Where designated as critical information infrastructure, comply with additional cybersecurity duties under the Act including incident reporting to the relevant authority, regular risk assessment and adoption of recognised security standards.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.