Standard · Post-Quantum Conformance · Architecture layer: STANDARD

PQ-Verified

The standard that defines what qualifies as post-quantum verified. PQ-Verified recognizes evidence that satisfies its published conformance requirements — it is the authority on post-quantum conformance, not a tool that performs it.

Definition. PQ-Verified is a conformance standard. Its one job is to assert conformance: it recognizes whether a system’s post-quantum evidence satisfies the published requirements. It does not generate that evidence (H33-74 produces it), does not verify the artifact (Verification does), does not score the implementation (HICS does), and does not perform cryptography (the implementation surfaces do). It answers “what qualifies as post-quantum verified?” — not “how do we do post-quantum cryptography?”

What qualifies as post-quantum verified

from graph: PQ_VERIFIED RECOGNIZES evidence satisfying published conformance requirements

The standard is a definition, not a verdict engine. It publishes the requirements a post-quantum migration’s evidence must satisfy to be called conformant, and it recognizes evidence that meets them. Conformance flows one way: an operator produces an artifact, the artifact carries a proof, and the standard recognizes that the proof satisfies its requirements.

artifact  →  proof  →  standard  (recognition, never the reverse)

PQ-Verified never runs the other direction: it does not push a verdict down onto an artifact, and the standard is never itself the proof. It recognizes evidence that satisfies the published conformance requirements.

The authority chain

from graph: implementation → evidence → verification → PQ_VERIFIED asserts → HICS incorporates

PQ-Verified is one link in a chain where every step belongs to a different concept:

Implementation → Evidence Artifact → Verification → PQ-Verified asserts → HICS incorporates

An implementation produces the evidence; an independent verifier checks the artifact; PQ-Verified asserts whether the checked evidence satisfies the conformance requirements; and HICS incorporates that assertion as the authority for its Crypto dimension. PQ-Verified sits at exactly one position and reaches into none of the others.

The conformance requirements it recognizes

from graph: published requirements PQ_VERIFIED recognizes (not crypto it performs)

An artifact is recognized as conformant when it satisfies published, versioned requirements — the standard states the requirements; the verifier checks them:

RequirementRecognized basis
Post-quantum signatures across the required familiesML-DSA-65 (FIPS 204) · SLH-DSA-SHA2-128f (FIPS 205) · FALCON-512 (draft FN-DSA / FIPS 206)
All required families validate (an AND-gate)3-of-3 — conformant only when every family validates
Content bound by a canonical commitmentSHA3 content commitment over the codebase
Portable, independently verifiable offlineverifiable by anyone, with H33 not contacted
Recognition is 3-of-3, not 2-of-3. An artifact is recognized as conformant only when all three signature families validate. A 2-of-3 rule would recognize an artifact after one family had already failed — accepting a partial result as conformant — so it is never the acceptance rule; it matches the AND-gate the Verification standard defines. And FALCON-512 is disclosed honestly: ML-DSA (FIPS 204) and SLH-DSA (FIPS 205) are finalized; FALCON is a draft, not yet a finalized FIPS signature — the requirement rests on it too, and that is stated rather than implied to rest on the finalized families alone.

Relationships — one verb each

from graph: each adjacent concept has exactly one, distinct relationship
NeighbourRelationshipWhat stays theirs
VerificationUSESPQ-Verified uses the independent verifier to check the evidence — it does not verify anything itself
H33-74PRODUCESH33-74 produces the cryptographic evidence; PQ-Verified only recognizes it
Evidence artifactsRECOGNIZESthe standard is proven by / recognizes the artifact; the artifact is never something the standard emits
HICSINCORPORATED BYHICS incorporates PQ-Verified as the authority for its Crypto dimension; PQ-Verified does not score
HATSPROVIDESHATS provides operational evidence of a running system; PQ-Verified asserts conformance of the migration
Agent-008MAY CLAIMAgent-008 may claim PQ-Verified status for a governed system, but it never defines what qualifies

The standards layer — three different jobs

from graph: HATS records · HICS scores · PQ_VERIFIED asserts

PQ-Verified completes the standards layer above the capabilities, and the three standards do three completely different jobs:

HATSrecordsoperational evidence — that controls operated as declared, over time
HICSscoresoperational maturity — a rating against a published rubric
PQ-Verifiedassertspost-quantum conformance — whether the evidence satisfies the requirements

What PQ-Verified is not

from graph: explicit scope disclaimers (preserved)

PQ-Verified is not a vendor certification or a trust seal — it recognizes evidence, it does not vouch for a company. It is not a substitute for SOC 2, ISO 27001, or a security audit. It is not a closed standard — the requirements are published and the artifact is independently verifiable. And it is not H33-dependent: you produce the artifact, anyone verifies it, and verification works offline, forever, without us.

H33 as the first attested operator — disclosed

from graph: self-attestation is self-reference, disclosed honestly (not independent)

H33 authors the standard and is its first operator — Customer #1 — attesting its own conformance. That self-reference is disclosed, not hidden: a standard without an attested operator is a proposal. The self-attestation is honest about what is not yet done — the badge is withheld until every pillar verifies clean — and H33 publishes its failures, not only its successes.

H33 self-attestation · Failure vectors · Artifact v1 specification

Read the standard

from graph: PQ_VERIFIED CONVERTS_TO evaluation path

Read the published conformance requirements and the artifact specification, or produce an artifact and have anyone verify it.

Read the artifact specification

Limitations & boundaries

from graph: explicit claim boundary (does-not / does)

Generate the evidence

PQ-Verified does not produce the artifact. H33-74 produces the cryptographic evidence.

Verify the artifact

PQ-Verified does not render the verdict. It uses the independent verifier to check the evidence.

Score the implementation

PQ-Verified does not rate anything. HICS scores; it incorporates this assertion.

Perform cryptography

PQ-Verified does not compute ML-DSA, SLH-DSA, or FALCON. The implementation surfaces do.

Certify the vendor

A recognition is not a trust seal or a compliance certification for a company.

What it does

PQ-Verified does define and assert what qualifies as post-quantum conformant — the authority on the requirements.