Engineering · Validation

NIST graded our cryptography. Zero failures.

We sent our post-quantum implementation to NIST's own test system and asked to be marked. NIST generated vectors nobody had seen, we answered them, NIST graded them: 2,130 cases, zero failures, demo certificate A11025. Eight days before every FIPS 140-2 certificate goes historical, here is exactly what that proves and what it does not.

NIST validated post-quantum ACVTS KXCO Engineering 13 September 2026 ~7 min read

We sent our post-quantum cryptography to NIST and asked to be marked. Not our own test files with the answers printed alongside. NIST's server generated vectors nobody had seen, we answered them over the ACVP protocol, and NIST graded the result.

The result, September 2026

2,130 test cases. Zero failures. ML-KEM, ML-DSA and SLH-DSA, in every parameter set NIST offers, key generation, signing, verification, encapsulation and decapsulation. Issued as demo certificate A11025 against kxco-post-quantum 1.7.2.

01What NIST graded

The Algorithm Validation Test System is the machinery a real FIPS validation runs on. You register what you claim to implement, the server builds test vectors for it, you have a limited window to answer, and the server decides whether you were right. There is no way to study for it, because the questions are generated for you and the answers are never sent.

Three non-sample sessions, run 12 and 13 September:

  • ML-KEM key generation, encapsulation and decapsulation.
  • ML-DSA key generation, signature generation and signature verification.
  • SLH-DSA key generation, signature generation and signature verification.
  • Every parameter set NIST offers across all three, at every security category.
  • Module kxco-post-quantum 1.7.2, on Node.js 26.1.0, Windows 10 Pro.

All three sessions passed and were taken through the certification step onto one record: validation 42204, demo certificate A11025. That number is what NIST asks to be quoted when production access is requested, and it is the prerequisite nobody skips. No vendor and no accredited laboratory may run an algorithm on the production system without first taking it through certification here.

02What it proves, and what it does not

It proves the implementation is correct against the standard as NIST computes it today, over the same protocol a real validation uses, judged by NIST rather than by us.

It is a Demo certificate. It is issued by NIST's demonstration instance, it does not appear on the public algorithm validation list, and it is not a CAVP validation. We say that plainly because the distinction is the whole currency of this subject. A vendor who blurs it is telling you something about how they will describe everything else.

What it is not is a participation badge. The vectors are generated, the window is real, and a wrong answer is a failure on NIST's record rather than on ours.

03Where we drew the line, on purpose

Our registration is deliberately narrower than NIST's full test matrix, and the reason is worth stating, because most conformance numbers are quoted without one.

The JavaScript backend refuses a pre-hash whose collision strength falls below the parameter set's security category: SHA2-224 with ML-DSA-44, and so on down the matrix. That is our policy rather than a FIPS 204 or 205 requirement, and NIST's vectors pair every hash with every parameter set. So we registered only the combinations we will actually perform, and declined the rest: 135 declined cases out of 975 in the offline set.

A conformance number quoted without its refusal list is doing less work than it appears to. That list is the claim boundary and it belongs beside the number every time.

04What the rest of the field looks like

On 21 September 2026 every FIPS 140-2 certificate still active moves to the historical list. Thousands of them. A great deal of compliance language written over the last decade stops being true that morning, and the obvious successor claim is a FIPS 140-3 certificate covering the post-quantum algorithms.

So we checked who holds one. Filtered to active certificates, on 13 September 2026:

# NIST CMVP validated modules search, CertificateStatus=Active
Algorithm=ML-KEM   → No certificates match the search criteria
Algorithm=ML-DSA   → No certificates match the search criteria
Algorithm=SLH-DSA  → No certificates match the search criteria
Algorithm=AES      → 454 certificates          # the control

Nobody has one. The control is what makes that an answer rather than a rumour: three empty results prove nothing on their own, because a query that quietly broke returns the same emptiness as one that worked. The same search with one field changed returns 454, so the zeros are the database answering.

Four modules are in the queue with post-quantum in scope: SafeLogic's CryptoComply provider, the AWS-LC 4 module in static and dynamic builds, Code Siren's PQC library, and the Go Cryptographic Module from Geomys. Any could clear this year. None has. The queue runs 12 to 18 months, and the interim route NIST opened to drain the backlog only covers modules received before January 2024.

05How to read a post-quantum claim

For the next several quarters every post-quantum assertion in a procurement document is one of four things. Three questions separate them.

  • Is it a module certificate? Ask for the number and check which algorithms sit in its approved mode. Today that check fails for everyone. A certificate covering AES that lists ML-DSA as non-approved is not a post-quantum certificate.
  • Is it an algorithm certificate? CAVP validates the mathematics, not the module. A real NIST result on a public list, and a narrower claim than a module certificate.
  • Is it conformance testing? Running NIST's published vector files and passing them. Honest and useful, and the weakest of the three, because the answers ship with the questions.
  • Is it nothing? A datasheet that says quantum-safe and cites a standard number.

The third category is where most vendors genuinely are. Being graded by NIST's own server is a different thing from grading yourself against NIST's published files, and that difference is what A11025 records.

06What happens next

Production ACVTS, where a public CAVP certificate is minted, is open only to accredited laboratories. The demo certificate is the ticket to that conversation, and we now hold it.

We are not joining the module queue this year. A CMVP submission buys 12 to 18 months of waiting for a certificate bound to one version of code on one named operating environment. Meanwhile our library already routes to OpenSSL 3.5 on Node 24 and later, reports which implementation actually performed the mathematics so an evidence bundle records it rather than infers it, and refuses to start on the wrong one when an operator sets KXCO_PQ_REQUIRE_NATIVE=1. When one of those four modules clears, binding to it is days of work.

Post-quantum cryptography has been in production across the KXCO platform since November 2025, signing records and issuing identities every day. As of this month it is also cryptography NIST has tested and passed. That is the claim, it is the whole claim, and the certificate number is there to be checked.


Sources: NIST ACVTS demonstration server, sessions 767289, 767291 and 767292, validation 42204, demo certificate A11025. NIST CMVP validated modules search and Modules In Process list, both read 13 September 2026. KXCO research. KXCO is a software company; regulated services are operated by licensed institutions. Cryptographic posture reflects NIST FIPS 203/204/205; KXCO does not claim CNSA 2.0. Nothing here is investment advice.