Although not separately mandated in the first three security requirements, manufacturers should deliver software updates over secure channels and verify integrity, in line with ETSI EN 303 645 expectations.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.