Class A Companies face enhanced obligations: independent audits of cybersecurity program based on risk, external pen testing at least every three years, automated vulnerability scans with manual review, privileged access management and password blocklisting, endpoint detection and response, centralized logging.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.