1 Signature scheme 0/10, weighted 30%
Band 0: Classical signatures only on mainnet, with nothing post-quantum protecting live funds. Short-lived devnets and one-off benchmarks sit here: they demonstrate research rather than something a user can hold keys on.
Sui accounts are signed with Ed25519 today and nothing post-quantum protects live funds on mainnet. The post-quantum schemes are committed and dated but not yet deployed.
source
2 Deployment stage 5/10, weighted 25%
Band 5: Tier 3: Committed.
Tier 3: Committed. Two named standards, a phased schedule with public dates running to the first quarter of 2027, and active engineering, with nothing post-quantum live on mainnet yet.
source
3 NIST alignment 9/10, weighted 15%
Band 9 to 10: The scheme in use is covered by a final NIST standard (FIPS 204, FIPS 205, or SP 800-208).
Both selected schemes are final NIST standards rather than candidates: ML-DSA-65 under FIPS 204 for accounts and SLH-DSA-SHA2-128s under FIPS 205 for contract vaults. Committing to two finalised standards is stronger than naming a scheme still awaiting publication.
source
Placement in the band Not a 10: both schemes are final standards, which is what puts Sui at the top of this dimension, but neither is deployed, so what is committed to is a standard rather than a standard in use.
4 Migration path 9/10, weighted 15%
Band 9 to 10: Holders can migrate today, or the published plan is dated, specific, and executable under the chain’s existing governance.
The strongest migration design among the committed chains. Post-quantum keys are derived from the recovery phrase holders already have, so accounts can move to quantum-safe authentication without changing addresses. That removes the coordination problem that makes migration hard elsewhere.
source
Placement in the band Not a 10: deriving post-quantum keys from the recovery phrase holders already have removes the coordination problem, but holders cannot migrate today, so the plan is executable rather than executed.
5 Exposure 2/10, weighted 10%
Band 0 to 2: Public keys are exposed for effectively all accounts, or a large, measured share of total supply sits in exposed addresses.
Sui uses an account model in which the public key is published when an account first transacts, so effectively all economically active supply has an exposed key today and is harvestable against a future quantum computer.
source
Placement in the band At the top of the band rather than a 0 or a 1: the key is published on first transaction rather than at account creation, so never-used accounts retain protection, though almost no active supply does.
6 Verification 8/10, weighted 5%
Band 6 to 8: Open source with public review or a named third-party audit of the relevant component.
The commitment was published by Sui under its own name with named schemes and dated milestones, and the protocol is open source, so each milestone is checkable against the calendar as it passes.
source
Placement in the band The top of the band: named schemes and dated milestones published under Sui's own name, against open source, make each milestone checkable as it passes. It stops short of 9 because there is no deployed component to audit.