# NIST Graded Our Post-Quantum Cryptography. Zero Failures.

We sent our implementation to NIST's own test system and asked to be marked. 2,130 test cases across ML-KEM, ML-DSA and SLH-DSA, zero failures, and a certificate number anyone can quote back at us.

Canonical HTML: https://www.livetradingnews.com/nist-graded-our-post-quantum-cryptography-zero-failures
Last modified: 2026-09-13

---

By Shayne Heffernan · 2026-09-13
Tags: NIST, ACVTS, post-quantum cryptography, FIPS 140-3, FIPS 140-2, CMVP, CAVP, ML-KEM, ML-DSA, SLH-DSA, cryptography, compliance, procurement, KXCO, quantum risk, Shayne Heffernan
Signed: ML-DSA-65, anchored on Armature L1.
Nothing in this article is investment advice.

We sent our post-quantum cryptography to NIST and asked to be marked. Not our own test files with the answers printed alongside them. NIST's server generated vectors nobody had seen, we answered them over the ACVP protocol, and NIST graded the result.

**2,130 test cases. Zero failures.** ML-KEM, ML-DSA and SLH-DSA, in every parameter set NIST offers, across key generation, signing, verification, encapsulation and decapsulation. Issued as demo certificate **A11025** against kxco-post-quantum 1.7.2.

## What NIST actually graded

The Algorithm Validation Test System is the machinery a real FIPS validation runs on. You register what you claim to implement, the server builds test vectors for it, you get a limited window to answer, and the server decides whether you were right. There is no studying for it. The questions are generated for you and the answers are never sent.

Three non-sample sessions, run on 12 and 13 September:

- ML-KEM key generation, encapsulation and decapsulation.
- ML-DSA key generation, signature generation and signature verification.
- SLH-DSA key generation, signature generation and signature verification.
- Every parameter set NIST offers across all three, at every security category.
- Module kxco-post-quantum 1.7.2, on Node.js 26.1.0.

All three passed and were taken through the certification step onto one record: validation 42204, demo certificate A11025. That number is what NIST asks to be quoted when production access is requested, and it is the prerequisite nobody skips. No vendor and no accredited laboratory may run an algorithm on NIST's production system without first taking it through certification here.

## What it proves, and what it does not

It proves the implementation is correct against the standard as NIST computes it today, over the same protocol a real validation uses, judged by NIST rather than by us.

It is a **Demo** certificate. It is issued by NIST's demonstration instance, it does not appear on the public algorithm validation list, and it is not a CAVP validation. We say so plainly, because that distinction is the entire currency of this subject. A vendor who blurs it is telling you something about how they will describe everything else.

What it is not is a participation badge. The vectors are generated, the window is real, and a wrong answer is a failure on NIST's record rather than on ours.

## Where we drew the line, on purpose

Our registration is deliberately narrower than NIST's full test matrix, and the reason is worth stating, because most conformance numbers are quoted without one.

Our JavaScript backend refuses a pre-hash whose collision strength falls below the parameter set's security category. That is our policy rather than a FIPS 204 or 205 requirement, and NIST's vectors pair every hash with every parameter set. So we registered only the combinations we will actually perform and declined the rest: 135 declined cases out of 975 in the offline set.

A conformance number quoted without its refusal list is doing less work than it appears to. That list is the claim boundary and it belongs beside the number every time.

## Why this matters this month

On 21 September 2026 every FIPS 140-2 certificate still active moves to the historical list. Thousands of them. A great deal of compliance language written over the last decade stops being true that morning, and the obvious successor claim is a FIPS 140-3 certificate covering the post-quantum algorithms.

So we checked who holds one. Filtered to active certificates on 13 September, NIST's validated modules database returns no certificates for ML-KEM, none for ML-DSA and none for SLH-DSA. The identical search for AES returns 454.

That control is what makes the zeros an answer rather than a rumour. Three empty results prove nothing on their own, because a query that quietly broke returns the same emptiness as one that worked. Change one field, get 454, and you know the database is answering.

Four modules are in the queue with post-quantum in scope: SafeLogic's CryptoComply provider, the AWS-LC 4 module in static and dynamic builds, Code Siren's PQC library, and the Go Cryptographic Module from Geomys. Any could clear this year. None has. The queue runs 12 to 18 months, and the interim route NIST opened to drain the backlog only covers modules received before January 2024.

## How to read a post-quantum claim

For the next several quarters, every post-quantum assertion in a procurement document is one of four things. Three questions separate them.

- **Is it a module certificate?** Ask for the number and check which algorithms sit in its approved mode. Today that check fails for everyone. A certificate covering AES that lists ML-DSA as non-approved is not a post-quantum certificate.
- **Is it an algorithm certificate?** The CAVP programme validates the mathematics, not the module. A real NIST result on a public list, and a narrower claim than a module certificate.
- **Is it conformance testing?** Running NIST's published vector files and passing them. Honest and useful, and the weakest of the three, because the answers ship with the questions.
- **Is it nothing?** A datasheet that says quantum-safe and cites a standard number.

The third category is where most vendors genuinely are. Being graded by NIST's own server is a different thing from grading yourself against NIST's published files, and that difference is what A11025 records.

## What happens next

Production ACVTS, where a public CAVP certificate is minted, is open only to accredited laboratories. The demo certificate is the ticket to that conversation and we now hold it.

We are not joining the module queue this year. A submission buys 12 to 18 months of waiting for a certificate bound to one version of code on one named operating environment. Meanwhile our library already routes to OpenSSL 3.5 on Node 24 and later, reports which implementation actually performed the mathematics, and refuses to start on the wrong one when an operator demands the native path. When one of those four modules clears, binding to it is days of work.

Post-quantum cryptography has been in production across our platform since November 2025, signing records and issuing identities every day. As of this month it is also cryptography NIST has tested and passed. That is the claim, it is the whole claim, and the certificate number is there to be checked.

Shayne Heffernan, Ph.D., is the founder of Live Trading News, the KnightsBridge Group, Knightsbridge Law and the KXCO.ai ecosystem spanning post-quantum cryptography, identity, attestation and enterprise ontology.

---

This Markdown mirrors https://www.livetradingnews.com/nist-graded-our-post-quantum-cryptography-zero-failures. The HTML page is canonical.
Site index for AI clients: https://www.livetradingnews.com/llms.txt
