Per Saudi NCA Essential Cybersecurity Controls (ECC-1) Domain 1: Cybersecurity Governance. Requirements include (a) Cybersecurity Strategy + (b) Cybersecurity Management + (c) Cybersecurity Policies and Procedures + (d) Cybersecurity Roles and Responsibilities + (e) Cybersecurity Risk Management + (f) Personnel Security + (g) Awareness + (h) Compliance.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.