Silver criterion sites_password_security (MUST; group Basics, Other). Criterion text: If the project sites (website, repository, and download URLs) store passwords for authentication of external users, the passwords MUST be stored as iterated hashes with a per-user salt by using a key stretching (iterated) algorithm (e.g., Argon2id, Bcrypt, Scrypt, or PBKDF2). If the project sites do not store passwords for this purpose, select "not applicable" (N/A).
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.