The organisation maximises use of secure, supported software, whether built internally or bought (new in v4.0). Partially achieved: suppliers follow secure development practices and understand software composition and provenance to a degree; development, test and production environments and repositories are proportionately secure; testing covers functional and non-functional aspects with static and dynamic analysis; timely security updates arrive through secure channels; suppliers handle vulnerabilities and notify significant events; open-source software is assessed; and support is in place. Achieved: suppliers use an established framework (for example NIST SSDF or Microsoft SDL), fully understand composition including third-party components monitored for vulnerabilities, environments resist capable actors, development uses threat modelling, and software authenticity and integrity can be attested.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.