NIST FIPS 203 — ML-KEM
Technical alignmentFinal NIST post-quantum key-encapsulation standard used as a structured migration target.
Official referenceTrust Center
RelixQ separates technical standards, customer evidence support, and vendor assurance. Product alignment is not customer certification, and assurance roadmap items are not achieved audits.
Evidence posture
Technical mappings and claim boundaries are public; independent assurance evidence is gated and not yet claimed as achieved.
Framework relationships
Final NIST post-quantum key-encapsulation standard used as a structured migration target.
Official referenceFinal NIST post-quantum digital-signature standard used as a structured migration target.
Official referenceFinal NIST stateless hash-based signature standard used as a structured migration target.
Official referenceDraft transition guidance used for planning context. It is not represented as a final NIST publication.
Official referenceA control-mapping pack and six dated algorithm profiles from 2025 to 2035. Citation and verdict content only; nothing asserts that CNSA 2.0 binds the scanned organization.
Mapped to detection rules because each names an algorithm, key length, mode, or protocol. National guidance covers BSI TR-02102, ANSSI PG-083, CCCS ITSP.40.062 and .111, CRYPTREC LS-0001, NCA NCS-1:2020, and ICP-Brasil DOC-ICP-01.01.
Signed packs relate finding evidence to SC-12, SC-13, SC-8(1), SC-28(1); 03.13.08, 03.13.10, 03.13.11; and PR.DS-01, PR.DS-02. Every mapping is background evidence for a customer control. None is an assessment result, an authorization, or a tier determination.
Relates finding evidence to the two addressable encryption specifications. Whether a system holds electronic protected health information is never visible to a scanner, so applicability is always the customer determination.
Relates a customer finding to criteria the customer is examined against. This is product content for a customer SOC 2 program. It is unrelated to RelixQ vendor assurance, and RelixQ does not claim a completed SOC 2 examination.
ISO controls are cited by identifier only. PCI DSS maps Requirement 4 alone, because the other requirements are process obligations a scanner cannot observe. Sector packs cover financial services, government and critical infrastructure, UAE instruments, and ETSI quantum-safe reports.
Control mapping and examination roadmap only. RelixQ does not claim a completed SOC 2 examination.
Information-security management roadmap only. RelixQ does not claim ISO/IEC 27001 certification.
RelixQ artifacts can support an assessment; they do not certify the customer or provide a legal opinion.
Claim register
Each statement carries its own scope, evidence posture, framework relationship, and review date. Roadmap language remains visibly separate from achieved controls.
Published claim
RelixQ can align product analysis to a technical standard, produce artifacts that support a customer control program, and operate its own vendor-assurance program. None of those statements automatically certifies a customer or converts a roadmap milestone into an achieved audit.
Evidence
Public summaryThe claim boundary is encoded in the public catalog and Trust Center.
Framework context
Customer security and resilience programs
Customer evidence support — RelixQ artifacts can support an assessment; they do not certify the customer or provide a legal opinion.
AICPA Trust Services Criteria / SOC 2
Assurance roadmap — Control mapping and examination roadmap only. RelixQ does not claim a completed SOC 2 examination.
ISO/IEC 27001
Assurance roadmap — Information-security management roadmap only. RelixQ does not claim ISO/IEC 27001 certification.
Published claim
RelixQ uses FIPS 203, FIPS 204, and FIPS 205 as final NIST migration targets. NIST IR 8547 is presented accurately as an Initial Public Draft used for transition-planning context.
Evidence
Design evidenceRules, findings, and reports carry named standards and source references.
Framework context
NIST FIPS 203 — ML-KEM
Technical alignment — Final NIST post-quantum key-encapsulation standard used as a structured migration target.
NIST FIPS 204 — ML-DSA
Technical alignment — Final NIST post-quantum digital-signature standard used as a structured migration target.
NIST FIPS 205 — SLH-DSA
Technical alignment — Final NIST stateless hash-based signature standard used as a structured migration target.
NIST IR 8547 — Initial Public Draft
Technical alignment — Draft transition guidance used for planning context. It is not represented as a final NIST publication.
Published claim
Inventory, CBOM, findings, policies, exceptions, release decisions, retests, and audit history can support customer assessments. RelixQ does not certify the customer, determine legal compliance, or replace the customer assessor.
Evidence
Gated evidenceCustomer artifacts are reviewable within the customer scope and are not vendor certifications.
Framework context
Customer security and resilience programs
Customer evidence support — RelixQ artifacts can support an assessment; they do not certify the customer or provide a legal opinion.
NIS2 and DORA
Customer evidence support — Risk-management evidence support only; not legal advice or certification.
PCI DSS, HIPAA, and GDPR security programs
Customer evidence support — Technical evidence support only; applicability and compliance remain the customer responsibility.
Published claim
RelixQ ships signed standards packs that relate cryptographic findings to customer-owned controls: NIST SP 800-53 Rev. 5, SP 800-171 Rev. 3, CSF 2.0, the HIPAA Security Rule, the AICPA Trust Services Criteria, ISO/IEC 27001 and 27002, PCI DSS v4.0.1, CNSA 2.0, and narrow sector packs. A pack contributes nothing until an organization owner activates it with a written statement of why it applies, and the signature is verified again at that moment. Control-mapping packs are non-blocking: they can warn but never fail a release. A pack that matches nothing reports insufficient evidence, which is never treated as a pass. No pack asserts that a regulation binds the customer or that a control is satisfied.
Evidence
Design evidencePack content, signing, activation, and verdict rules are product source and test evidence. Availability in a given tenant follows the managed-service release, and production operating evidence is not yet claimed.
Framework context
NIST SP 800-53 Rev. 5, SP 800-171 Rev. 3, and CSF 2.0 (customer control packs)
Customer evidence support — Signed packs relate finding evidence to SC-12, SC-13, SC-8(1), SC-28(1); 03.13.08, 03.13.10, 03.13.11; and PR.DS-01, PR.DS-02. Every mapping is background evidence for a customer control. None is an assessment result, an authorization, or a tier determination.
HIPAA Security Rule, 45 CFR § 164.312 (customer control pack)
Customer evidence support — Relates finding evidence to the two addressable encryption specifications. Whether a system holds electronic protected health information is never visible to a scanner, so applicability is always the customer determination.
AICPA Trust Services Criteria CC6.1 and CC6.7 (customer control pack)
Customer evidence support — Relates a customer finding to criteria the customer is examined against. This is product content for a customer SOC 2 program. It is unrelated to RelixQ vendor assurance, and RelixQ does not claim a completed SOC 2 examination.
ISO/IEC 27001 and 27002, PCI DSS v4.0.1, and sector packs (customer control packs)
Customer evidence support — ISO controls are cited by identifier only. PCI DSS maps Requirement 4 alone, because the other requirements are process obligations a scanner cannot observe. Sector packs cover financial services, government and critical infrastructure, UAE instruments, and ETSI quantum-safe reports.
NSA CNSA 2.0
Technical alignment — A control-mapping pack and six dated algorithm profiles from 2025 to 2035. Citation and verdict content only; nothing asserts that CNSA 2.0 binds the scanned organization.
Published claim
RelixQ maintains a catalog of 204 standards, regulations, and guidance documents. A reference is mapped to detection rules only when it names something a scanner can observe, such as an algorithm, a key length, a mode, or a protocol; 34 are mapped on that basis. 138 are deliberately left unmapped, including principles-based instruments such as GDPR, NIS2, DORA, LGPD, and POPIA, because matching them to rules would be a guess. An organization selects one of eight compliance regions to scope which citations it sees. The region is a display filter and is never a determination that a regulation applies.
Evidence
Design evidenceThe counts are taken from the generated coverage report, and each record carries a verification flag and date. Nine records are marked unverified because the issuing body blocks automated retrieval, and unverified records are never mapped.
Framework context
NIST SP 800-131A, 800-57, 800-56A/B, 800-38A/D, 800-52, 800-208, and national guidance
Technical alignment — Mapped to detection rules because each names an algorithm, key length, mode, or protocol. National guidance covers BSI TR-02102, ANSSI PG-083, CCCS ITSP.40.062 and .111, CRYPTREC LS-0001, NCA NCS-1:2020, and ICP-Brasil DOC-ICP-01.01.
NIST IR 8547 — Initial Public Draft
Technical alignment — Draft transition guidance used for planning context. It is not represented as a final NIST publication.
Customer security and resilience programs
Customer evidence support — RelixQ artifacts can support an assessment; they do not certify the customer or provide a legal opinion.
Published claim
SOC 2 Type II, ISO/IEC 27001, independent penetration testing, continuity testing, CAIQ, and expanded security questionnaires are roadmap work. Achieved reports or certifications will be published only with exact scope, period, and issuing party.
Evidence
Not availableNo completed SOC 2 Type II report or ISO/IEC 27001 certificate is claimed.
Framework context
AICPA Trust Services Criteria / SOC 2
Assurance roadmap — Control mapping and examination roadmap only. RelixQ does not claim a completed SOC 2 examination.
ISO/IEC 27001
Assurance roadmap — Information-security management roadmap only. RelixQ does not claim ISO/IEC 27001 certification.
Roadmap distinction
Documented controls, operating evidence, independent testing, and formal assurance appropriate to enterprise procurement.
Roadmap work is not a completed examination, certification, penetration test, or contractual warranty.
Published claim
RelixQ does not currently claim SOC 2 completion or ISO/IEC 27001 certification. Product standards support and customer evidence mappings must not be read as vendor certification.
Evidence
Public summaryThe non-claim is explicit and reviewable.
Framework context
AICPA Trust Services Criteria / SOC 2
Assurance roadmap — Control mapping and examination roadmap only. RelixQ does not claim a completed SOC 2 examination.
ISO/IEC 27001
Assurance roadmap — Information-security management roadmap only. RelixQ does not claim ISO/IEC 27001 certification.
Publication boundary
This page is a public summary. Detailed evidence may still require controlled access, an NDA, or an active procurement review. The catalog entry was last reviewed on .