GOVERNED CLAIMS REGISTER
Public wording must have an evidence source and limitation.
Approved public claims, status, evidence source, scope, owner, limitations and approval state.
| ID | Public claim | Status | Evidence source | Version / scope | Owner | Limitations | Approval |
|---|---|---|---|---|---|---|---|
| CLM-001 | Trusted Key Token is a FIPS 140-3 Level 3 validated hardware cryptographic module | Validated | NIST CMVP Certificate #5331 and public Security Policy | Identified module and validated firmware/configuration | Product Security | Does not imply PQC algorithm validation | Approved |
| CLM-002 | Mobile-ID provides QuantumSafe readiness, architecture, pilot, migration, validation and operation services | Available service | Service catalogue and approved statement of work templates | Project-defined scope | QuantumSafe Program | Specific product capability remains version-specific | Approved |
| CLM-003 | Specific ML-KEM/ML-DSA/Hybrid capability | Pilot / release-specific | Approved capability matrix and project evidence | Algorithm, parameter, provider, firmware, OS and application required | Product Engineering | Not covered by #5331 unless separately evidenced | Conditional |
