Refined for the optical side, the module's emissions over the quantum channel must not enable access to TSF or user data: the light it sends has to match what the protocol's proof assumes in photon-number distribution, mean photon number and stability, independence of pulse intensities, encoding accuracy, indistinguishability in non-encoding degrees of freedom and phase randomization, and on the receiver side the ST assigns which of the detection-side properties tested in part 2 clause 8 fall under it. The aim is that a TOE meeting it at the chosen EAL resists the known attacks run from the quantum channel.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.