Cryptography protecting NSS must have been acquired under CNSSP 11 or otherwise approved by NSA. Cybersecurity and cybersecurity-enabled IT products with integrated cryptography must (1) use the approved public algorithms in the policy's CNSA table or a commensurate NSA-approved suite, (2) use an NSA-approved source for cryptographic keys and certificates, and (3) protect their firmware and software update mechanisms with approved cryptography. The scope covers every department's and agency's acquisition of such products for NSS and classified government developments using cryptography, across confidentiality, authentication, non-repudiation, integrity and availability. (The policy's paragraph 8(b) points to Annex C for the algorithms; the table is Annex B.)
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.