A manufacturer that becomes aware of a severe incident with an impact on the security of its product must notify it at the same time to the coordinating CSIRT and ENISA via the single reporting platform. An incident is severe where it harms or can harm the product's ability to protect the availability, authenticity, integrity or confidentiality of sensitive or important data or functions, or has led or can lead to malicious code being introduced or run in the product or in users' systems (Article 14(5)).
This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.