Where cybersecurity-related processes are outsourced or shared with partners, the manufacturer remains responsible for compliance with R155 and shall demonstrate control over those processes.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.