Per NIST SSDF SP 800-218 + EO 14028: PO group. Requirements include (a) Define Secure Software Development Policies + (b) Roles and Responsibilities + (c) Communicate to third parties + (d) Workforce Training + role-based training + (e) Toolchains + (f) Criteria for software security checks.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.