Design products and run the organisation to meet CISA's Cybersecurity Performance Goals (the NCSC-UK Cyber Assessment Framework is cited as similar); the guidance says a manufacturer falling short of them, such as one whose staff are not all on phishing-resistant MFA, does not qualify as producing secure by design products.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.