Compliance & Standards

QCORE-COMP-001Rev 0.9 — January 2026

FIPS 203 (ML-KEM) conformance, CNSA 2.0 alignment matrix, side-channel resistance validation methodology, and export control classifications for the QCORE-C1 chiplet.

FIPS 203 Conformance #

RequirementFIPS 203 SectionQCORE-C1 Status
ML-KEM.KeyGen correctness§7.1✓ Validated (100 KAT vectors per parameter set)
ML-KEM.Encaps correctness§7.2✓ Validated
ML-KEM.Decaps correctness§7.3✓ Validated (including implicit rejection)
Implicit rejection§7.3, Note✓ Constant-time conditional select in hardware
All three parameter sets§8✓ ML-KEM-512, 768, 1024
Approved hash functions§4.1✓ SHA3-256, SHA3-512, SHAKE-128, SHAKE-256
Random number generation§3.3External seed required (host provides 32-byte d/z)

FIPS 140-3 Targeting #

FIPS 140-3 Security Level Mapping
AreaLevel 1Level 2QCORE-C1
Cryptographic moduleApproved algorithms+ tamper evidenceLevel 2 target
Physical securityProduction-gradeTamper-evident coatingsVoltage glitch + temp detectors
Self-testsPower-on + conditionalSame✓ BIST + KAT on boot
Key managementKey storage+ key zeroization✓ Hardware zeroization (64 cycles)
Design assuranceConfiguration management+ delivery/operationIn progress

CNSA 2.0 Alignment #

NSA CNSA 2.0 Algorithm Timeline
FunctionCNSA 2.0 AlgorithmDeadlineQCORE-C1
Key EstablishmentML-KEM-10242030 (prefer by 2025)✓ Supported
Key EstablishmentML-KEM-768Acceptable interim✓ Supported
Digital SignaturesML-DSA-872035Not in scope (KEM-only accelerator)
HashSHA-384 or SHA-512ImmediateSHA3-512 via Keccak core

Side-Channel Validation #

Side-Channel Resistance Testing Methodology
TestStandardTraces RequiredResult
TVLA (Test Vector Leakage Assessment)ISO 17825100,000Pass (t-value < 4.5 at 25% dummy)
CPA (Correlation Power Analysis)—1,000,000No key recovery at 1st-order masking
Timing analysis—10,000Zero timing variation (constant-time hardware)
EM analysis (near-field probe)—500,000Pending (requires silicon samples)

Export Control Classification #

JurisdictionClassificationNotes
US (EAR)ECCN 5A002.a.1Cryptographic hardware performing encryption/decryption
US (EAR)License Exception ENC (§740.17)Eligible for mass-market exception review
WassenaarCategory 5, Part 2Information security — cryptographic hardware
US origin100% US-designed, US-fabricated (SkyWater/GF)ITAR-free, CHIPS Act eligible