NIST Graded Our Post-Quantum Cryptography. Zero Failures.
We sent our implementation to NIST's own test system and asked to be marked. 2,130 test cases across ML-KEM, ML-DSA and SLH-DSA, zero failures, and a certificate number anyone can quote back at us.
Part of theKXCO Center
We sent our post-quantum cryptography to NIST and asked to be marked. Not our own test files with the answers printed alongside them. NIST's server generated vectors nobody had seen, we answered them over the ACVP protocol, and NIST graded the result.
2,130 test cases. Zero failures. ML-KEM, ML-DSA and SLH-DSA, in every parameter set NIST offers, across key generation, signing, verification, encapsulation and decapsulation. Issued as demo certificate A11025 against kxco-post-quantum 1.7.2.
What NIST actually graded
The Algorithm Validation Test System is the machinery a real FIPS validation runs on. You register what you claim to implement, the server builds test vectors for it, you get a limited window to answer, and the server decides whether you were right. There is no studying for it. The questions are generated for you and the answers are never sent.
Three non-sample sessions, run on 12 and 13 September:
ML-KEM key generation, encapsulation and decapsulation.
ML-DSA key generation, signature generation and signature verification.
SLH-DSA key generation, signature generation and signature verification.
Every parameter set NIST offers across all three, at every security category.
Module kxco-post-quantum 1.7.2, on Node.js 26.1.0.
All three passed and were taken through the certification step onto one record: validation 42204, demo certificate A11025. That number is what NIST asks to be quoted when production access is requested, and it is the prerequisite nobody skips. No vendor and no accredited laboratory may run an algorithm on NIST's production system without first taking it through certification here.
What it proves, and what it does not
It proves the implementation is correct against the standard as NIST computes it today, over the same protocol a real validation uses, judged by NIST rather than by us.
It is a Demo certificate. It is issued by NIST's demonstration instance, it does not appear on the public algorithm validation list, and it is not a CAVP validation. We say so plainly, because that distinction is the entire currency of this subject. A vendor who blurs it is telling you something about how they will describe everything else.
What it is not is a participation badge. The vectors are generated, the window is real, and a wrong answer is a failure on NIST's record rather than on ours.
Where we drew the line, on purpose
Our registration is deliberately narrower than NIST's full test matrix, and the reason is worth stating, because most conformance numbers are quoted without one.
Our JavaScript backend refuses a pre-hash whose collision strength falls below the parameter set's security category. That is our policy rather than a FIPS 204 or 205 requirement, and NIST's vectors pair every hash with every parameter set. So we registered only the combinations we will actually perform and declined the rest: 135 declined cases out of 975 in the offline set.
A conformance number quoted without its refusal list is doing less work than it appears to. That list is the claim boundary and it belongs beside the number every time.
Why this matters this month
On 21 September 2026 every FIPS 140-2 certificate still active moves to the historical list. Thousands of them. A great deal of compliance language written over the last decade stops being true that morning, and the obvious successor claim is a FIPS 140-3 certificate covering the post-quantum algorithms.
So we checked who holds one. Filtered to active certificates on 13 September, NIST's validated modules database returns no certificates for ML-KEM, none for ML-DSA and none for SLH-DSA. The identical search for AES returns 454.
That control is what makes the zeros an answer rather than a rumour. Three empty results prove nothing on their own, because a query that quietly broke returns the same emptiness as one that worked. Change one field, get 454, and you know the database is answering.
Four modules are in the queue with post-quantum in scope: SafeLogic's CryptoComply provider, the AWS-LC 4 module in static and dynamic builds, Code Siren's PQC library, and the Go Cryptographic Module from Geomys. Any could clear this year. None has. The queue runs 12 to 18 months, and the interim route NIST opened to drain the backlog only covers modules received before January 2024.
How to read a post-quantum claim
For the next several quarters, every post-quantum assertion in a procurement document is one of four things. Three questions separate them.
Is it a module certificate? Ask for the number and check which algorithms sit in its approved mode. Today that check fails for everyone. A certificate covering AES that lists ML-DSA as non-approved is not a post-quantum certificate.
Is it an algorithm certificate? The CAVP programme validates the mathematics, not the module. A real NIST result on a public list, and a narrower claim than a module certificate.
Is it conformance testing? Running NIST's published vector files and passing them. Honest and useful, and the weakest of the three, because the answers ship with the questions.
Is it nothing? A datasheet that says quantum-safe and cites a standard number.
The third category is where most vendors genuinely are. Being graded by NIST's own server is a different thing from grading yourself against NIST's published files, and that difference is what A11025 records.
What happens next
Production ACVTS, where a public CAVP certificate is minted, is open only to accredited laboratories. The demo certificate is the ticket to that conversation and we now hold it.
We are not joining the module queue this year. A submission buys 12 to 18 months of waiting for a certificate bound to one version of code on one named operating environment. Meanwhile our library already routes to OpenSSL 3.5 on Node 24 and later, reports which implementation actually performed the mathematics, and refuses to start on the wrong one when an operator demands the native path. When one of those four modules clears, binding to it is days of work.
Post-quantum cryptography has been in production across our platform since November 2025, signing records and issuing identities every day. As of this month it is also cryptography NIST has tested and passed. That is the claim, it is the whole claim, and the certificate number is there to be checked.
Shayne Heffernan, Ph.D., is the founder of Live Trading News, the KnightsBridge Group, Knightsbridge Law and the KXCO.ai ecosystem spanning post-quantum cryptography, identity, attestation and enterprise ontology.

The Problem Is Not the Problem
People treat the Jack Sparrow line as a joke. The attribution is a joke. The sentence is not. Forty years in markets says the same thing Epictetus said in 125 CE and Robert Merton named in 1948: the event is finite, and the story you appoint to govern it is not. This essay walks the quote back to its actual sources, draws the loop that turns a feeling into an order, and sets out the four places a rule written in advance cuts the loop. Faith is not a hedge. It is a stance.

What KXCO Is, and Why the Hard Problem Was Never Intelligence
The prevailing enthusiasm assumes the hard problem is intelligence. It is not. It is that banks, hospitals, courts and governments are being asked to let software act on their behalf with no way to establish who decided, on what basis, or whether the record will still read in a decade. KXCO founder Shayne Heffernan sets out the architecture that answers those questions, drawn as a graph, and argues that properly constructed AI is an amplifier of human judgement rather than a replacement for it.

AI Intelligence Scales. Accountability Does Not. Why KXCO Is Built for It.
Capability is becoming abundant and everything abundant gets cheap. What does not get cheap is the person who has to sign, and they can only carry what they can see. Four conditions follow from that, and four independent authorities reached the first of them last month without knowing it.

KXCO Quantum Toolkit: The Cryptography You Did Not Choose Is Already in Your Software
Almost no company can say what cryptography actually runs inside its own software, and auditors have started asking. KXCO publishes five free packages that find it, replace it with the NIST post-quantum standards, and fail the build when someone gets it wrong.
Every story, signed and delivered.
Subscribe to the kxco channel and get the headline, the AI-written key takeaways, and the chain-anchor link the moment we publish. Audio versions and per-ticker subscriptions arrive in the next iteration.