Cryptographic algorithms and primitives can be replaced (crypto-agility); changing them is treated as a security-relevant change, and a non-updateable device's intended life should not exceed the recommended lifetime of its algorithms and key sizes. Status in Table B.1: R (recommendation, a should provision).
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.