An importer that believes a product or the manufacturer's processes do not conform must not place it until conformity is restored. Where the product presents a significant cybersecurity risk it must inform the manufacturer and market surveillance authorities; where it believes a significant risk arises from non-technical risk factors it must inform the authorities.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.