M5 / Standards and status discipline

Status discipline: seven values, seven real examples

FoundationsPractitionerAdvisor

After this lesson you can

  • Distinguish the seven status values (FINAL/DRAFT/SELECTED/CANDIDATE/VALIDATED/DEPLOYED/WITHDRAWN), each with a real example from within the course
  • Justify, in the original brief's own words, why status precision is a credibility signal

Before thisM4: Signatures

Mental model

In every module of this course from M0 to M4, you have seen a status badge beside every mention of a standard or algorithm: FINAL2024-08-13, DRAFT2026-07-14, SELECTED2025-03-11, and so on. This lesson gathers the seven values together and, by giving a real, live-verified example from within the course for each, makes the differences clear enough that you can tell them apart instantly in a meeting.

One of the project’s own core rules states why this precision matters: “Never call a draft a standard, never call a selected algorithm a published FIPS, never call a vendor roadmap commitment a validated module. This distinction is the expertise.” In other words, using these seven words correctly is not decorative jargon; it is the basic discipline you need when advising a bank.

Seven statuses, seven real examples

FINAL2024-08-13: a standard has been published in a form that will not change. Example: FIPS 203/204/205 (ML-KEM, ML-DSA, SLH-DSA) became final on 13 August 2024 (M3, M4).

DRAFT2026-07-14: a draft, in public comment or editorial review, not final yet. Example: KMIP v3.0, still at Committee Specification Draft (CSD02) stage (you will see it in M9, a module not yet opened on the FOUNDATIONS path; this one line is enough for now).

SELECTED2025-03-11: NIST has chosen an algorithm for standardization, but no draft or final text exists yet. Example: HQC, selected on 11 March 2025 and still at this status today (September 2026) (M2). FN-DSA has the same status; as you saw in M4, despite NIST’s “nearly ready” wording in 2025, its draft (IPD) was still unpublished in September 2026, a concrete reminder that SELECTED may not mean “soon”.

CANDIDATE: a contender in an evaluation round, not selected yet. Example: the additional signature candidates NIST IR 8610 advanced to round 3 (FAEST, MAYO, SQIsign, UOV and others) have this status today; none of them is even SELECTED yet (M4).

VALIDATED2026-07-29: validated by an independent laboratory or program, not a vendor claim. Example: Thales TCT Luna T7, CMVP Certificate #5450, verified directly against NIST’s own database (you will see it in detail in M9).

DEPLOYED2026-02-27: observed running live in production, not a roadmap promise. Example: hybrid ML-KEM key exchange (X25519MLKEM768) is enabled by default in browsers (Chrome, Edge, Firefox). According to Cloudflare’s own live measurement, 60%+SOURCED of the clients connecting to it offered PQ support as of February 2026; that is a capability measurement (does the client support it), not the same thing as “what the traffic uses”. In a separate metric that measures use directly, Cloudflare’s 2025 Year in Review shows that 52%SOURCED of human-generated web traffic was actually PQ-encrypted. Both figures are real DEPLOYED evidence, but they measure different things; it is an example of clarifying what a metric measures as well as the status.

WITHDRAWN2026-07-29: withdrawn from the process or cancelled. Example: HAWK was a candidate in NIST’s round 3 additional signatures and was withdrawn by its own team because of a cryptanalysis finding (you met it in M4; you will see the full case in M14).

Why this distinction is a credibility signal

All seven examples are real events verified live in earlier modules of this course; none is hypothetical. Being able to use these seven words correctly, with their sources, in front of an architect or auditor shows two things at once: current knowledge (statuses change fast; a SELECTED algorithm can become FINAL within years), and source discipline (every status claim must rest on a primary source, usually a live database or an official announcement). Conversely, someone who uses these seven words loosely (for example a vendor presentation mixing up “selected” and “published”) puts their own credibility in question without realizing it.

Numbers to know

  • Seven statuses, with the course's own examples: FINAL (FIPS 203/204/205, 13 Aug 2024), DRAFT (KMIP v3.0, CSD02), SELECTED (HQC, 11 Mar 2025), CANDIDATE (IR 8610's round 3 signature candidates), VALIDATED (Thales TCT Luna T7, CMVP #5450), DEPLOYED (Cloudflare: more than 60% of clients offer PQ support, Feb 2026; 52% of human traffic itself is actually PQ-encrypted, Dec 2025, two different measurements), WITHDRAWN (HAWK, July 2026)

Lab: Check your own status labels in three steps

[not run] This is a verification exercise, not a runnable command

Requires: internet access. Check your setup

shell
# Before the next lesson, line up in your head the 7 examples you have seen in this course: for each one, recall which primary source you checked (FIPS text, CMVP certificate, live project page)
Recorded output
All seven were verified live in the course's earlier modules (M2, M4, the M9 preview, the M14 preview); none rests only on secondary news

At the table

How to say this in a bank meeting.

To an executive
If you notice 'draft' and 'final', or 'selected' and 'candidate', used interchangeably in a vendor or consultant presentation, that alone is a warning sign; status precision is a cheap, instantly checkable indicator of real expertise.
To an architect
Each of the seven statuses carries a different risk: locking a production architecture to a DRAFT specification, investing early in a CANDIDATE algorithm, trusting a 'we support it' claim that is not VALIDATED. All three are errors of the same kind, but with risks of different size.
Objection
“"Do the differences between status labels matter that much? Aren't they all 'future technology' anyway?"”
Answer
No, and the original brief says so plainly: 'never call a draft a standard, never call a selected algorithm a published FIPS, never call a vendor roadmap commitment a validated module. This distinction is the expertise.' The difference between generating a root CA key under a DRAFT specification and under a FINAL standard is a real production risk, not wordplay.

Sources

  • internal project document, 2026. The primary source for how status precision is defined as one of this course's core disciplines (item 3)

    section 10, item 3 / 3 min

  • Cloudflare, 2026. A real, measured example of DEPLOYED status (a live measurement, not a roadmap promise); careful: this source measures 'client support' (capability), while 'use by human traffic' is a separate metric, and the two should not be mixed up

    post-quantum client support growth chart / 5 min

    Commercial stake: Cloudflare is announcing its own network's leadership in PQ adoption; the figures can be checked live (Radar is public), but it is still a claim about its own platform

Checkpoint

Answer first, then compare with the model answer and score yourself against the rubric. Saved in this browser only.

  1. 01Recall

    What is the difference between FINAL and VALIDATED? Can a standard be FINAL while no module is VALIDATED?

  2. 02Recall

    What is the difference between SELECTED and CANDIDATE, and which real examples have you seen in the course?

  3. 03Scenario

    In a vendor presentation you hear 'Our algorithm was selected by NIST, our standard is ready.' Which two statuses might this sentence be mixing up, and how do you clarify?

  4. 04Hostile

    An architect says 'In practice, what's the difference between SELECTED and FINAL? Both mean nearly ready.' Push back using the examples of FN-DSA (SELECTED, still without a draft despite the 'nearly ready' claim you saw in M4) and FIPS 203/204/205 (FINAL). (PRACTITIONER/ADVISOR: you will see the same argument once more in M9 with KMIP's DRAFT status.)

Project linkThe basis of the status verification column in Project 4's (capstone) vendor and technology assessment rubric: the discipline of marking which of the seven values each claim corresponds to.