EAs for FPT_EMS.1/Quantum and FPT_PHP.3 check that the controls resist known quantum-channel attacks. Their verdicts take one of three forms: a control recognized as effective is shown to be implemented (double-click handling, 8.11); a measured parameter is compared with a threshold (isolation and monitor sensitivity, 7.8, 7.9, 8.4); or a measured parameter is fed into privacy amplification, in which case the evaluator also checks the threshold is used correctly there (8.2). Continuous parameter spaces are scanned in even steps or probed at random (7.9, 8.5, 8.9, 9.2). Evaluators account for measurement error and aim for statistically significant results, and where probabilities approach zero (for example at the edge of a gated detector's window) may treat a test as failed only on a statistically significant failure after a reasonable amount of data. Table D.1 relates EAs to known attacks.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.