1 Signature scheme 0/10, weighted 30%
Band 0: Classical signatures only on mainnet, with nothing post-quantum protecting live funds. Short-lived devnets and one-off benchmarks sit here: they demonstrate research rather than something a user can hold keys on.
Bitcoin mainnet uses ECDSA and Schnorr on secp256k1, both broken by Shor's algorithm. BIP-360 is a Draft and states it does not introduce post-quantum signature schemes; it mentions ML-DSA and SLH-DSA only as examples worth scrutinising.
source
2 Deployment stage 2/10, weighted 25%
Band 2: Tier 4: Debating.
Tier 4: Debating. The threat is acknowledged and two proposals are formally documented, but both are Draft, neither is activated, and there is no consensus on an activation path or a timeline.
source
3 NIST alignment 3/10, weighted 15%
Band 3 to 5: NIST schemes are referenced as candidates without a committed selection, or the work is bespoke research.
No post-quantum scheme has been selected. BIP-360 references ML-DSA and SLH-DSA only as examples of quantum-resistant algorithms worth scrutinising, explicitly declining to propose them for integration.
source
Placement in the band At the floor of the band rather than a 4 or a 5: BIP-360 does not merely leave a scheme unchosen, it explicitly declines to propose ML-DSA or SLH-DSA for integration. Naming algorithms in order to set them aside is the least committed form this band describes.
4 Migration path 2/10, weighted 15%
Band 0 to 2: No agreed migration path, or the proposals on the table would strand or freeze holder funds.
The hardest migration problem in the index. Bitcoin has no mechanism to move coins whose keys are already exposed without their owners acting, and BIP-361's answer is to make legacy signatures unspendable at a fixed block height: Phase A at roughly three years after activation, Phase B two years after that. Coins whose owners never migrate are lost by design. Activation itself requires soft-fork consensus that does not currently exist.
source
Placement in the band A 2 rather than a 0 because a concrete mechanism is on the table: BIP-361 sets out phased sunset heights, which is more than an acknowledgement. It can go no higher because that mechanism makes unmigrated coins permanently unspendable, which is the stranding case this band names.
5 Exposure 1/10, weighted 10%
Band 0 to 2: Public keys are exposed for effectively all accounts, or a large, measured share of total supply sits in exposed addresses.
The largest measured exposure in the index. Deloitte's analysis of the full chain found roughly 2 million BTC in original pay-to-public-key addresses and 2.5 million in reused pay-to-public-key-hash addresses, over 4 million BTC or about 25% of supply, every coin of it with the public key already visible on-chain. Later estimates from Galaxy Digital and Glassnode run higher still and are set out in the exposure note below.
source
Placement in the band Not a 0, because the address model still protects never-spent pay-to-public-key-hash coins, and not a 2, because the measured exposed share of over 4 million BTC is the largest in the index by a wide margin.
6 Verification 7/10, weighted 5%
Band 6 to 8: Open source with public review or a named third-party audit of the relevant component.
Bitcoin's process is maximally open: the proposals are public documents in a public repository, subject to years of adversarial review, and a functional testnet implementation exists in BTQ Technologies' Bitcoin Quantum testnet v0.3.0 from March 2026. Openness is not the same as progress, but it is real verification.
source
Placement in the band A 7 rather than an 8 because the open review covers proposals rather than a deployed component. The testnet implementation is third-party and unaudited, so there is no named audit of anything Bitcoin itself runs.