---
title: The Hardy Score methodology
url: "https://hardyindex.com/methodology"
version: 1.1
effective: 2026-08-12
---

# Methodology

The Hardy Score is a composite of six weighted dimensions, each scored from 0 to 10 against published anchors. This page is the whole rubric.

**Version 1.1, effective 12 August 2026.**

> This is a security-readiness assessment, not investment advice.

## The principle

Authority in a benchmark comes from showing the work, not from asserting the number.

- **Everything is sourced.** Every dimension score carries a note and a link to a primary source.
- **Judgement calls are declared.** Where a placement is contestable, the chain's profile says so.
- **The score is arithmetic, not opinion.** Given six dimension scores, the total is fixed.

## The five-tier readiness spine

1. **Native**: Post-quantum secure at mainnet today, with quantum-resistant signatures built in from genesis. (Deployment dimension: 10/10)
2. **Shipping**: Post-quantum signature features are live on mainnet and a migration for existing holders is underway. (Deployment dimension: 8/10)
3. **Committed**: A funded roadmap with public dates and active research exists, but no post-quantum signature is live on mainnet. (Deployment dimension: 5/10)
4. **Debating**: The threat is acknowledged and proposals exist, but there is no consensus and no published timeline. (Deployment dimension: 2/10)
5. **Exposed**: The signatures securing funds on mainnet today are quantum-vulnerable, and no public post-quantum plan, proposal or research programme could be found. (Deployment dimension: 1/10)

Tier 5: Exposed is a statement about the published record, not about competence or intent. It records two findings together: the signatures securing funds on mainnet today are quantum-vulnerable, and no post-quantum plan, proposal or research programme could be found.

### Unverified is a flag, not a rung

A chain that markets itself as quantum-safe but whose deployed scheme cannot be confirmed against a primary source is not given a rung on the strength of its own marketing. Either the row is held back, which is the default, or, where the live scheme is confirmably still vulnerable, the chain is placed on the rung the evidence supports and carries a visible "Claims unverified" flag on its profile. This keeps the ladder a measure of readiness and stops marketing from buying a position on it. No chain in the current dataset carries the flag.

## The six dimensions

### 1. Signature scheme: 30%

Whether the signature scheme protecting funds on mainnet today is quantum-vulnerable (ECDSA, EdDSA, Schnorr, BLS) or post-quantum (hash-based or lattice-based).

- **10**: A post-quantum signature is the mandatory scheme for all accounts on mainnet.
- **7 to 9**: A post-quantum signature is available on mainnet at the protocol level as a first-class account type.
- **4 to 6**: A post-quantum signature is available on mainnet only as an opt-in, application-level or experimental primitive.
- **1 to 3**: Classical signatures only on mainnet, with a post-quantum implementation running on a public testnet or devnet.
- **0**: Classical signatures only on mainnet, with nothing post-quantum protecting live funds.

### 2. Deployment stage: 25%

How far the chain has actually moved along the five-tier readiness spine, from Native at the top to Exposed at the bottom.

- **10**: Tier 1: Native.
- **8**: Tier 2: Shipping.
- **5**: Tier 3: Committed.
- **2**: Tier 4: Debating.
- **1**: Tier 5: Exposed.

### 3. NIST alignment: 15%

Whether the chosen post-quantum scheme is standardised by NIST (ML-DSA, SLH-DSA, XMSS, LMS), on the NIST standardisation track (Falcon/FN-DSA), or bespoke and unreviewed.

- **9 to 10**: The scheme in use is covered by a final NIST standard (FIPS 204, FIPS 205, or SP 800-208).
- **6 to 8**: The scheme is NIST-selected but the standard is not yet final, or a NIST-approved scheme is named but not yet deployed.
- **3 to 5**: NIST schemes are referenced as candidates without a committed selection, or the work is bespoke research.
- **0 to 2**: No named post-quantum scheme, or a proprietary scheme with no public cryptanalysis.

### 4. Migration path: 15%

Whether existing holders have a credible, low-loss route to quantum-safe keys, and whether the chain’s governance can plausibly deliver it.

- **9 to 10**: Holders can migrate today, or the published plan is dated, specific, and executable under the chain’s existing governance.
- **6 to 8**: A credible published plan exists with a mechanism identified, but key parts are unbuilt or undated.
- **3 to 5**: Migration is acknowledged as a problem with no agreed mechanism, or the mechanism is contested.
- **0 to 2**: No agreed migration path, or the proposals on the table would strand or freeze holder funds.

### 5. Exposure: 10%

The share of supply or accounts whose public keys are already visible on-chain, which is what makes harvest-now-decrypt-later attacks possible.

- **9 to 10**: No quantum-vulnerable public keys are exposed on-chain, or the exposed keys protect nothing.
- **6 to 8**: Addresses are key hashes and exposure is limited to spent outputs, keeping a meaningful share of supply unexposed.
- **3 to 5**: Most active accounts have revealed a public key, or the chain has no live supply to assess.
- **0 to 2**: Public keys are exposed for effectively all accounts, or a large, measured share of total supply sits in exposed addresses.

### 6. Verification: 5%

Whether the chain’s post-quantum claims are backed by open source, third-party audits and independent review, or rest on marketing.

- **9 to 10**: Open source, independently audited, with the claim checkable on-chain or in public research.
- **6 to 8**: Open source with public review or a named third-party audit of the relevant component.
- **3 to 5**: Some independent verification exists, but the headline quantum-safety claim itself is not verified.
- **0 to 2**: Claims rest on marketing material with no independent verification.

## The calculation

    Hardy = ( signature    x 30
          + deployment   x 25
          + nist         x 15
          + migration    x 15
          + exposure     x 10
          + verification x  5 ) / 10

Each dimension is scored 0 to 10. The maximum is 100.0.

## Why deployment is derived, not scored

The deployment dimension is the tier expressed as a number: Tier 1 scores 10, Tier 2 scores 8, Tier 3 scores 5, Tier 4 scores 2 and Tier 5 scores 1. If deployment were scored separately, a chain's tier and its score could drift apart. Deriving it means the build fails if an editor sets a deployment score that contradicts the tier.

Tier 5 maps below Tier 4 on purpose. A chain that has published nothing at all on the threat has demonstrated less than a chain that openly acknowledges the problem and has proposals on the table, even where neither has a post-quantum signature running.

## What the score does not measure

- It does not measure whether a chain is a good investment, and it is not investment advice.
- It does not measure liquidity, market capitalisation, adoption, developer activity or ecosystem size.
- It does not measure general security.
- It does not predict when a cryptographically relevant quantum computer will exist.

## Known limits of this rubric

- **Availability is not adoption.** The signature dimension credits a post-quantum scheme that is live and usable on mainnet, even where very few accounts use it.
- **Exposure is scored on structure as much as on measurement.** Only a few chains have published, independent measurements of exposed supply.
- **Pre-mainnet chains distort the exposure dimension.** A chain with no live network has no exposed supply, which is an absence of risk rather than an achievement.

## Update cadence and corrections

Every chain carries an "as of" date. Scores change when the underlying facts change, and every change is logged at https://hardyindex.com/changelog with a reason and a source. Send corrections, with the primary source that contradicts us, to index@hardyindex.com.
