It must list the harmonised standards, common specifications or European cybersecurity certification schemes applied in full or in part (stating which parts where partial) and, where none were applied, describe the solutions adopted to meet Annex I Parts I and II, with other technical specifications applied.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.