A secure SDLC is not enough if the manufacturer's own enterprise and build environments can be used to tamper with a product during development, an attack that has already harmed customers; consider publishing conformance to the CISA Cross-Sector Cybersecurity Performance Goals, the NIST Cybersecurity Framework or another programme framework.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.