Article 32 sets the conformity assessment routes: (1) Default PDE - Module A (internal production control - self-assessment by the manufacturer); (2) Important PDE Class I (Annex III Class I) - Module A if the manufacturer applies harmonised standards or European cybersecurity certification, otherwise Module B+C (EU type-examination + conformity to type) or Module H (full quality assurance) by a notified body; (3) Important PDE Class II (Annex III Class II) - Module B+C or Module H mandatory by a notified body; (4) Critical PDE (Annex IV) - mandatory European cybersecurity certification at assurance level 'substantial' or higher under (EU) 2019/881.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.