Where an organization finds quantum-vulnerable cryptography in its custom-built technologies, it should identify the risk to the data or functions relying on them and either migrate those technologies to PQC or develop system security upgrades that mitigate the risk of their continued use. Custom-built products, especially in older systems, are expected to need the most effort.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.