{
  "report": "NIST ACVP ML-DSA-65 (post-quantum)",
  "id": "nist-acvp-mldsa65",
  "component": "FIPS 204 accept/reject vectors — in-scope modes",
  "suite_file": "test/test_nist_acvp_mldsa65.mjs",
  "suite_file_sha256": "f91c404d16b16a33ffb9b78a0e0bb32e48ac79dbe0fb09bec1c4410c7a1c58dc",
  "result": {
    "passed": 16,
    "failed": 0,
    "skipped": 44,
    "unit": "vectors",
    "suites": 1,
    "status": "PASS"
  },
  "detail": "16 in-scope pass; 44 skipped (modes outside receipt-layer usage)",
  "note": "The 44 skipped modes are ML-DSA parameter sets outside receipt-layer usage — out of scope, not failures. ACVP conformance here validates the VERIFIER logic; the deployed signing path uses a software signer, not an HSM-certified signer (see non-claim).",
  "what_it_proves": "For the ML-DSA-65 modes the receipt layer uses, the verifier matches NIST's official ACVP accept/reject vectors.",
  "what_it_does_not_prove": "A FIPS-certified PQ implementation. The deployed signing path uses a software signer, not an HSM-certified signer. No FIPS-certified PQ implementation is claimed.",
  "raw_excerpt": "$ node test/test_nist_acvp_mldsa65.mjs\nNIST ACVP ML-DSA-65 sigVer: 16 passed, 0 failed, 44 skipped (modes outside receipt-layer usage)\nRESULT: PASS — PQ leg matches official FIPS 204 accept/reject vectors",
  "frozen_tag": "audit-tob-v1.1.0",
  "commit": "697f339",
  "reproduced_utc": "2026-07-27",
  "node": "v22.22.3",
  "repo": "github.com/DCS-LabsAI/dcs-rseries-core",
  "prod_dependencies": 0,
  "reproduced_by": "DCS Labs — live reproduction from clean checkout",
  "posture": "ground-demonstrated; not externally audited",
  "non_claim": "Post-quantum signature: the current R-Series hybrid profile signs the post-quantum leg with real ML-DSA-65. Key custody: a software signer — hardware-backed HSM/KMS custody is a separate deployment control, is not deployed here, and no FIPS-validated module is claimed. Not independently audited by external third parties."
}