Which modules are evaluated follows from the protocol architecture. In prepare-and-measure QKD both the sending and the receiving module are in scope, since the system's security rests on both. In MDI-QKD the middle receiving party carries no security assumption in the proofs, so its module is left out of evaluation scope; the measurement results it returns over unauthenticated classical links may be tampered with. In entanglement-based QKD the middle sending party is likewise left out. Where an implementation folds the middle party into one of the other two parties, the PP or ST author has to account for that degree of integration so overall security holds, and where a component needing evaluation shares a module with one that normally does not, the PP or ST and the TOE definition must state plainly how the two are segregated.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.