Within a year of signing, make sure each CVE the manufacturer publishes carries a correct CWE and CPE, and issue CVEs promptly at least for all critical or high-impact vulnerabilities, whether found internally or externally, that need customer action to patch or show evidence of active exploitation; publicly describing when a CVE is issued is an example of showing progress. More CVEs in the short term is not to be read as a negative sign.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.