PQC Compliance Matrix
How BrainstormRouter maps to NSM-10, EU CRA, and SWIFT 8.0 requirements
PQC Compliance Matrix
NSM-10 (National Security Memorandum on Quantum Computing)
| Requirement | BR Status | Implementation |
|---|
| Inventory cryptographic systems | Done | crypto-agility.ts algorithm registry |
| Prioritize HNDL-vulnerable data | Done | AI prompts, API keys, audit trails identified |
| Deploy PQC for key exchange | Ready | Hybrid X25519+ML-KEM-768 on OpenSSL 3.5+ |
| Deploy PQC for signatures | Ready | ML-DSA-65 dual-sign for audit entries |
| Maintain crypto agility | Done | Config-driven algorithm selection |
EU Cyber Resilience Act (CRA)
| Requirement | BR Status | Implementation |
|---|
| Cryptographic protection of data in transit | Done | TLS 1.3 with PQC hybrid key exchange |
| Vulnerability handling | Done | Graceful fallback on unsupported platforms |
| Security by design | Done | Crypto agility built into architecture |
SWIFT Customer Security Programme (CSP) 8.0
| Requirement | BR Status | Implementation |
|---|
| Protect transmitted data | Done | Hybrid PQC TLS |
| Ensure integrity of records | Done | Dual-signed audit trail (HMAC + ML-DSA) |
| Cryptographic key management | Done | Secrets Manager integration, key rotation |
Timeline
- 2025 Q4: Crypto agility layer shipped
- 2026 Q1: Hybrid PQC TLS + dual signatures
- 2026 Q2: Full FIPS 203/204 compliance testing