Consider publishing which controls of a secure development framework have been implemented, and any alternative controls used; in the United States the NIST Secure Software Development Framework (SSDF, SP 800-218) is the suggested reference, a set of sound practices rather than a checklist.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.