The acquirer keeps, for every PIN-entry device, the vendor name, model name and PCI PTS approval number, with a summary listing the models in use and the number of devices per model; an application that replaces or disables the evaluated firmware voids the approval unless it is itself PTS-validated and listed.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.