A.2.2 Protection of the TSF (FPT) / FPT_INT_EXT.1 Support for Introspection / FPT_INT_EXT.1.1
This may not be applicable as a possible requirement anymore. There is a modern effort to keep customer VMs confidential from VS admins - especially in commercial cloud environments like AWS.
NIAP response: This will be addressed in a future version