A staged path from a bounded, reversible pilot to a national currency in circulation. Each stage widens scope only after the previous one is hardened, audited, and signed off by the issuer.
The rollout is structured as gated stages, each with a defined blast radius, so the sovereign never bets the currency on an unproven leap.
The first stage runs with a limited participant set, capped balances, and constrained transaction types. It exercises the full issuance-to-settlement path end to end while keeping any fault contained to a small, known population.
Participation, transaction ceilings, and use cases are widened incrementally. Each widening is a discrete change with its own approval, not an open-ended ramp.
National rollout begins only after the engine has run under production-representative conditions. The cutover is a planned event with defined success criteria, not a soft launch.
Every stage is designed to be rolled back to the prior state with the ledger intact, so an issue discovered late does not force the sovereign to choose between shipping broken and starting over.
Progression is condition-based, not calendar-based — a stage advances when its exit criteria are demonstrably met.
Each stage carries written conditions covering correctness, security posture, and operational readiness that must be satisfied before the next stage opens. The criteria are agreed with the issuer up front.
The central bank formally approves each transition. Advancement is a sovereign decision, and the vendor cannot self-certify a move to wider scope.
External review is aligned to the gates, so findings are addressed before scope grows rather than after the currency is live at scale.
Each gate produces a recorded decision with the evidence behind it, giving the issuer an auditable trail of why the deployment was allowed to progress.
Production readiness is built stage by stage — load, failure, and abuse conditions are exercised before the population that would feel them arrives.
Throughput and latency are validated against volumes ahead of each expansion, so the engine is proven against tomorrow's load before that load exists rather than discovered under it.
Node loss, network partition, and storage faults are deliberately induced in pre-production to confirm the ledger stays consistent and settlement remains atomic under stress.
The deployment is probed for double-spend, replay, and authorization bypass before wider release, with the post-quantum signature path exercised against forged and malformed inputs.
External audit and internal hardening close out at each gate, so unresolved findings block expansion instead of accumulating into a live national system.
Moving between stages must never orphan balances or break the audit chain; continuity is a hard requirement of the path.
Balances and transaction history established in pilot are preserved into production. The hash-chained record is continuous across the cutover, so nothing is re-minted or reset.
Rollback procedures are exercised in advance of each gate, so reverting is a tested operation with known recovery behavior rather than an improvised emergency.
After a transition, ledger state is verified against the pre-transition head so the issuer can prove no value was created, lost, or altered in the move.
Engine versions across stages are designed to interoperate with existing state, so hardening improvements ship without forcing a disruptive break in the running system.