Where a vulnerability affects several vendors, where the reporter has gone through a coordinator, or where the vendor cannot reach or agree with a reporter, the vendor should involve a coordinator (a CERT, CSIRT or industry body) to mediate and synchronize the disclosure; the CRA harmonized-standard draft cites this with 5.5.5 and 8.1.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.