Publish a self-attestation stating which controls of the NIST SSDF or a similar framework the manufacturer has put in place and for which products; other schemes such as the Israel Cyber Supply Chain Methodology are also named.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.