• Uncategorized ccframework what hybrid buys

    What hybrid buys

    The vendor sentence says hybrid means covered. The counting says otherwise, layer 1 still reads 10,000 and layer 2 gained a lineage. What hybrid buys is a smaller consequence for a single break, under three verifiable conditions, and the entry recorded when nobody can verify the combiner is hybrid-unverified.

    Read More »
  • Uncategorized ccframework end to end or not at all

    End to end, or not at all

    A path protected at your endpoint and exposed at the counterparty's is a protected half, and Effective Coverage counts it as unprotected. The metric takes the minimum across every party and every hop, never the average, and classifies every counterparty by who can move them. A zero from this metric arrives with a plan attached.

    Read More »
  • Uncategorized ccframework the achievable frontier

    The achievable frontier

    A band table measures a holding. The supplier market decides which holdings exist to buy, and independent post-quantum lineages number in the single digits. Why every reading above a boundary carries its market context, why appetite is set against what the market sells, and what a determination log proves that no index can.

    Read More »
  • Uncategorized ccframework the reviewer error catalogue

    The reviewer error catalogue

    The clearest finding of our review process was about the reviewers: confidence and accuracy ran in opposite directions. The framework's answer was a standing rule, no claim adopted without primary-source verification, and a catalogue, the ten validator errors, in order of frequency, published in the Universal itself.

    Read More »
  • Uncategorized ccframework similarity is not lineage

    Similarity is not lineage

    Over late 2023 and early 2024, a secret-dependent timing flaw crossed multiple Kyber implementations at once. Where derivation is evidenced, that is one dependency wearing several names. Where it is not, the framework bars the leap: similarity of vulnerability alone never creates an edge. Our rule, now normative.

    Read More »
  • Uncategorized ccframework silence is a bound

    Silence is a bound

    The last row of our reviewer error catalogue is the worst one: a layer-6 cell with no entropy data, read as diversified. Absence recorded as good news inverts the finding entirely. The framework's answer is one rule applied everywhere it binds, and it prices a supplier's silence in reach points.

    Read More »
  • Uncategorized ccframework running 2017 through the framework

    Running 2017 through the framework

    The framework's first validation runs backwards. We take the 2017 ROCA disclosure, feed the public record through all six layers, and check whether a second line would have seen the concentration before the suspension made it public. What the retrodiction validates, what it cannot, and where the evidence tiers land.

    Read More »
  • Uncategorized ccframework 4 900 not 5 000

    4,900, not 5,000

    A correction story with a moral about round numbers. The Universal derives the Highly-concentrated boundary at 4,900 from the 70% largest-share bound, our script encoded 5,000, and the specification took precedence. What we fixed, what we checked afterwards, and why the gap between the two values held nothing.

    Read More »
  • Uncategorized ccframework six false moves

    Six false moves

    Multi-vendor sourcing from one code lineage. Two platforms from one firmware family. Redundant roots chained to one anchor. Every one of them rearranges the supplier list and leaves every layer where it was, and the one-line diagnostic at the end of Part E catches all six before the money is spent.

    Read More »
  • Uncategorized CC Framework

    Two figures, on purpose

    One number cannot be both a stable index and an honest account of how far a shared upstream failure travels, so every layer reports two. Why the pair exists, what the spread between evidenced reach and its bound is priced in, and the tolerance question the second figure answers that the first never could.

    Read More »