The vendor should protect vulnerability information during handling: need-to-know access to reports, protected storage and encrypted transmission, protection of the reporter's identity where anonymity is requested and no premature disclosure, the practices ISO/IEC 30111 7.3 details; the CRA harmonized-standard draft cites this clause for its operational security requirement.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.