At LoA3 there is high confidence in the identity, for substantial risk; multifactor authentication shall be employed; any secret information exchanged in authentication protocols shall be cryptographically protected in transit and at rest, though a cryptographic challenge-response protocol is not required; credentials may be stored or generated in general-purpose computers or special-purpose hardware; examples are a company submitting confidential information to a government agency, online access to accounts allowing financial transactions and a contractor's remote access to sensitive client personal information.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.