For products whose core functionality matches an Annex IV category, the Commission may require by delegated act a European cybersecurity certificate at assurance level at least substantial under a scheme adopted under Regulation (EU) 2019/881. Until such an act applies, a critical product must use one of the third-party routes of Article 32(3). The delegated act gives at least six months of transition.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.