1 Signature scheme 0/10, weighted 30%
Band 0: Classical signatures only on mainnet, with nothing post-quantum protecting live funds. Short-lived devnets and one-off benchmarks sit here: they demonstrate research rather than something a user can hold keys on.
Polkadot uses sr25519 for most signing and Ed25519 in places, both elliptic-curve schemes broken by Shor's algorithm. No post-quantum signature is live at protocol level for accounts or consensus.
source
2 Deployment stage 5/10, weighted 25%
Band 5: Tier 3: Committed.
Tier 3: Committed. A published Web3 Foundation roadmap covers both Polkadot and JAM, names specific replacement schemes for each signature role, and is backed by a research organisation, with nothing live on mainnet.
source
3 NIST alignment 8/10, weighted 15%
Band 6 to 8: The scheme is NIST-selected but the standard is not yet final, or a NIST-approved scheme is named but not yet deployed.
The roadmap names CRYSTALS-Dilithium, standardised as ML-DSA in FIPS 204, for consensus signatures and Falcon for account signatures. One is a final standard and the other is NIST-selected but not yet published.
source
Placement in the band Not a 9: only one of the two named schemes, ML-DSA, is a final standard. Falcon is NIST-selected but unpublished, and neither is deployed.
4 Migration path 6/10, weighted 15%
Band 6 to 8: A credible published plan exists with a mechanism identified, but key parts are unbuilt or undated.
Polkadot has a genuine advantage in that its runtime is upgradeable on-chain through forkless upgrades and on-chain governance, so enacting a cryptographic change does not require a contentious hard fork. The deduction is for the breadth of the problem: consensus, parachain and account signatures all have to move, and no dated schedule was found.
source
Placement in the band The floor of the band: forkless on-chain upgrades are a genuine mechanism for enacting a cryptographic change without a contentious fork. It cannot reach 7 because consensus, parachain and account signatures all have to move and no dated schedule was found.
5 Exposure 3/10, weighted 10%
Band 3 to 5: Most active accounts have revealed a public key, or the chain has no live supply to assess.
Polkadot addresses are SS58 encodings of the public key itself rather than a hash of it, so an account's key is readable from its address without the account ever having signed. Balances are therefore harvestable today.
source
Placement in the band The floor of the band: an SS58 address is the public key itself, so keys are readable without an account ever signing, which is the worst structural position this band covers. It is not a 2 because no measured share of at-risk supply has been published.
6 Verification 8/10, weighted 5%
Band 6 to 8: Open source with public review or a named third-party audit of the relevant component.
The roadmap was published openly on the Polkadot forum by the Web3 Foundation, the cryptography is documented in public research and wiki material, and the implementation is open source and independently audited.
source
Placement in the band The top of the band: the implementation is open source and independently audited, and the roadmap was published openly by the Web3 Foundation. It stops short of 9 because the audited component is the existing cryptography, not a post-quantum one.