The organization makes sure it is able to satisfy what is required of the products and services it plans to offer, and reviews them before it commits to supply. The review covers: what the customer specifies, including delivery and post-delivery activity; requirements the customer has not stated but which the specified or intended use makes necessary; the organization's own requirements; the laws and regulations that apply; and any requirement in a contract or order that differs from one expressed earlier. Any such differences are resolved, and where the customer gives no documented statement of requirements, the organization confirms them before accepting. Documented information on the review's outcome and on any new requirements is retained.
This control maps to 7 controls across 6 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 7 it maps to, and the evidence behind each claim, over MCP and REST.