Assurance is not an annual event. The system continuously measures itself against national standards and surfaces drift the moment it appears.
A once-a-year attestation says nothing about the state of the system on any other day.
National and institutional requirements are expressed as machine-checkable controls rather than prose in a binder. Each control has a defined evidence source and a pass condition that can be evaluated on demand.
Controls are evaluated on a schedule and on relevant events, so posture reflects the current configuration. A control that lapses is visible within its evaluation window, not at the next audit.
Each control result links to the underlying artifact — a configuration value, a signed log entry, a key attestation. Assurance is grounded in observable facts a regulator can inspect.
The sovereign owner sees the posture of their own deployment, mapped to the standards that bind them. The view is national by construction, not a shared multi-tenant dashboard.
Post-quantum guarantees hold only if keys, algorithms, and rotation stay within policy over time.
The system continuously confirms that signing and settlement use the mandated post-quantum primitives, ML-DSA-65 under FIPS 204. A downgrade or misconfiguration is flagged as a control failure.
Key age, custody location, and rotation status are monitored against policy. Keys approaching a rotation boundary are surfaced before they breach it.
Assurance verifies that owner-held keys and weights remain within the sovereign custody boundary. Any signing path that would move authority outside that boundary is treated as a violation.
The hash-chained trail is re-verified continuously rather than only during investigations. Chain discontinuities raise an assurance signal in near real time.
Most failures begin as small, unremarked drift from a known-good state.
An approved configuration and policy baseline is recorded and version-controlled. Every subsequent state is compared against it, so drift is measured against something explicit.
Detected drift is correlated with the audit trail entry that caused it. An operator sees not only that a control failed but which authorized action moved it.
Control failures route to defined owners with severity aligned to the standard they violate. Escalation is deterministic rather than dependent on who happens to be watching.
Acknowledgements and temporary exceptions are themselves logged with an authorizing key and expiry. An accepted risk leaves a record, and a silenced alert cannot silently persist.
A report is credible only when its recipient can reconstruct the claims behind it.
Assurance output is organized against the specific national framework in force for that deployment. A regulator reads results in the structure of their own requirements.
Any historical moment can be reconstructed to show the posture as it stood then. Investigations are answered from recorded state, not reconstructed from memory.
Assurance reports are signed with post-quantum keys, so their integrity and origin are verifiable. A tampered report is detectable by the same mathematics as a tampered ledger.
Because each result links to public-standard checks over recorded evidence, a regulator can recompute it. Assurance is a claim the recipient can test, not one they must accept.