion. The Verifier's source code verification report checks that the code implements the component design, that the coding standards were applied correctly, that the code meets the readability, traceability and specific requirements, and that the component test report properly records the tests run against the specification.
This control maps to 8 controls across 4 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 8 it maps to, and the evidence behind each claim, over MCP and REST.