Covers FTP_QKD.2 after sifting, and is run only once 6.2 has passed. With a shared authentication key long enough for the test (possibly reused per session in the adapted module), n_exe complete sessions are run between the module under test and an emulator, recording the post-sifting input and the final key on both sides. The evaluator re-runs post-processing independently to get an emulated final key and checks that the module produces a key exactly when the emulator does (or both abort), that its keys are not on average significantly longer than the emulated ones (so privacy amplification is adequate), and that the fraction of matching final-key bits is at least T_PP (which may be 1); the whole is repeated with the roles reversed.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.