L1 requires the supplier to hold Cyber Essentials certification and apply the controls specified in Def Stan 05-138 Annex A at the L1 level.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.