Evidence
Cryptographic threat monitoring, as evidence
Regulated crypto firms are now asked to show that they monitor cryptanalytic threats, quantum included, and can change their cryptography as those threats develop. The tools that sell evidence for this look at enterprise PKI and TLS. None of them looks at the on-chain signing keys that actually hold a crypto firm’s assets. This pack measures both surfaces from public data, maps each fact to the clause it evidences, says plainly where the result is a gap, and signs the whole thing with ML-DSA-65 so a supervisor or auditor can confirm it is unaltered.
Nothing leaves the public record: the domain scan uses public certificate logs and a TLS handshake; the addresses are read from public chain data. No key material is ever requested.
What the pack maps to
Each clause below is quoted from, and linked to, the primary text. The pack also maps to NIST CSWP 48 (post-quantum cryptography in CSF 2.0 terms).
EU DORA, RTS 2024/1774 (in force since January 2025)
Recital 9 and Article 6(4)
Firms must deal with "the dynamic landscape of cryptographic threats, including threats from quantum advancements," and their cryptographic policy must include "provisions for updating or changing the cryptographic technology on the basis of developments in cryptanalysis." Applies to MiCA-authorised crypto-asset service providers through Article 2(1) of DORA.
primary textFINMA Guidance 05/2026 (9 July 2026)
PQC roadmap and provider readiness
A board-approved post-quantum roadmap by mid-2027, a cryptographic inventory, and an evaluation of the post-quantum readiness of service providers.
primary textMAS Advisory TCRS/2024/01 (20 February 2024)
Inventory and migration priorities
Maintain a cryptographic inventory, identify priority assets for migration, and build crypto-agility.
primary textUK FCA FG26/6 (30 June 2026; regime live 25 October 2027)
Paragraph 2.2
Firms "should remain aware of emerging technologies such as advances in artificial intelligence, quantum computing," with sound private-key custody practices.
primary textNIST IR 8547 (Initial Public Draft, November 2024)
Algorithm timeline
Classical elliptic-curve signatures deprecated after 2030 and disallowed after 2035. The clock every supervisor cites.
primary text
How to read a status
Evidence: the measurement supports the clause as written.
Partial: it supports part of the clause; the pack names what is missing.
Gap: the measurement shows the clause is not yet met, or cannot be met with current standards. On-chain signatures are one such gap for every firm today: no production post-quantum signature exists for them, so the pack records that honestly rather than pretending otherwise.
Need the pack on a schedule, under NDA, or for addresses that are not public? The method is the same; only the address set and the cadence change.
Talk to usRelated: on-chain exposure, reserve attestations, how reports are signed and verified.