# QuantumSafe Procurement & Public-Claims Checklist

## Product identification
- [ ] Exact product name, model, version and firmware are stated.
- [ ] Supplier, manufacturer and integration partner roles are distinguished.
- [ ] Production, pilot, architecture, roadmap and research states are not mixed.

## FIPS and validation
- [ ] The exact certificate number and live status are verified.
- [ ] The validated module boundary and approved services match the ordered configuration.
- [ ] FIPS 140-3 module validation is not described as PQC algorithm validation.
- [ ] CAVP/ACVP or other algorithm evidence is referenced separately where applicable.

## PQC capability
- [ ] Algorithm, parameter set, provider, firmware and platform are named.
- [ ] Hybrid composition and verifier behavior are documented.
- [ ] Unsupported or untested combinations are disclosed.
- [ ] The product capability matrix and claim register are approved.

## Interoperability and performance
- [ ] OS/runtime/application/relying-party versions are listed.
- [ ] Signed sample corpus and expected verification results are supplied.
- [ ] Latency, throughput, object-size and capacity impact are measured.
- [ ] Known limitations, fallback and rollback are accepted.

## Security and lifecycle
- [ ] Threat model, security architecture and key boundary are available.
- [ ] Vulnerability disclosure and security-advisory processes are published.
- [ ] Patch, maintenance, EOL/EOS and migration policies are contractual.
- [ ] SBOM/CBOM and supply-chain requirements are agreed where needed.

## Delivery and acceptance
- [ ] Secure delivery, personalization, key ceremony and custody are defined.
- [ ] Acceptance test and evidence package are part of the contract.
- [ ] SLA, support, incident response and recovery responsibilities are clear.
- [ ] Data residency and managed-service boundaries are approved.

## Prohibited wording without specific evidence
- “100% quantum proof”
- “Unbreakable”
- “PQC certified”
- “Supports all PQC algorithms”
- “Compatible with all systems”
- “FIPS-certified quantum-safe token”
