Frontier Census – Methodology

The Public Record

The census measures implementation-lineage and key-generation-design concentration across the payments cryptographic frontier: the validated modules inside payment HSMs, terminals and adjacent scheme infrastructure. It is an Applied Quantum property built with the framework’s own published technique. No CCF document depends on a census figure.

Method, at the level the Technical Companion publishes. Enumerate the validated cryptographic modules on the payments frontier from public certification listings. Retrieve each module’s published non-proprietary security policy. Extract named upstream libraries, integrity function names, repository references and entropy-design statements. Resolve toward lineage and design nodes, and grade every claim: a policy naming an upstream is vendor-published free text, an attestation agreeing with a policy is corroboration, and the absence of a named upstream is never evidence of an independent implementation.

Publication. Semiannual dated snapshots, the first with v1.0 final in November 2026. Every snapshot carries its date, its enumeration basis, per-claim evidence grades, and the register of modules whose policies say nothing, published as a share in every snapshot. Vendors named in a snapshot receive the same right-of-reply window the payments whitepaper’s Section 5 defines, and replies or their absence publish with the snapshot.

What the census does not claim. It is not a market-share estimate, a vulnerability assertion against any module, or a completeness claim about any vendor’s product line. It measures what the public certification record supports, tiered, and stops there.