Organizations should feed the quantum-vulnerable inventory into their risk assessment process so that risk officials can prioritise where post-quantum cryptography is used first once available. Priority goes to high impact systems, industrial control systems and systems with long-term confidentiality needs.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.