The achievable frontier
An institution reading 6,000 at layer 2 may already hold the most diversified position the market supports. One reading 2,400 may hold the only two independent lineages that exist. The index cannot tell these two estates apart, and the Universal Framework says so in writing. A band table read without market context turns a supply problem into a blame assignment.
What the bands do not measure
The bands measure the position an institution occupies. They do not measure what the market sells, and at layers 2, 4 and 6 the achievable score is bounded by supply. The number of genuinely independent post-quantum lineages available to any buyer is in the single digits, and firmware families and key-generation designs are fewer than the brands selling them, for the rebadging reasons the unit definition exists to catch.
The public record of the post-quantum supply chain makes the bound concrete.
PQClean, which has influenced a significant body of post-quantum implementation work, was archived read-only on 4 August 2026. mlkem-native now supplies ML-KEM implementation code to projects including liboqs and AWS-LC. Downstream software may obtain ML-KEM through providers incorporating those implementations. A buyer shopping for a genuinely independent second lineage is choosing from a short list, and parts of the list share ancestors.
Reporting against the frontier
Two consequences follow for anyone publishing a reading, and the framework makes both mandatory. A reading above a band boundary at the supply-bounded layers is reported with its market context, meaning how many independent dependencies were available to buy and how many the institution actually bought. And risk appetite is set against the frontier rather than against the band table alone, because an appetite every market participant would breach produces no behaviour. It produces paperwork.
Portfolio theory reached the same conclusion at its founding. Harry Markowitz’s 1952 frontier was never an instruction to diversify without limit. It was the set of best positions available given the assets that actually exist and how they move together.
Setting a target beyond it is a category error, not ambition, and a cryptographic estate has an efficient frontier too, one that at three of the six layers is close, known, and shared by every buyer in the market.
The determination log is what separates a 6,000 bought at the frontier from a 6,000 arrived at by neglect. The first records the short list of available independent lineages, the ones purchased, and the reasoning behind the selection.
The second records nothing, and an assessor reading the log tells the difference in one minute, which no index value permits. The distinction decides whether a finding becomes a remediation demand or a documented market limit.
The sector reading
The last consequence belongs to supervisors rather than institutions. The count of independent lineages in the supplier market, and the disclosure response rate, are themselves concentration figures, and they bound what any single institution’s remediation can achieve. A supervisor aggregating institutional results should publish both numbers alongside the aggregate. A sector target that ignores the frontier assigns institutions homework the market cannot grade.
That sentence is also the honest justification for our frontier census. If the frontier bounds every remediation programme in the sector, somebody has to measure the frontier, on a dated snapshot, with per-claim evidence grades and a published silent share. The first snapshot arrives with v1.0 final in November, payments-scoped, built from public certification listings by the framework’s own published technique.
Until the market widens, the practical advice is unheroic. Buy the independence that exists, document what was available when you bought it, and set appetite against the market you are actually in. A remediation target should name a purchasable position, and at three layers that is a shorter sentence than most risk committees expect.