Count what runs

Three implementation families serve 4,200 cryptographic assets in one of our published test fixtures, at 2,400, 900 and 900. The layer-2 index computes to 4,184, and any assessor following the published rules gets 4,184. That convergence comes from one design decision.

The unit

At layer 2 the Cryptographic Concentration Index counts executing implementation families. Products, brands and suppliers are the tempting units, and none of them is the unit. The index counts the code that actually executes the in-scope cryptographic function on the asset’s primary configured path, resolved to the family it belongs to, and each asset maps to exactly one family. A fallback library sitting configured but idle is a genuine fact about the estate, and it’s recorded as a reach edge rather than a second assignment.

The same rule shapes every layer’s unit. Terminating anchor of the primary accepted path at layer 3, firmware family at layer 4, generation point at layer 6.

Why exclusivity

Exclusivity is what makes the arithmetic legitimate. The index is a Herfindahl-Hirschman computation, the concentration form supervisory audiences already read in merger review, and a Herfindahl index is only defined over a partition, meaning shares that sum to 100 because each unit is counted once. That constraint is older than any of us. Albert Hirschman built the measure for trade concentration in 1945, Orris Herfindahl adapted it for industry in 1950, and competition authorities have used it since because market shares partition a market.

Assign one asset to two units and the shares stop summing. The squares stop meaning anything, and two assessors with the same evidence produce different numbers depending on how each splits the overlap. A concentration figure that varies with the assessor’s judgement is an opinion with decimals.

What we retired

Earlier editions of this framework handled undisclosed lineage differently, and honestly so. The same cell carried a double reading, one number treating silent suppliers as independent and one treating them as potentially shared. The semantics were right and the location was wrong.

Two numbers per cell meant every report needed a paragraph explaining which one to believe. Benchmark comparisons became arguments about charity toward silence, and a supplier’s disclosure could move the headline index in either direction. Version 1.0-RC retires the mechanism. The index is single-valued over evidenced executing units, and non-disclosure moves to where uncertainty belongs, a bounded interval on failure-domain reach, the second figure every cell reports.

The retirement bought a property we consider more valuable than elegance. The index is stable under disclosure. Executing units are the institution’s own estate, so the layer-2 index computes at the lowest conformance level with no supplier data at all. Learning that two families share an ancestor moves a reach bound while the index stands still.

That’s incentive design as much as measurement design. A metric that worsened whenever a supplier answered a lineage request would teach every supplier that silence is the safe reply, which is the opposite of what a disclosure programme exists to obtain.

Rebadging, counted once

The choice also settles what happens to the most common shape of false diversity. Much of what the market sells as implementation choice is rebadging, five product names and five price lists over one upstream codebase, and a unit defined on brands would count it as five. A unit defined on what executes counts it as one, which matches what a single defect reaches. Where shared ancestry is disclosed rather than direct, the families stay distinct in the index and the shared ancestor appears as a reach node covering all of them, so neither figure overstates the estate’s diversity.

All of it is fixtured. The 4,184 above is vector TV-04 in the published set, generated by the same reference implementation that computes every canonical figure in the document family, under Apache-2.0, ten vectors, one command. Run it. If your 4,184 comes out different, one of us has an erratum, and ours are published loudly.