Article 12 sets the substantive operating conditions for DIS: (a) the DIS provider shall not use the data for purposes other than the intermediation; (b) the DIS provider shall not use derived insights from intermediated data for its own commercial gain; (c) the DIS provider shall provide its services through a separate legal person (structural separation from any other commercial activity); (d) the DIS provider must enable interoperability with other DIS; (e) ICT-security measures appropriate to the risks; (f) fair, transparent and non-discriminatory access; (g) procedures to prevent fraudulent or abusive practices.
This control maps to 2 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 2 it maps to, and the evidence behind each claim, over MCP and REST.