Calder Standard
Regulatory compliance · Quantum readiness

Compliance evidence that stays attributable when the rules change.

Calder Standard gives regulated distributed ledger firms one place to hold the evidence behind every regulatory principle, watches the sources that change those principles, and records where the business still depends on cryptography a quantum computer would break.

Built jurisdiction-agnostic. Gibraltar's DLT regulatory framework is loaded; adding another market is a data change, not a rebuild.

Three things, kept in one record

Most firms hold this in documents, shared drives and inboxes. That works until somebody asks what you attested three years ago, and what the rules said at the time.

1

Evidence, per principle, per cycle

Write what you do to meet each regulatory principle and attach the documents that show it. Re-attestation opens a new cycle rather than overwriting the last one, and a submitted cycle is frozen. What you told your regulator in a given year stays answerable as a query.

2

Regulatory change, watched daily

The regulator's publications, the legislation register and ministerial statements are read every day; standards bodies monthly. Anything that looks material is put in front of a person with the source attached. Nothing is recorded as a regulatory event without someone approving it.

3

Quantum readiness, classified

List the systems you run, the algorithms they rely on and who supplies them. Each algorithm is labelled against the published NIST post-quantum standards, with the citation attached. Knowing what you depend on is the part almost nobody can answer on request.

What the record is worth depends on how it was made

A compliance tool is only useful if a sceptical reader can check it. Four rules the system holds itself to.

  • Every regulatory event cites its sourceA recorded event carries the link it was found at, taken from the page that was actually read. The system has no path that lets it record an event it cannot point at.
  • Nothing changes your record for youWhen something published may affect evidence you hold, you are told which principle and why. Your compliance status is never altered automatically. The judgement stays with the firm and its regulator.
  • Rules resolve to the version in forceFrameworks get amended and restated. Each principle carries the date it took effect, so evidence written in one year is never displayed against a rule introduced later. Old answers stay attached to the rules they answered.
  • A person approves every changeMonitoring drafts proposals; it cannot publish them. Approval is deliberate and takes two steps, and an ambiguous finding goes to a daily digest rather than into the approval queue.

Why quantum readiness sits alongside compliance

Encrypted data taken today can be stored until it becomes readable. For a business holding keys or client assets, that makes the question current rather than distant, and supervisors have started asking it.

The inventory is the hard part

Which systems use which algorithms, and whose software are they? Most firms have never had that written down in one place, and it is the first thing asked for.

Classification, not a score

Which algorithms fall to a quantum computer is settled and citable, so each entry is labelled against the NIST publication that says so. There is no readiness percentage: a number like that would be an opinion wearing precision.

Suppliers included

Most exposure sits in software a firm buys rather than writes. Vendor migration positions are tracked next to the inventory, because that is the part a firm cannot fix on its own.

Start with your own evidence

Create an account, pick your jurisdiction, and work through the principles at your own pace. Nothing is published anywhere and nothing is shared with a regulator.