I have not agreed with anything until I confirm the fact.
When reading Larry and David's comments, they are saying that it should not be a fault ( non conformity) on our side if it's beyond the SOA. As a suggestion we could accept to modify out SOA to include encryption going forward. But it is not a fault against our current SOA. It needs to be separated clearly.
As David said, it is okay for us to enhance the SOA based on the findings but please do not mix two different things.
Thank you,