Within a year of signing, show action toward a significant measurable reduction in one or more chosen vulnerability classes across products, such as SQL injection, cross-site scripting or memory safety flaws. Example approaches: consistently enforced parameterised queries, auto-escaping web template frameworks, a prioritised memory safety roadmap with new products in memory safe languages, and secure building blocks for developers; progress may be shown by a blog post including CWE analysis of CVEs over time, or by publishing a memory safety or similar roadmap. A short-term rise in CVEs while the class is reduced is regarded as success.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.