What hybrid buys
The most common sentence in post-quantum vendor material is some version of “we support hybrid, so you are covered,” and the framework’s arithmetic is unmoved by it. The claim needs a precise answer rather than a dismissal, and the precise answer runs through three of the six layers. A hybrid such as X25519 with ML-KEM still contains a quantum-vulnerable classical component, so the asset stays in the layer 1 denominator. Layer 1 reads 10,000 for every institution until the last vulnerable asset retires, and a hybrid deployment does not move it by a point. At layer 2 the construction adds an implementation lineage rather than removing one, since both components’ code now executes on the path. Hybrid, counted honestly, increases the number of things you depend on.
What it changes is what a single failure costs, and the change is real. In a sound construction, breaking one component does not break the exchange. The framework’s rule compresses to one line: hybrid reduces consequence, not concentration, and it is defence in depth during migration, never diversification.
The word “sound” is doing the work
The consequence benefit exists only under conditions, and the framework names three, because coverage figures are comparable across institutions only when a hybrid means one thing.
A standardised post-quantum component. The post-quantum side is a standardised algorithm, the FIPS 203, 204 and 205 family or a successor. The parameter set meets the service’s target definition, evidenced to the same tier a pure post-quantum deployment would need.
AND-compromise composition. For key establishment, both shared secrets enter a key-derivation combiner such that the derived key stands while either component stands. For signatures, verification requires both signatures to verify. The opposite shape, where a defect in either component or in the combiner defeats the exchange, is the OR-compromise case, and it takes no credit anywhere. An OR-shaped hybrid adds a lineage dependency without adding protection, which leaves the estate in a worse position than not deploying it. The OR shape is not rare either, because it is the default outcome of bolting a second algorithm onto an exchange without redesigning the combiner.
Downgrade resistance on the path. Negotiation cannot fall back to a classical-only tuple silently. Where a fallback exists, the path’s state is the fallback’s state, because an attacker negotiates for a living. Silent fallback is free to check and rarely checked.
A path meeting all three may count at target state where the service’s definition accepts hybrids. A path failing any one counts at its classical state. And a path whose combiner or fallback behaviour cannot be established is recorded hybrid-unverified and counts below target, since an unverifiable construction is never a favourable value.
Redundancy without independence
Aviation learned this in public. United 232 lost an engine over Iowa in 1989, and the aircraft carried three independent hydraulic systems so that no single hit could remove flight control. The uncontained disk failure cut all three, because their lines ran together through the tail section the debris passed through. Three systems, one routing decision, and the redundancy the design promised had never existed. Certification practice afterwards treated claimed redundancy as unproven until the common-cause analysis was done, which is what the three-condition test is, the common-cause analysis for a hybrid.
The sharpest common cause is the quiet one. Where a hybrid’s classical and post-quantum components share an implementation lineage, even the AND case is weaker than it appears, and layer 2 records the shared ancestor. That is the fourth of our six false moves in its fullest form.
So the procurement conversation is three questions long. What are the combiner semantics, in writing. What is the fallback behaviour on the path, observed rather than configured. And what are the two components’ lineages, disclosed to the evidence tier the claim needs. Three answers, then credit, and the credit is real. One answer missing, and the honest entry is hybrid-unverified, which every reader of this framework now knows is not a favourable value. The lineage disclosure request asks the third question in writing, which is why a supplier who has answered it once can answer a hybrid review quickly.