Methodology · v1.4 · effective 16 August 2026
Methodology
The Hardy Score is a composite of six weighted dimensions, each scored from 0 to 10 against published anchors. This page is the whole rubric. If you disagree with a score, you should be able to work out exactly where our reading differs from yours.
The principle
Authority in a benchmark comes from showing the work, not from asserting the number. Three rules follow from that, and we hold to them throughout.
- Everything is sourced. Every dimension score carries a note and a link to a primary source: the chain's own documentation, a standards body, a public repository or a named research paper. Where we rely on a secondary source, it is labelled as one.
- Judgement calls are declared. Where a placement is contestable, the chain's profile says so in its own words and explains what a reader who weighs things differently would conclude instead.
- The score is arithmetic, not opinion. Given six dimension scores, the total is fixed. There is no adjustment, no override and no house view applied afterwards.
- Placement inside a band is stated, not assumed. Several anchors below cover more than one score. Saying the total is arithmetic would be a sleight of hand if the choice between a 7 and a 9 were left unexplained, so where a band covers a range the profile names the value we did not choose and the fact that decided it. The build refuses to publish a dataset where it does not.
The five-tier readiness spine
Every chain sits in exactly one tier. The tier answers a single question: how far has this chain actually moved, as opposed to how far it intends to move?
- Native Deployment score 10/10
Post-quantum secure at mainnet today, with quantum-resistant signatures built in from genesis.
- Shipping Deployment score 8/10
Post-quantum signature features are live on mainnet and a migration for existing holders is underway.
- Committed Deployment score 5/10
A funded roadmap with public dates and active research exists, but no post-quantum signature is live on mainnet.
- Debating Deployment score 2/10
Post-quantum work on the chain’s own signatures is documented by people with authority over it, in a formal improvement proposal or a public research programme, but no scheme is agreed and no timeline is published.
- Exposed Deployment score 1/10
The signatures securing funds on mainnet today are quantum-vulnerable, and no public post-quantum plan, proposal or research programme addressing them could be found.
Tier 5: Exposed is a statement about the published record, not about competence or intent. It records two findings together: the signatures securing funds on mainnet today are quantum-vulnerable, and we found no post-quantum plan, proposal or research programme.
Unverified is a flag, not a rung
A chain that markets itself as quantum-safe but whose deployed scheme cannot be confirmed against a primary source is not given a rung on the strength of its own marketing. One of two things happens instead. Either the row is held back, which is the default and is what we do with the chains listed on the about page, or, where the live scheme is confirmably still vulnerable, the chain is placed on the rung the evidence supports and carries a visible "Claims unverified" flag on its profile.
This keeps the ladder a measure of readiness and stops marketing from buying a position on it. No chain in the current dataset carries the flag.
The six dimensions
Each dimension is scored 0 to 10, multiplied by its weight, and divided by ten. The six weights sum to 100, so a chain scoring 10 on every dimension lands on exactly 100.
Where an anchor below covers a range, the profile prints a line headed "placement in the band" giving the reason for that exact value. That line has to name a score we did not choose, either as a number or with one of a fixed set of phrases: midpoint, top of the band, bottom of the band, top of this band, bottom of this band, the band above, the band below, floor of the band, ceiling of the band, perfect ten. The rule is checked mechanically, so it is published here rather than left as an in-house style note: a lint rule that shapes what you read should not be invisible to you.
1 Signature scheme
30%Whether the signature scheme protecting funds on mainnet today is quantum-vulnerable (ECDSA, EdDSA, Schnorr, BLS) or post-quantum (hash-based or lattice-based).
| 10 | A post-quantum signature is the mandatory scheme for all accounts on mainnet. |
|---|---|
| 7 to 9 | A post-quantum signature is available on mainnet at the protocol level as a first-class account type. |
| 4 to 6 | A post-quantum signature is available on mainnet only as an opt-in, application-level or experimental primitive. |
| 1 to 3 | Classical signatures only on mainnet, with a post-quantum implementation live and usable by the public on a persistent test network. |
| 0 | Classical signatures only on mainnet, with nothing post-quantum protecting live funds. Short-lived devnets and one-off benchmarks sit here: they demonstrate research rather than something a user can hold keys on. |
2 Deployment stage
25%How far the chain has actually moved along the five-tier readiness spine, from Native at the top to Exposed at the bottom.
| 10 | Tier 1: Native. |
|---|---|
| 8 | Tier 2: Shipping. |
| 5 | Tier 3: Committed. |
| 2 | Tier 4: Debating. |
| 1 | Tier 5: Exposed. |
3 NIST alignment
15%Whether the chosen post-quantum scheme is standardised by NIST (ML-DSA, SLH-DSA, XMSS, LMS), on the NIST standardisation track (Falcon/FN-DSA), or bespoke and unreviewed.
| 9 to 10 | The scheme in use is covered by a final NIST standard (FIPS 204, FIPS 205, or SP 800-208). |
|---|---|
| 6 to 8 | The scheme is NIST-selected but the standard is not yet final, or a NIST-approved scheme is named but not yet deployed. |
| 3 to 5 | NIST schemes are referenced as candidates without a committed selection, or the work is bespoke research. |
| 0 to 2 | No named post-quantum scheme, or a proprietary scheme with no public cryptanalysis. |
4 Migration path
15%Whether existing holders have a credible, low-loss route to quantum-safe keys, and whether the chain’s governance can plausibly deliver it.
| 9 to 10 | Holders can migrate today, or the published plan is dated, specific, and executable under the chain’s existing governance. |
|---|---|
| 6 to 8 | A credible published plan exists with a mechanism identified, but key parts are unbuilt or undated. |
| 3 to 5 | Migration is acknowledged as a problem with no agreed mechanism, or the mechanism is contested. |
| 0 to 2 | No agreed migration path, or the proposals on the table would strand or freeze holder funds. |
5 Exposure
10%The share of supply or accounts whose public keys are already visible on-chain, which is what makes harvest-now-decrypt-later attacks possible.
| 9 to 10 | No quantum-vulnerable public keys are exposed on-chain, or the exposed keys protect nothing. |
|---|---|
| 6 to 8 | Addresses are key hashes and exposure is limited to spent outputs, keeping a meaningful share of supply unexposed. |
| 3 to 5 | Most active accounts have revealed a public key, or the chain has no live supply to assess. |
| 0 to 2 | Public keys are exposed for effectively all accounts, or a large, measured share of total supply sits in exposed addresses. |
6 Verification
5%Whether the chain’s post-quantum claims are backed by open source, third-party audits and independent review, or rest on marketing.
| 9 to 10 | Open source, independently audited, with the claim checkable on-chain or in public research. |
|---|---|
| 6 to 8 | Open source with public review or a named third-party audit of the relevant component. |
| 3 to 5 | Some independent verification exists, but the headline quantum-safety claim itself is not verified. |
| 0 to 2 | Claims rest on marketing material with no independent verification. |
The calculation
The Hardy Score is the weighted sum of the six dimension scores, expressed on a 0 to 100 scale and rounded to one decimal place.
Hardy = ( signature × 30
+ deployment × 25
+ nist × 15
+ migration × 15
+ exposure × 10
+ verification × 5 ) / 10
each dimension scored 0 to 10, maximum 100.0 Why deployment is derived, not scored
The deployment dimension is not an independent judgement. It is the tier expressed as a number, using the fixed mapping in the spine above: Tier 1 scores 10, Tier 2 scores 8, Tier 3 scores 5, Tier 4 scores 2 and Tier 5 scores 1.
This is deliberate. If deployment were scored separately, a chain's tier and its score could drift apart and the rubric would have a place for a thumb to rest on the scale. Deriving it means the build fails if an editor sets a deployment score that contradicts the tier. The inconsistency cannot be published.
Tier 5 maps below Tier 4 on purpose. A chain that has published nothing at all on the threat has demonstrated less than a chain that openly acknowledges the problem and has proposals on the table, even where neither has a post-quantum signature running.
Why the score is a weighted sum, not a weakest link
There is more than one defensible way to compose a readiness score, and the choice deserves stating rather than assuming.
Enterprise quantum-readiness frameworks generally do the opposite of what we do. QRAMM, the open maturity model published by CyberSecurity NonProfit, scores each of its four dimensions as the lowest of the practices beneath it, and only then averages the four. The reasoning is sound: an organisation with one unaddressed gap is exposed through that gap, whatever the rest of its programme looks like, and a self-assessment should stop a firm averaging away the thing that will actually breach it.
That rule fits a framework whose reader and subject are the same party. This is a benchmark, where they are not. Two things follow. A third party is comparing chains against each other, so the score has to discriminate between them, and a weakest-link rule collapses that comparison: every chain holding a zero on any single dimension lands in the same place, which is most of the field. And a chain is not an organisation running a remediation programme. Some dimensions here are structural rather than volitional, exposure in particular, which follows from an address model chosen years before the threat was legible. Scoring the minimum would read those inherited facts as failures of effort.
The cost of a weighted sum is real and runs the other way: a strong dimension can mask a weak one in the total. Three things hold that in check. All six dimensions are published separately on every profile, so the total is never the only number a reader sees. The tier is a separate statement that is never averaged into anything, and it reports deployment alone. And more than half the weight, 55%, sits on the signature scheme and the deployment stage together, which are the two dimensions a chain can least easily compensate for elsewhere.
Why market value and chain age are not in the score
Readiness indices do not all run in the same direction, and they do not all measure the same thing. Two differences are worth stating plainly, so a reader comparing this index against another knows what they are holding.
Direction. On the Hardy Index a high number is good: 100 is fully prepared and 0 is wholly exposed. Some indices score vulnerability instead, where a high number is bad and the best-prepared chain sits at the bottom of the table. The two kinds of number look alike and mean opposite things.
Composition. Some readiness scores fold in the value held on the chain and the length of time it has been running, on the reasoning that a larger, older chain has more at stake and a longer window in which public keys could have been harvested. Both of those risks are real. Neither is in the Hardy Score.
They are excluded because they measure consequence rather than preparation. A chain does not become less ready when its token appreciates. Folding market value into a readiness score marks a chain down for being successful, marks a small chain up for being small, and moves the ranking on a day when nothing about the cryptography has changed. The risk those factors reach for is scored here, but through the exposure dimension, which measures the share of supply whose public keys are already visible rather than inferring it from the chain's age.
This is why Bitcoin is not at the bottom of this index. Bitcoin carries the largest measured exposure and by far the most value at risk of any chain rated here, and it still ranks above chains that have published nothing at all, because it is debating the problem in the open with a live proposal on the table. This index ranks preparation. It does not rank how much there is to lose.
What the score does not measure
The Hardy Score is narrow by design, and reading it as anything broader will mislead you.
- It does not measure whether a chain is a good investment, and it is not investment advice.
- It does not measure liquidity, market capitalisation, adoption, developer activity or ecosystem size.
- It does not measure general security. A chain can score highly here and be weak against entirely conventional attacks.
- It does not predict when a cryptographically relevant quantum computer will exist. It measures preparedness for the possibility, not the probability of the event.
The say-do record, published beside the score and not inside it
A chain can announce post-quantum work indefinitely without shipping any, and announcing is cheaper than shipping. From v1.4, where we can compile one, each profile carries a record of the chain's dated public commitments over a stated window and what followed on mainnet, with a counted summary line: how many shipped, how many shipped in part, how many did not.
It does not enter the Hardy Score, and it never will in this form. Three reasons, and the first is the one that matters. The score's whole claim is that a reader can reproduce it from six published dimension scores and six published weights. A seventh input derived from a corpus we assembled ourselves cannot be reproduced by anyone who does not have our corpus, and the claim would quietly stop being true.
The second is that any weight on how much a chain has said is a weight on press-release volume. A chain that publishes a detailed, honest roadmap and then slips it would be marked down against a chain that published nothing at all, which is the opposite of the behaviour this index should encourage. The third is arithmetic: a shipped-to-announced ratio divides by zero on precisely the chains the measure is aimed at, and every way of handling that case is a judgement call dressed up as a calculation.
So the record is counted rather than scored, and the entries are printed rather than summarised into a coefficient. A count can be checked against the list underneath it. That is the point of publishing it this way.
What we count as a commitment:
- A dated, public statement by the chain's foundation, its core development team, or a formally adopted improvement proposal, naming a specific post-quantum deliverable.
- Marketing that names no deliverable is not a commitment, and neither is a third party's prediction about the chain, however well informed.
- Shipped means the named thing is live on mainnet. In part means some of the named scope is live, or it is live somewhere that is not mainnet. Not shipped means a stated date has passed with nothing live, or no dated delivery has followed.
- Below three commitments we publish no record at all. Two entries is an anecdote, and a layout like this one would lend it the authority of a register.
Exposure as a quantity, where somebody has measured one
The exposure dimension is a 0 to 10 score, and as the limits below say, it is scored on address structure as much as on measurement. That leaves a reader without the figure they actually need, which is how much is exposed. From v1.4, where a credible measurement exists, the profile prints it: the amount, the share of supply where the source states one, who measured it and when.
Where sources disagree we print all of them rather than choosing. Bitcoin is the case this rule was written for, with published estimates running from about 4 million BTC to about 7 million. The spread is not noise to be averaged away: it is where each analyst draws the line between exposed and unexposed, and a reader who can see three figures and three methods is better informed than one handed a single number with the disagreement hidden behind it.
A measurement is evidence behind the exposure score, not a separate input alongside it. The dimension is still scored against the published anchors, so printing the figure changes the profile and not the arithmetic.
Update cadence and corrections
Every chain carries an "as of" date, and the index carries the most recent of them. Scores change when the underlying facts change, and every change is logged in the changelog with a reason and a source.
Phase 1 of this index is maintained editorially: a person reads the primary sources and writes the note. If you believe a score is wrong, the useful thing to send is the primary source that contradicts it, to index@hardyindex.com. Corrections are logged publicly, including the ones we get wrong.
Known limits of this rubric
Stating a rubric's weaknesses is part of publishing it. Five are worth knowing.
- The signature and deployment dimensions are related, and they carry 55% between them. They are not the same measure: signature reports what protects funds on mainnet today, deployment reports how far along the spine the chain has moved. But they correlate strongly, because a chain with a post-quantum signature live at genesis is also a chain near the top of the spine. A reader should treat them as one signal seen from two angles rather than two independent confirmations, and the weight they carry together is the strongest single assumption in this rubric.
- NIST alignment rewards standardisation, not security. A scheme that is rigorously peer-reviewed, audited and well understood cannot score above the middle of that dimension unless it sits on the NIST track. That is a deliberate trade: a benchmark needs a reference that we do not get to adjust, and a national standards process is the only one available that is external to both us and the chains. It is still a real cost, and a chain running a strong non-NIST scheme is marked down here for a reason that is about institutional process rather than cryptography.
- Availability is not adoption. The signature dimension credits a post-quantum scheme that is live and usable on mainnet, even where very few accounts use it. A chain can score meaningfully on this dimension while almost all of its value remains classically protected.
- Exposure is scored on structure as much as on measurement. Only a few chains have published, independent measurements of exposed supply. For the rest we score the address model, which determines exposure but does not quantify it.
- Pre-mainnet chains distort the exposure dimension. A chain with no live network has no exposed supply, which is an absence of risk rather than an achievement. We score those cases at the neutral midpoint and say so, but the dimension still flatters them.
- The say-do record is not exhaustive. It holds the commitments we found in public sources over the window each profile states. A commitment we missed is a commitment the count omits, and a chain that communicates in a language we do not read, or in a forum we do not follow, will be undercounted. This is the reason the entries are listed rather than summarised: the list is auditable and a coefficient would not be. Send us the ones we have missed.
This is a security-readiness assessment, not investment advice.