Within a year of signing, show measurable progress in reducing universally shared default passwords across products, focusing on internet-facing ones, so that once set-up is complete the customer alone knows the credentials. Example approaches: random instance-unique initial passwords, a strong password set at installation, time-limited setup passwords, physical access for initial setup, and campaigns or updates moving existing deployments off defaults; progress may be shown by blog post or by publishing counts of products with default passwords and customers moved off them.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.