The standard that defines what qualifies as post-quantum verified. PQ-Verified recognizes evidence that satisfies its published conformance requirements — it is the authority on post-quantum conformance, not a tool that performs it.
The standard is a definition, not a verdict engine. It publishes the requirements a post-quantum migration’s evidence must satisfy to be called conformant, and it recognizes evidence that meets them. Conformance flows one way: an operator produces an artifact, the artifact carries a proof, and the standard recognizes that the proof satisfies its requirements.
artifact → proof → standard (recognition, never the reverse)
PQ-Verified never runs the other direction: it does not push a verdict down onto an artifact, and the standard is never itself the proof. It recognizes evidence that satisfies the published conformance requirements.
PQ-Verified is one link in a chain where every step belongs to a different concept:
Implementation → Evidence Artifact → Verification → PQ-Verified asserts → HICS incorporates
An implementation produces the evidence; an independent verifier checks the artifact; PQ-Verified asserts whether the checked evidence satisfies the conformance requirements; and HICS incorporates that assertion as the authority for its Crypto dimension. PQ-Verified sits at exactly one position and reaches into none of the others.
An artifact is recognized as conformant when it satisfies published, versioned requirements — the standard states the requirements; the verifier checks them:
| Requirement | Recognized basis |
|---|---|
| Post-quantum signatures across the required families | ML-DSA-65 (FIPS 204) · SLH-DSA-SHA2-128f (FIPS 205) · FALCON-512 (draft FN-DSA / FIPS 206) |
| All required families validate (an AND-gate) | 3-of-3 — conformant only when every family validates |
| Content bound by a canonical commitment | SHA3 content commitment over the codebase |
| Portable, independently verifiable offline | verifiable by anyone, with H33 not contacted |
| Neighbour | Relationship | What stays theirs |
|---|---|---|
| Verification | USES | PQ-Verified uses the independent verifier to check the evidence — it does not verify anything itself |
| H33-74 | PRODUCES | H33-74 produces the cryptographic evidence; PQ-Verified only recognizes it |
| Evidence artifacts | RECOGNIZES | the standard is proven by / recognizes the artifact; the artifact is never something the standard emits |
| HICS | INCORPORATED BY | HICS incorporates PQ-Verified as the authority for its Crypto dimension; PQ-Verified does not score |
| HATS | PROVIDES | HATS provides operational evidence of a running system; PQ-Verified asserts conformance of the migration |
| Agent-008 | MAY CLAIM | Agent-008 may claim PQ-Verified status for a governed system, but it never defines what qualifies |
PQ-Verified completes the standards layer above the capabilities, and the three standards do three completely different jobs:
| HATS | records | operational evidence — that controls operated as declared, over time |
| HICS | scores | operational maturity — a rating against a published rubric |
| PQ-Verified | asserts | post-quantum conformance — whether the evidence satisfies the requirements |
PQ-Verified is not a vendor certification or a trust seal — it recognizes evidence, it does not vouch for a company. It is not a substitute for SOC 2, ISO 27001, or a security audit. It is not a closed standard — the requirements are published and the artifact is independently verifiable. And it is not H33-dependent: you produce the artifact, anyone verifies it, and verification works offline, forever, without us.
H33 authors the standard and is its first operator — Customer #1 — attesting its own conformance. That self-reference is disclosed, not hidden: a standard without an attested operator is a proposal. The self-attestation is honest about what is not yet done — the badge is withheld until every pillar verifies clean — and H33 publishes its failures, not only its successes.
H33 self-attestation · Failure vectors · Artifact v1 specification
Read the published conformance requirements and the artifact specification, or produce an artifact and have anyone verify it.
Read the artifact specificationPQ-Verified does not produce the artifact. H33-74 produces the cryptographic evidence.
PQ-Verified does not render the verdict. It uses the independent verifier to check the evidence.
PQ-Verified does not rate anything. HICS scores; it incorporates this assertion.
PQ-Verified does not compute ML-DSA, SLH-DSA, or FALCON. The implementation surfaces do.
A recognition is not a trust seal or a compliance certification for a company.
PQ-Verified does define and assert what qualifies as post-quantum conformant — the authority on the requirements.