DeliveryTag
Public · Technical Specification
Integrity Protocol Foundation · Swiss Stiftung in formation, Canton of Zug
Correspondence: Baarerstrasse 135, 6300 Zug, Switzerland
WHITEPAPER V1.3

DeliveryTag

A protocol for auditable deliverability verification of 24/7 CFE claims.

REF: AXIOM-01

EnergyTag covers When.
DeliveryTag adds Where on top.

Published
April 2026 · Revised July 2026 (v1.3)
USPTO Prov. Appl. 64/023,803
USPTO Prov. Appl. 64/023,364
FRAND Licensing Commitment
Revision History
v1.3 — July 2026: accuracy and clarity revision — corrected IP status language, PTDF definition and worked examples, verification-layer physics descriptions, fee framing, assurance-pathway status, regulatory citations; added entity-structure clarification, data-sources detail, references section; terminology normalization.
v1.2 — April 2026: previously published edition.
The Problem

What DeliveryTag Solves

EnergyTag established the temporal layer of clean-energy claims, that is its intentional scope. The spatial dimension, addressed in complementary work, is what DeliveryTag contributes on top. Three forces make this complementary layer increasingly load-bearing.

01, Temporal, Not Spatial

GCs cover when; where is the dimension to add

An hourly GC can be issued for wind generated in one region but curtailed at a corridor interface, never reaching the buyer's busbar. The timestamp matches. The electrons never arrived.

02, Hyperscaler Scale

Single busbars move the marginal generator

A 100, 500 MW AI data center on a single 400 kV bus is large enough to change the merit-order outcome at that node. Diffuse country-level matching no longer reflects physical impact.

03, Regulatory Tightening

Nodal proof is becoming a compliance requirement

EU RED III Article 19, IRA §45V, and the WRI GHG Protocol Scope 2 revision (Alternate Methodology 2) all push toward geographic + temporal deliverability as an audit criterion, not a marketing claim.

The DeliveryTag Answer

DeliveryTag extends the EnergyTag Granular Certificate with a nodal attribution layer (PTDF-weighted deliverability) and hardware-verified delivery proof (dual-PIN seven-layer sensor validation + CRYSTALS-Dilithium signatures). Every DT-F satisfies both pillars: the timestamp EnergyTag already proves, and the busbar it physically reached.

Physics Scope

DeliveryTag does not claim to track individual electrons. It proves power deliverability under network-flow physics: PTDF-weighted corridor attribution + causal dispatch proof + seven-layer sensor validation. The claim is forensic, not metaphysical. Full detail in §5.

How DeliveryTag Works

A one-page overview of the protocol, from generator to a DT-F certificate designed for ISAE 3000 assurance.

Block 1, The Background

The Existing Certificate Landscape

Step 1
Annual RECs (2001–2022)

One certificate per MWh, no hourly timestamp, no nodal binding. €2–5/MWh voluntary price reflects limited credibility.

Step 2
EnergyTag Granular Certificates (2022+)

Hourly resolution, cancelled against measured consumption. Answers When? but not Where? or How?

The Gap
Nodal Delivery Proof

On a congested grid, a certificate can be issued for clean energy that never physically reached the buyer's transmission node. The temporal principle is satisfied; the physical delivery is not.

Block 2, The DeliveryTag Protocol

Adding the Spatial Layer

01, SUPPLY
S-PIN + 7-Layer Validation

Tamper-evident hardware at the generator or flex-load busbar signs 7-layer sensor bundles with CRYSTALS-Dilithium.

02, CORRIDOR
PTDF + LME

A PTDF network model, computed by the verification body and validated against published flow-based parameters, supports auditable deliverability inference from source node to buyer node under binding network-flow constraints. Settlement-grade LME attests the emissions impact (US).

03, DEMAND
D-PIN + Tri-Sensor

Tamper-evident hardware at the buyer's POI signs consumption bundles. Binds cancellation to the claimed grid node cryptographically.

04, ASSURANCE
Accredited Signer

ISAE 3000 reasonable-assurance opinion over the Guardian policy, issued by an Accredited Signer. A design target: no signer is engaged as of publication. Replaces the legacy VVB framing.

Cryptographic counterbalance enforced ex ante. A second cancellation on the same (corridor, hour, MWh) is rejected at the Guardian policy layer, not by post-hoc audit. Satisfies WRI Scope 2 Alternate Methodology 2 anti-gaming clause.

Block 3, What This Produces

A Single Assurance-Ready DT-F Certificate, Multiple Frameworks

The same DeliveryTag Final (DT-F) certificate is designed to support every major 24/7 CFE reporting framework, because it carries a superset of their evidence requirements natively. Official acceptance under each framework is tracked at deliverytag.org/regulatory-watch; current status is directional alignment, not across-the-board ratification.

GHG Protocol
Scope 2, Alt. Method 2
SBTi
CNZ, FLAG criteria
IFRS S2 / CSRD
ESRS E1-6
EU RED III
Article 19 RFNBO
IRA §45V
Deliverability pillar

EnergyTag covers the temporal layer; DeliveryTag adds the spatial layer on top of the same certificate.

Physics Scope

DeliveryTag does not claim to track individual electrons. It proves power deliverability under network-flow physics: PTDF-weighted corridor attribution + causal dispatch proof + seven-layer sensor validation. The claim is forensic, not metaphysical. Full detail in §5.

Contents

DeliveryTag Whitepaper v1.3, July 2026. Eleven sections and one appendix, organized across five thematic parts.

1. Preface 1 2. Executive Summary 2
A Foundations
3. Background, From RECs to GCs to DeliveryTags 3
3.1 Annual REC Era  ·  3.2 EnergyTag Era  ·  3.3 The Spatial Layer
3.4 Market Mandate (WRI Scope 2)  ·  3.4.4 Alignment with SBTi, IFRS S2, CSRD, RED III, 45V
B Protocol
4. Components of a DeliveryTag System 4
4.1 Account Holding  ·  4.2 Double Counting  ·  4.3 Issuance  ·  4.4 Transfer  ·  4.5 Cancellation
4.5.1 Claim-Based Allocation  ·  4.6 Registration  ·  4.7 Nodal Attribution  ·  4.8 Causal Dispatch Proof
4.9 Hepta-Validation  ·  4.10 Physical Principles as Verification Infrastructure  ·  4.11 Dual-PIN (S-PIN + D-PIN, Tri-Sensor, Deployment Tiers)
C Economics & Governance
5. Benefits of Nodal Granularity 5 6. The Integrity Protocol Foundation 6
D Rules & Compliance
7. DeliveryTag Guidelines, 38 Principles 7
18 inherited from EnergyTag + 20 nodal extensions, including Accredited Signer, Dual-PIN, Tiers, Total Node Issuance Cap, Claim-Based Allocation, Cryptographic Counterbalance
8. Compliance with EnergyTag 8
8.1 Live Regulatory Tracking, active signals Q2 2026: EC Recommendation 22 April 2026, GHG Protocol Scope 2 revision, IRA §45V, CBAM, RED III, CSRD (post-Omnibus) + IFRS S2 + California SB 253/261. Living version at deliverytag.org/regulatory-watch.
E Deployment
9. Reference Architectures (EU Zonal + US Nodal) 9 10. Next Steps, Pilot Acceptance Criteria, Milestones 10
Back Matter
11. Glossary 11 12. References 12 Appendix A, Threat Model A
Section 01

1. Preface

The global energy transition has entered a phase where hourly matching of corporate load with clean generation, the 24/7 Carbon-Free Energy (CFE) paradigm, is rapidly becoming the minimum credible standard for hyperscale data centers, electrified industry, and green hydrogen producers. The EnergyTag Initiative and its 100+ member organizations have, since the initiative’s launch in 2020, delivered the foundational framework that enables this shift: the Granular Certificate (GC), an Energy Attribute Certificate with temporal resolution of one hour or better, cancelled against measured consumption at a defined Consumption Point.

Large electricity buyers, from hyperscale data center operators to green hydrogen producers, seeking 24/7 CFE need an additional layer of evidence beyond temporal matching: that the certified MWh was deliverable to the buyer’s busbar under congested grid conditions. DeliveryTag adds this spatial layer on top of the EnergyTag Granular Certificate as an extension attribute set, making the resulting claim auditable on both dimensions.

The EnergyTag framework is a breakthrough. It establishes time resolution, measurement discipline, registry immutability, and independent verification as the baseline for credible clean-energy claims. Every principle in the EnergyTag whitepaper is preserved, honored, and extended in this document.

This whitepaper addresses the one dimension the EnergyTag whitepaper explicitly leaves open: space. A Granular Certificate issued at 12:00 UTC from a solar plant in Andalucía and cancelled against 12:00 UTC consumption at a data center in Frankfurt is temporally aligned, but it is not physically delivered if the Iberian–French or French–German corridor is saturated during that hour.

The same problem exists in the United States. A wind farm in West Texas generates a GC at 14:00 CST, matched against consumption at an AI data center in Dallas. The hour matches. The volume matches. But in this illustrative hour the West Texas Export interface was binding at its limit, a routine condition: ERCOT experienced at least one binding transmission constraint in 86% of hours in 2024, and 5.3 TWh of low-cost generation, primarily West and Panhandle wind and solar, was curtailed that year because of grid transmission constraints (Potomac Economics, 2024 State of the Market Report for the ERCOT Electricity Markets, 2025). The electrons never left ERCOT West. The certificate says “matched.” The ERCOT dispatch log says “curtailed.”

Kirchhoff’s laws do not honor spreadsheets. Buyers increasingly demand, and regulators increasingly require, certificates that reflect not only when the clean MWh was produced, but where it actually flowed on the network.

The DeliveryTag™ (DT) is an implementation profile of the EnergyTag Granular Certificate with two additions: (i) a nodal attribution scope bound to a specific transmission bus or node, and (ii) a causal dispatch proof that demonstrates, via Transmission System Operator (TSO) dispatch data and Power Transfer Distribution Factor (PTDF) network-flow analysis, that the marginal generator at the buyer’s node was physically displaced during the certificate’s time interval.

This whitepaper is not a competitor to EnergyTag. It is a structural complement, specifically, an extension of the EnergyTag “Domain” concept from market or country level down to busbar or node level, preserving every EnergyTag principle while adding the spatial layer required for a physically honest 24/7 CFE claim.

Section 02

2. Executive Summary

Adding the spatial layer left open by the EnergyTag whitepaper: DeliveryTag attaches as an extension attribute set to the EnergyTag Granular Certificate, adding nodal attribution and PTDF-based deliverability evidence. This document specifies the protocol through two reference architectures spanning EU zonal and US nodal markets.

DeliveryTag™ is an open-standard protocol for auditable deliverability verification of 24/7 CFE claims. It inherits all principles of the EnergyTag Granular Certificate (time resolution ≤ 1 hour, cancellation against measured consumption, registry immutability, independent verification) and adds nodal attribution, PTDF corridor-relief inference, and hardware-signed telemetry. EnergyTag certifies hourly matching; DeliveryTag adds nodal attribution and PTDF-based deliverability evidence.

A spatial layer for every hour, not just the congested ones. EnergyTag Granular Certificates establish the temporal layer by design. DeliveryTag adds the spatial layer on top: nodal attribution and PTDF-based corridor inference. The aim is to extend the certificate with assurance-ready evidence of where the energy was delivered, across every hour and every certificate, not only during congestion windows.

A DeliveryTag certificate attests that, during a specified time interval, at a specified transmission node, a specified volume of measured energy was consumed by a specified offtaker, and that the marginal generator serving that node was physically displaced by a specified flexible load curtailment or a specified clean injection, as verified by the TSO’s own dispatch log and corroborated by hardware-verified sensor events.

The Forensic Moat. In plain terms: a hardware-based barrier to replication. The DeliveryTag protocol is anchored in Hardware-Verified Events, physical sensor data (Fluxgate magnetometers, FLIR thermal imaging, multispectral satellite imagery) that prove curtailment and generation at the hardware level. This ensures verifiability and prevents replication by pure software traders or paper-certificate arbitrageurs. The physical proof layer is the moat.

The Economic Baseline. Physical proof that a facility curtailed is not enough. Mode B curtailments must also pass the Opportunity Cost Oracle, which checks that the curtailment was a deliberate financial sacrifice rather than a routine market exit. Rationale and mechanics in §4.10 (Layer 7) and Principle 32.

Value Proposition for 24/7 CFE Market Participants
Spatial Binding Adds the spatial layer on top of the EnergyTag GC. The temporal layer covered by EnergyTag remains intact; DeliveryTag binds the same certificate to a specific transmission node via PTDF attribution.
Auditability Designed for ISAE 3000 attestation, aligned with CSRD and California SB 253/261. Every certificate carries an evidence chain (hardware-signed sensor data, PQC-signed, Hedera-anchored) designed to be verified by an Accredited Signer under ISAE 3000.
Native Compatibility Not a competitor, a natively compatible extension. DeliveryTag attributes attach to standard EnergyTag Granular Certificates. Nothing in the EnergyTag framework is displaced, only extended.

Seven-Layer Forensic Validation Stack

1 Electrical

Revenue-grade IEC 62053-22 Class 0.2S metering at the Consumption Point. Interval data at 15-min resolution.

2 Thermal

IR sensors (FLIR) at flex load facility proving equipment cooldown during curtailment (Ohm’s Law / Joule effect).

3 Magnetic + Freq

Fluxgate magnetometers confirming current flow cessation (Ampère’s Law) + 50/60 Hz voltage-waveform and harmonic analysis corroborating the electrical record.

4 Acoustic

Decibel monitoring at flex load facility confirming cessation of the equipment’s vibro-acoustic operating signature.

5 Spatial

Satellite multispectral/SAR imagery confirming upstream wind turbine restart and site-level activity changes post-curtailment.

6 Emissions

Mass balance verification (Lavoisier’s Law): carbon in fuel = carbon in exhaust, proving emissions displacement.

7 Economic

Opportunity Cost Oracle checks that the curtailment was a deliberate financial sacrifice, not a routine market exit. Rationale in §4.10, Layer 7.

DeliveryTag is immediately compatible with existing EnergyTag-compliant registries as an extension attribute set on a standard Granular Certificate. Issuance, transfer, cancellation, and retirement follow the EnergyTag lifecycle. Nothing in the EnergyTag framework is displaced, only extended.

Two-State Issuance Lifecycle (DT-P / DT-F)

The framework explicitly accommodates the different settlement timings of EU and US markets through a two-state issuance lifecycle (Provisional / Final).

DT-P
Provisional

Issued at D+1 to D+7 with preliminary dispatch data. Valid for PPA settlement, internal reporting, buyer-side accruals. Not ISAE 3000 attestable as final.

DT-F
Final

Issued after final settlement data + third-party LME attestation. Supersedes DT-P with identical registry serial. Designed for ISAE 3000 reasonable assurance.

In the EU, where D+1 public data (ENTSO-E Transparency Platform, JAO flow-based parameters, national redispatch publications) plus TSO data under access agreements support direct final issuance, DeliveryTags are minted in final form at D+1 to D+7 and third-party LME is optional. In US RTO/ISO markets (MISO, PJM, ERCOT, CAISO, SPP, NYISO), settlement-grade nodal LME is published at T+30 to T+45 days ex-post, so a provisional DeliveryTag is issued at D+1 to D+7 and promoted to final upon LME attestation. Full timing rules are specified in §4.3.1 and Principle 30.

This asymmetry is structural and reflects the underlying data-availability reality of each market.

Two Operating Modes

The DeliveryTag operates in two distinct modes, covering 100% of operating hours:

A Nodal Attribution Mode
Corridor NOT congested: no curtailment needed
Verifies and records that the physical path between generator and buyer was clear and capable of carrying the energy. The system does not create capacity but validates that standard GCs are physically deliverable.

1. PTDF Binding: certificate bound to specific transmission path, quantifying flow share
2. Infrastructure Verification: path traced from source through substations to buyer POI
3. Binding Constraint Check: confirms no transmission constraint blocked delivery
4. LME Attribution: records which marginal generator was displaced at the node

Plus: PQC hardware signing (CRYSTALS-Dilithium), Hedera blockchain anchoring, and Accredited Signer certification under ISAE 3000 for every certificate.
B Physical Electron Swap Mode
Corridor IS congested: flex curtailment frees capacity
In plain terms, a flex-load curtailment swap: when grid physics block delivery, the flex pool curtails flexible load served across the congested corridor, reducing loading on the binding element in proportion to the flex load’s PTDF and freeing headroom for the buyer’s attributed transfer. Attribution remains capped at the buyer’s metered consumption. Full Causal Dispatch Proof + seven-layer validation stack required (§4.9).

1–4. All Mode A checks (PTDF, infrastructure, constraints, LME)
5. Causal Dispatch Proof: TSO merit-order log + PTDF relief + flex SCADA telemetry
6. Seven-layer sensor validation (§4.9): Electrical, Thermal, Magnetic, Acoustic, Spatial, Emissions, Economic

Mode A applies in hours when the relevant corridor is uncongested; Mode B applies in hours when it is saturated. Congestion incidence is corridor- and node-specific and varies widely, from a few percent of hours at typical nodes to well above 20% at chronically constrained interfaces. The ~80/20 split used in the illustrative economics of Section 6.3 is a scenario assumption, not a measured protocol constant. Together, the two modes extend the certificate with assurance-ready evidence across the full hour set.

Part A
A

Foundations

Why physical delivery proof is the missing layer, and why the WRI GHG Protocol Scope 2 consultation has made it a reporting requirement.

Section 3

3. Background

From RECs to GCs to DeliveryTags

3.1 The Annual REC Era (2001–2022)

For two decades, the global market for voluntary renewable-energy procurement ran on annual-resolution Renewable Energy Certificates: one certificate per MWh of clean generation, with no time stamp finer than a calendar year, and no spatial binding below the market or country level. A corporate buyer could claim “100% renewable” while consuming coal-generated electricity in the dead of night or during a calm, cloudy winter afternoon. The market recognized the shortcoming: voluntary REC prices collapsed to €2–5/MWh, reflecting limited credibility.

3.2 The EnergyTag Era (2022–present)

The EnergyTag Initiative, launched in 2020, published its foundational whitepaper in 2021 and codified the framework in the Granular Certificate Scheme Standard (V1, March 2022; V2, December 2024). The standard defines the Granular Certificate (GC): an EAC with time resolution ≤ 1 hour, issued by an EAC Issuing Body against measured generation and cancelled against measured consumption at a Consumption Point. The EnergyTag framework introduced formal roles, Measurement Body, GC Issuer, Registry, Consumption Verification Body, and a detailed principles catalogue (avoidance of double counting, immutability, verifiability, energy storage dual-role handling, UTC time zones, and more).

EnergyTag’s impact is now visible across the industry: Google’s 24/7 CFE program, Microsoft’s 100/100/0 pledge, M-RETS’s hourly certificate pilot in North America, Energinet’s Origin Hub in Denmark, TenneT’s CertiQ roadmap in the Netherlands. The GC Scheme Standard V2 (December 2024) and the GC Matching Standard V1 (2024) are the canonical normative references for temporal granularity in clean-energy attribution, and EnergyTag accredited its first Granular Certificate issuers in 2025.

3.3 The Spatial Layer

The EnergyTag whitepaper is explicit about its scope: temporal granularity. It defines “Domain” as the geographic region in which GCs are issued and cancelled, typically mapped to a market or country. It does not address transmission congestion, corridor saturation, Power Transfer Distribution Factors, nodal pricing, or Locational Marginal Emissions. These are, by design, left for future work or for complementary frameworks.

In practice, this creates a structural limitation. On a congested grid, a GC can be issued for wind energy that was generated in one region but curtailed at the corridor interface, never reaching the consumption region. A buyer in a congested zone can cancel a GC against a clean MWh produced several PTDF-distant nodes away, while the marginal generator actually serving their busbar remains a coal or gas plant. The temporal principle is satisfied; the physical delivery is not.

Three Forces Making the Spatial Layer Load-Bearing

  • Hyperscaler scale. A single 100–500 MW AI data center on a single 400 kV bus is large enough to move the marginal generator at that node. Diffuse matching at the country level no longer reflects the buyer’s actual grid impact.
  • Regulatory tightening. EU RED III Article 19 (renewable fuel of non-biological origin criteria for hydrogen), the Inflation Reduction Act Section 45V hydrogen tax credit rules, and the GHG Protocol Scope 2 Market-Based Method revision all push toward geographic + temporal additionality. Nodal proof is becoming a compliance requirement, not a marketing differentiator.
  • Available telemetry. Grid data transparency has improved materially, though unevenly. What is genuinely public: ENTSO-E’s Transparency Platform (Regulation (EU) 543/2013) publishes per-unit actual generation, load, and cross-border physical flows; the JAO Publication Tool publishes the daily day-ahead flow-based parameters, zonal PTDFs and remaining available margins per critical network element, for the Core capacity-calculation region; the four German TSOs publish plant-level redispatch measures on netztransparenz.de; and US RTOs publish nodal LMPs and binding-constraint shadow prices (PJM Data Miner 2 at 5-minute resolution; ERCOT market reports, with unit-level dispatch and offer data disclosed at a 60-day lag). What remains restricted: full nodal PTDF matrices, network models, and real-time unit-level dispatch data, treated as CEII in the US (18 CFR § 388.113) and as confidential by EU TSOs. DeliveryTag therefore does not assume a public nodal-PTDF product: the Dispatch Verification Body computes nodal PTDFs from network models obtained under market-participant and TSO data-access agreements and cross-validates them against the published zonal factors and constraint data (§9, Data Sources; Principles 21 and 36).

3.4 The Market Mandate (GHG Protocol Scope 2 Public Consultation, 2025–2026)

Between 20 October 2025 and 31 January 2026, the World Resources Institute and the GHG Protocol Secretariat ran the first round of public consultation on the revised Scope 2 Standard. The draft revision makes two things mandatory for corporate reporting: hourly temporal correlation (Quality Criterion 4) and deliverability (Quality Criterion 5). Criterion 5 is satisfied through one of three approved pathways, zonal market boundaries, price-differential deliverability, or physical-delivery deliverability.

The third pathway, Alternate methodology 2, is the clause that operationalises physical delivery. Verbatim (consultation document, Section 5.1.2, p. 24):

"A reporting entity may claim consumption of power delivered from any point in an interconnected transmission system if it demonstrates the existence of exclusive rights allocating to the reporting entity or its energy provider the transmission capacity necessary to deliver power bundled with associated energy attributes from the point of generation to the point of consumption. […] Delivery of power and attributes must be demonstrated on an hourly or more frequent basis with no direct counterbalancing reverse transactions."

This clause did not exist in the 2015 Scope 2 Guidance. Its appearance in the 2025 draft reflects a convergence of integrity-camp demand and regulator recognition that annual matching, even layered over high-quality EACs, no longer maps to physical flows.

3.4.1 The Feasibility Gap the Market Identified

The first-round consultation surfaced a consistent objection. The Clean Energy Buyers Association (CEBA), in its 23 May 2025 letter to the Independent Standards Board signed by CEO Rich Powell, stated: "mandatory matching is infeasible in many markets and would hinder energy buyers' efforts to procure carbon emissions-free electricity." WattTime's public position is that the proposed requirements will be "considerably more complex, and in most cases far more expensive." Morrison Foerster's practitioner survey found "nearly 80% of respondents lack confidence in their ability to procure time-matched clean electricity within smaller market boundaries" and "70% stated that their current procurement contracts would no longer be eligible."

These concerns are empirically correct for today's infrastructure. They describe the gap between what the Standard now requires and what market participants can currently prove. They do not describe a permanent limitation, they describe the absence of purpose-built physical-verification infrastructure.

3.4.2 DeliveryTag Maps Clause-by-Clause to Alternate Methodology 2

DeliveryTag v1.3 is calibrated against the published proposed text. The mapping is deliberate, not coincidental:

WRI Alternate Methodology 2 ClauseDeliveryTag Component
Exclusive rights over transmission capacityPTDF-weighted corridor allocation; Mode B tokenised capacity (T-NAC, USPTO provisional application 64/023,364)
Recognition by transmission operatorsDeliverability computed from TSO/RTO-published flow and constraint data (JAO flow-based parameters, PJM constraint feeds) and validated against them; network models obtained under TSO/RTO data-access agreements (§9)
Mutually compatible tracking systemsEnergyTag overlay, DT-F extends the standard GC, does not replace it
Hourly or more frequent proofIEC 62053-22 Class 0.2S metering at 15-min resolution; DT-P at D+1–7, DT-F at D+30–45
No direct counterbalancing reverse transactionsGuardian policy enforces cryptographically via CRYSTALS-Dilithium signatures (DSEE, USPTO provisional application 64/023,803)

DeliveryTag does not ask the Secretariat to invent a new category, it supplies the technology the category presupposes.

3.4.3 Protection for Buyers and Sellers Against Greenwashing

The anti-gaming clause, "no direct counterbalancing reverse transactions", is the load-bearing anti-greenwashing provision in the entire deliverability regime. Human-audited registries enforce this post hoc. DeliveryTag enforces it ex ante: a second certificate claiming the reverse flow on the same corridor-hour-MWh triple is rejected by the Guardian policy at the cryptographic layer and cannot be recorded.

For buyers, this means a 24/7 CFE claim is substantiated by the TSO's own operational data, signed hardware, and an Accredited Signer opinion under ISAE 3000, not a self-reported attestation.

For sellers (clean generators, flex loads), it means delivery proof is independently verifiable and designed to resist forgery by a competitor or arbitrageur. This hardware-verified proof layer protects both sides of the transaction.

The 2025–2026 Scope 2 consultation describes the regulatory destination. DeliveryTag is the infrastructure that makes arriving there feasible today.

3.4.4 Alignment with Adjacent Frameworks (SBTi, IFRS S2, CSRD, RED III, 45V)

The WRI GHG Protocol revision is the upstream source, but corporate reporters are bound by a broader set of frameworks that inherit from or reference Scope 2 methodology. DeliveryTag maps to each:

FrameworkDeliveryTag Contribution
SBTi (Science-Based Targets initiative)SBTi's CNZ and FLAG criteria require hourly-matched 24/7 CFE reporting by 2030 for near-term targets. DeliveryTag satisfies the physical-deliverability requirement that SBTi's forthcoming Scope 2 criteria are expected to inherit verbatim from the revised GHG Protocol. Tier 1 assurance maps directly to SBTi's external-verification expectation.
IFRS S2 (ISSB climate-related disclosures)IFRS S2 requires disclosure of Scope 2 emissions with location-based and market-based methodologies, specifying underlying assumptions and data quality. The DeliveryTag causal_dispatch_proof and cancellation_tier attributes are structured to surface in IFRS S2 disclosure templates without additional transformation.
EU CSRD / ESRS E1 (Corporate Sustainability Reporting Directive)ESRS E1-6 requires gross Scope 2 emissions under both methods, plus GHG removals and mitigation projects. DeliveryTag cancellations are designed to feed the market-based method line with assurance-ready traceability and to satisfy the ESRS double-materiality evidence chain for purchased electricity.
EU RED III Article 19 (RFNBO hydrogen temporal + geographic correlation)RED III requires hourly matching and same-bidding-zone geographic correlation, with a tightening pathway to higher granularity. DeliveryTag's PTDF-based nodal attribution exceeds the bidding-zone requirement by a full order of magnitude and is future-proof against tightening geographic criteria.
IRA Section 45V (US clean hydrogen tax credit)45V requires three pillars: incrementality, deliverability (same region), temporal matching (annual, hourly by 2028). DeliveryTag's Mode A nodal attribution and Mode B flex-load curtailment swap satisfy deliverability at a resolution below the 45V region boundary and are natively compatible with the 2028 hourly transition.

DeliveryTag is framework-agnostic by design: the same DT-F certificate serves GHG Protocol Scope 2, SBTi, IFRS S2, CSRD, RED III, and 45V reporting without re-issuance or re-verification, because it carries the union of their evidence requirements natively.

3.4.5 UK Market Context, Existing Flex Infrastructure Meets Nodal Verification

The UK is a distinctive case. As an island system with a single system operator (NESO, the National Energy System Operator, established October 2024) and a well-developed DNO / DSO flexibility layer, it has the institutional surface for nodal-level attribution but has approached the problem from the opposite direction, dispatch first, verification second. DeliveryTag slots into that stack as the verification-first complement, not as a competing marketplace.

The demand backdrop is public record. Google has committed to operating on 24/7 Carbon-Free Energy by 2030 across its operations, including the UK (see §12 References), and other hyperscale operators are expanding UK data-centre capacity against the same shareholder and reporting pressure. NESO's connections queue contains a large and growing volume of prospective data-centre demand. DESNZ's AI Growth Zones framework and the Clean Power 2030 programme both treat locational signals as load-bearing. (Companies are named here as public-record market context only; no commercial relationship is implied.)

Constraint economics are already material. GB network constraint costs ran just over £1.5bn in the 2023/24 financial year and are trending higher, with balancing costs rising a further ~10% in 2024/25 (NESO, Annual Balancing Costs Report, 2025). The Scottish B5 / B6 transmission boundary alone accounts for a material fraction, driven by constrained-off Scottish wind that cannot physically reach southern demand. Every constrained MWh is a nodal-delivery question: the GC timestamp matches but the electrons do not arrive. This is the textbook geography for DeliveryTag's virtual-transmission mechanism (see §5.3): a flexible load served across B5 / B6 that curtails demand reduces loading on the boundary in proportion to its PTDF, and the resulting corridor relief raises the deliverability cap at the buyer's node, with attributed MWh always capped at the buyer's metered consumption.

Regulatory trajectory is convergent. DESNZ's Low-Carbon Hydrogen Standard v3 already requires both temporal and geographic correlation for RFNBO eligibility, aligning UK hydrogen policy with EU RED III Article 19. Ofgem's REMA (Review of Electricity Market Arrangements) and NESO's Strategic Spatial Energy Plan both move toward locational pricing signals. The direction of travel is identical to the GHG Protocol Scope 2 deliverability clause, spatial granularity is no longer a US-nodal curiosity.

UK DNO / DSO flex marketplaces are complementary, not competitive.

GB's fourteen DNO licence areas (operated by six distribution groups, several now running DSO functions) already host flexibility marketplaces, with Electron and Pico as the principal software platforms. Those platforms handle dispatch, clearing, and settlement. DeliveryTag does not. DeliveryTag is the authentication layer on top: PIN-signed sensor evidence that a specific flex event produced the claimed corridor relief and node-hour attribution, carrying an Accredited Signer's ISAE 3000 opinion over the Guardian policy. One marketplace, two layers, no overlap. Flex dispatched by Electron or Pico, attested by DeliveryTag.

The UK does not need a new flex marketplace. It needs an interoperable authentication standard that lets UK-dispatched flex service a Scottish wind corridor relief event for a London hyperscaler in a way that survives CSRD and IFRS S2 assurance. That is the gap DeliveryTag fills.

The DeliveryTag is the framework that closes this gap by extending the Granular Certificate with a spatial proof layer.

Part B
B

Protocol

Dual-PIN hardware, seven-layer sensor validation, PTDF-weighted nodal attribution, and the Claim-Based Allocation mechanism that keeps multi-buyer nodes honest.

Section 4

4. Components of a DeliveryTag System

A DeliveryTag system preserves the EnergyTag component architecture and adds two roles: the Dispatch Verification Body and the Nodal Attribution Registry extension.

4.1 Account Holding

Identical to EnergyTag. Producers, traders, and consumers hold accounts in an EnergyTag-compliant registry. DeliveryTag certificates are issued, held, transferred, and cancelled within these same accounts as extension attributes on standard GCs.

4.2 Avoidance of Double Counting

DeliveryTag inherits the EnergyTag double-counting avoidance principle in full. A DeliveryTag attribute set can only be attached to a GC that is itself non-duplicated within the registry. Additionally, because the DeliveryTag binds the certificate to a specific node, the same clean MWh cannot simultaneously be claimed as "delivered" at two different nodes. The nodal binding is exclusive.

§ 4.2, Nodal Exclusivity

How It Works, Atomic Nodal Binding

One physical dispatch event, one supply of tokens, two nodal buyers. HTS atomicity, enforced at the Hedera layer, guarantees that the same MWh cannot be credited to two different nodes, nor re-scoped after issuance.

Illustrative worked example. Buyer A and Buyer B are hypothetical parties; no commercial relationship with any real company is implied.

SOURCE EVENT
Nuclear Plant produces 1,000 MWh @ 14:00 UTC
Smart contract mints exactly 1,000 tokens. Not 1,001.
DT-F-001, 500 MWh
Buyer: Buyer A (hyperscale data-center operator, illustrative)
Node: Ashburn, VA
PTDF path: Plant → 345kV → Ashburn
→ HTS token transferred to Buyer A
DT-F-002, 500 MWh
Buyer: Buyer B (hyperscale data-center operator, illustrative)
Node: Chicago, IL
PTDF path: Plant → 345kV → Chicago
→ HTS token transferred to Buyer B
Enforced, Not Promised

Buyer A cannot acquire a certificate that asserts delivery to Buyer B’s node. The Node of Attribution is set at issuance and cannot be re-scoped (Principle 28). The HTS token is atomic: once transferred, the seller’s balance is zero for that token. “Same MWh to two nodes” is blocked at the protocol layer on Hedera rather than being caught in a post-hoc audit.

Tradability on EAC secondary markets. DeliveryTags are transferable between accounts (Principle 17) but the Node of Attribution is immutable. A DeliveryTag for Node A can be resold to another buyer at Node A, but never re-scoped to Node B. On EAC secondary markets, buyers filter by their node; the marketplace matches sellers who hold certificates attributed to that specific node. This creates node-specific liquidity pools rather than a single fungible market, reflecting the physical reality of grid delivery.

4.3 Issuance

Structural independence

DeliveryTag is structurally independent of any matching platform, ETRM provider, or registry. This independence is required by ISAE 3000: an attestation source cannot be the same entity that produces the management assertion. The Accredited Signer audits the DeliveryTag evidence chain (hardware-signed sensor data, PTDF computation, Hedera anchoring) as a source independent of any commercial matching engine that consumes the certificate downstream.

ETRM and portfolio-management platforms (Granular Energy, Power Ledger, and others) consume DeliveryTag attestations as inputs to their hourly matching, allocation, and reporting workflows. They do not replace the attestation. This separation of roles, measurement, attestation, matching, prevents the judge-and-party conflict that ISAE 3000 and ISO 14065 are designed to eliminate.

A DeliveryTag is issued by the Integrity Protocol Foundation upon certification by an Accredited Signer, a party qualified to issue a reasonable-assurance opinion under ISAE 3000 (or equivalent). Intended scope includes major international assurance practices and ISO 14065 / IAF-MLA accredited validation bodies. No assurance engagement is in place as of this publication. Executing a signed engagement is a gating dependency for Tier 1 and Tier 2 issuance and a pilot acceptance criterion (Section 10); until a reasonable-assurance opinion is issued, the DT-F assurance level is a design target, not an attested status. Engagements will be disclosed once in place. Issuance requires the following independent inputs:

  • a valid underlying GC (produced and metered under the EnergyTag framework),
  • a TSO dispatch log entry (merit-order data covering the issuance time interval),
  • a Power Transfer Distribution Factor attestation from the Dispatch Verification Body, confirming that the named generator or flex curtailment physically relieved the buyer’s node during the interval,
  • for US RTO/ISO jurisdictions (MISO, PJM, ERCOT, CAISO, SPP, NYISO), a third-party Locational Marginal Emissions (LME) attestation from an accredited LME provider, quantifying the fossil-marginal emissions displaced by the clean injection or flex curtailment at the specific node and hour (for EU bidding-zone jurisdictions, ENTSO-E and national TSO dispatch data is used instead, as described in the subsection below), and
  • an Accredited Signer certification confirming proof integrity and compliance with the DeliveryTag standard.

Issuance timing is jurisdiction-dependent and is bounded by the availability of final settlement data:

D+1 to D+7

EU Jurisdictions (ENTSO-E)

LME is not mandatory. The EU grid uses bidding zones, not nodal pricing. Deliverability is computed from public flow and congestion data (ENTSO-E Transparency Platform, JAO flow-based parameters, national redispatch publications) plus TSO network and dispatch data under data-access agreements (§9). Emissions impact is derived from the counterfactual generator's known emissions factor. Settlement at D+1.

T+30 to T+45

US Jurisdictions (RTO/ISO + LME)

LME is mandatory. US RTOs use nodal pricing (LMP). Settlement-grade LME is supplied by accredited third-party providers. LME reconciles RTO final settlement dispatch, ex-post generator attribution, and congestion components. Published on month-end batch cycle. DeliveryTag issuance in MISO, PJM, ERCOT, CAISO, SPP, NYISO.

4.3.1 Provisional and Final Issuance States

To support the two-speed timing of EU and US markets without forcing buyers to wait 30–45 days for a certificate, the DeliveryTag specification defines two issuance states:

Provisional DeliveryTag (DT-P). A DeliveryTag issued with preliminary dispatch data and a candidate LME estimate. DT-P is valid for internal reporting, PPA settlement, and buyer-side accruals, but is not ISAE 3000 attestable as a final certificate. DT-P is issued at D+1 to D+7.

Final DeliveryTag (DT-F). A DeliveryTag issued after final settlement data and third-party LME attestation are received. DT-F supersedes the DT-P with identical registry serial (same parent GC, same Node of Attribution) and carries the full Causal Dispatch Proof object. DT-F is issued at D+30 to D+45 in US jurisdictions and at D+1 to D+7 in EU jurisdictions where no third-party LME settlement is required.

A DT-P that is not promoted to DT-F within the maximum window (60 days) is automatically voided in the registry and cannot be used for cancellation. A DT-F that materially diverges from its DT-P predecessor (>10% on PTDF relief or >15% on LME) triggers a mandatory correction notice to the offtaker and the Dispatch Verification Body.

This two-state lifecycle mirrors the provisional/final structure already used in RTO settlement accounting (e.g. MISO’s Initial Settlement Statement at T+5 days and Final Settlement Statement at T+55 days) and preserves the EnergyTag principle of cancellation against measured consumption without blocking near-real-time operational workflows.

4.4 Transfer

DeliveryTag certificates transfer as extension attributes on their parent GCs. Transfer between accounts follows EnergyTag transfer semantics. However, transfer does not break the nodal binding: a DeliveryTag continues to attest to its original node of attribution regardless of which account holds it. Buyers may transfer DeliveryTags to affiliates or aggregators but may not re-scope the node of attribution.

4.5 Cancellation and Retirement

DeliveryTags cancel against measured consumption at a specific Consumption Point in accordance with the EnergyTag cancellation principle. Additionally, the DeliveryTag can only be cancelled against consumption that is electrically connected to the node of attribution specified in the certificate. A DeliveryTag issued for node X cannot be cancelled against consumption at node Y, even if the timestamps match.

The node-binding check is enforced cryptographically through the Demand-side PIN (D-PIN) installed at the buyer’s consumption point, which is registered to a specific transmission node in the Guardian policy and signs the cancellation certificate with CRYSTALS-Dilithium before Hedera anchoring. This makes the “node X ≠ node Y” rule a computational constraint, not a procedural one. See Section 4.11.2 for the D-PIN architecture and the three cancellation tiers (Tier 1 full seven-layer validation with D-PIN; Tier 2 attested meter; Tier 3 registry-only).

4.5.1 Claim-Based Allocation at Multi-Buyer Nodes

Most practical grid nodes serve several consumers simultaneously (urban substations, 345 kV collector buses, industrial zones, hyperscaler co-location campuses). When a node’s deliverable clean capacity at hour H, capped by the corridor-headroom check (§7.1), is less than the aggregate demand of the buyers connected to that node, a resolution rule is required. DeliveryTag uses a market-driven, claim-based allocation with two cryptographic constraints, enforced at the Guardian policy layer:

Issuance constraint. The Guardian policy rejects any DT-F issuance that would push the total issued at (node, hour) above the node-hour deliverability cap: the minimum of the named portfolio’s metered injection, the aggregate metered consumption at the node, and the transfer capability implied by the binding corridor’s available headroom and the transfer’s PTDF on that corridor. This is enforced by the total-node-issuance-check-block against the applicable PTDF matrix and corridor-loading data. Scarcity at the node is enforced at the source, not post hoc.

Cancellation constraint. Each buyer can only retire DT-Fs against its own verified consumption at the node. In Tier 1 this is enforced cryptographically: the buyer’s D-PIN signs a cancellation bundle and the Guardian policy compares the retired volume against the D-PIN’s attested consumption for the hour. A buyer cannot retire more than it consumed, and cannot retire against another buyer’s consumption. In Tier 2 the same constraint is enforced by an Accredited Signer attestation over the buyer’s metered consumption.

Market allocation. Scarce node-hour DT-Fs are traded on the EAC-compatible secondary markets. Price allocates scarce capacity to the highest willingness-to-pay, naturally serving the most demanding 24/7 CFE commitments first. The protocol does not set the allocation; it enforces the two constraints and lets the market resolve the distribution.

The combination of headroom-capped issuance, D-PIN-enforced cancellation, and market-priced allocation makes multi-buyer node attribution fully decentralised, cryptographically verifiable, and privacy-preserving between competing buyers. No buyer needs to disclose its consumption data to another, and the TSO remains a passive publisher of PTDF and dispatch data rather than an active data intermediary.

4.6 Registration

DeliveryTags register in an EnergyTag-compatible registry (e.g. M-RETS, Guarantee of Origin hub, Hedera Guardian topic). Proof data is anchored on Hedera (HCS for consensus, HTS for tokenized certificates). Certificates carrying DeliveryTag proofs trade on the EAC-compatible secondary markets, where buyers access verified 24/7 CFE instruments. The extension attributes required for DeliveryTag registration are:

Attribute Description
node_of_attribution ISO-standard transmission substation identifier
ptdf_relief_mw Numeric, MW of corridor headroom freed
dispatch_log_hash Cryptographic hash of TSO merit-order log covering the interval
counterfactual_lme Locational marginal emissions displaced, tCO₂e/MWh
flex_curtailment_ids Array of sub-metered flexible-load SCADA identifiers

4.6.1 Registry-Independent Integrity

The DeliveryTag proof chain survives independently of any certificate registry. The proof lives on Hedera, not in the registry. The registry stores only a pointer (hedera_proof_id) to the immutable proof on the public ledger.

The registry is the filing cabinet. Hedera is the notary. Certificates can move between registries (M-RETS, AIB Hub, GREXEL, Hedera Guardian). The notarial stamp (Hedera anchoring + PQC signature + Accredited Signer countersign) remains identical and independently verifiable, forever.

Accredited Signer audit trails are registry-independent. The audit follows the same 7-step path regardless of which registry holds the certificate:

1 Receive Hedera proof ID
2 Query Hedera HCS for signed bundle
3 Verify PQC signature (PIN hardware)
4 Check all 7 validation-layer sensor readings
5 Verify PTDF against TSO data
6 Confirm Oracle verdict (Mode B)
7 Issue Accredited Signer certification (ISAE 3000)

This architecture is strictly stronger than traditional GO integrity. If a registry is compromised or deletes a record, the Hedera proof survives. The HTS token is atomic: the same certificate cannot exist in two registries simultaneously.

PhaseApproachRegistries
2026Direct APIM-RETS (US), Hedera Guardian
2027Secondary-market APIEAC trading venues
2027+AIB Hub bridgeAIB Hub EECS member registries (~30 issuing bodies across 36 European countries; AIB, 2026)
§4.6.2, Marketplace Integration

The Math Meets the Market

DeliveryTag does not operate its own exchange. Verified certificates trade on EAC-compatible secondary markets. DeliveryTag provides the physics layer; the secondary market provides the liquidity layer.

01, SCHEMA
Metadata Extension

A single field (dt_proof_id) added to the GC schema. Zero changes to matching engine or settlement.

02, API
API Bridge

DeliveryTag API returns verification status in real time. GCs display a “DT Verified” badge in the order book.

03, FEED
Exchange Data Feed

Verification data published alongside price data on exchange-connected terminals. Banks and utilities see sensor confidence and PTDF attribution in their existing workflow.

Physics-backed certainty, priced accordingly. A DT-verified GC bundles nodal PTDF attribution, dual-PIN attestation, and an evidence chain designed for ISAE 3000 assurance. The design thesis is that buyers pursuing externally assured 24/7 CFE, hydrogen, and Scope 2 claims will treat that evidence as a material input and price it as one; the pilots exist to test that thesis.

4.7 Nodal Attribution (New Component)

The Dispatch Verification Body, an independent entity distinct from the GC Issuer and the Measurement Body, is responsible for validating that the TSO dispatch log and the flex-curtailment telemetry are consistent and that the PTDF-weighted relief attested in the DeliveryTag is mathematically sound. Candidate entities include national TSOs, regional system operators (ENTSO-E for the EU), independent grid analytics firms (accredited LME providers for North America), and accredited third-party auditors.

4.8 Causal Dispatch Proof (New Component)

Each DeliveryTag carries a causal dispatch proof: a structured data object containing:

  • (i) the TSO merit-order log for the interval,
  • (ii) the PTDF matrix row covering the node of attribution,
  • (iii) the flexible-load SCADA telemetry that was curtailed or dispatched, and
  • (iv) the counterfactual LME calculation.

This object is hashed and anchored in the registry.

4.9 Hepta-Validation™: The Forensic Proof Stack

To ensure verifiability and raise the cost of replication by pure software traders, the DeliveryTag protocol anchors each Causal Dispatch Proof in seven independent Hardware-Verified Event layers, branded Hepta-Validation and referred to throughout this document by its plain name, the seven-layer validation stack: six observational layers grounded in physical measurement, plus one economic baseline:

Layer Sensor / Source Verification Target
1. Electrical Revenue-grade IEC 62053-22 Class 0.2S metering kWh consumed / curtailed at 15-min interval resolution
2. Thermal FLIR infrared sensors Equipment cooldown signature proving physical load reduction, not meter manipulation
3. Magnetic + Freq Fluxgate magnetometers + frequency analyzers Current flow cessation at feeder level (Ampère’s Law) + 50/60 Hz voltage-waveform and harmonic analysis confirming synchronous operation and time-aligning the record against reference grid-frequency data (anti-replay)
4. Acoustic Decibel monitoring arrays Mechanical cessation of industrial equipment (arc furnaces, compressors, turbines)
5. Spatial Satellite multispectral / SAR imagery Upstream generation restart confirmation; wind turbine restart verification post-curtailment
6. Emissions Mass balance sensors (Lavoisier’s Law) Carbon in fuel = carbon in exhaust; emissions displacement verified via conservation of mass
7. Economic Opportunity Cost Oracle Economic baseline: real-time comparison of facility revenue potential vs. curtailment cost distinguishes deliberate sacrifice from market exit (rationale in §4.10, Layer 7)

Layers 1–4 are collected at the edge gateway installed at the flex load facility (not on grid infrastructure). Layer 5 is sourced from independent satellite providers using multispectral imagery. Layer 6 applies Lavoisier’s conservation of mass to verify emissions displacement. Layer 7 is computed from real-time market prices and the facility’s production schedule (economic-baseline rationale in §4.10).

Each seven-layer validation event is signed with a Post-Quantum Cryptographic (PQC) signature (CRYSTALS-Dilithium) at the edge gateway, ensuring tamper-resistance against both classical and quantum adversaries. The signed proof object is then anchored to a Hedera Guardian topic, producing a public, immutable, timestamped record that can be independently verified by any auditor without privileged access. The combination of hardware-verified sensor data, PQC-signed proof objects, and Hedera’s distributed ledger creates a hardware-rooted evidence chain that software-only certificate systems are not designed to provide.

4.10 Physical Principles as Verification Infrastructure

DeliveryTag grounds its sensor stack in five physical principles, Kirchhoff’s and Ohm’s Laws (electrical and thermal via the Joule effect), Ampère’s Law (magnetic), mechanical vibration (acoustic), and conservation of mass (emissions inference), plus an economic baseline (Layer 7), deployed across the seven validation layers of Section 4.9. Physical sensor corroboration is designed to make paper-only falsification detectable: a claimed curtailment must simultaneously reproduce consistent electrical, thermal, magnetic, and acoustic signatures, each independently signed at source and cross-checked against calibrated thresholds. Appendix A specifies the adversary model and residual risks.

1. Ohm’s Law and the Thermal Signature (Joule Effect)

Ohm’s Law is inseparable from the Joule effect: P = R × I². When current (I) flows through a cable or machine, resistance (R) converts part of the energy into heat.

DeliveryTag application (Layer 2, Thermal): FLIR infrared sensors measure this thermal signature. When a refinery or data center curtails load, Ohm’s Law dictates that conductor temperature must drop. If a trader attempts to falsify a curtailment on paper, the equipment remains hot. The FLIR sensor is the “lie detector” grounded in Ohm’s Law.

2. Ampère’s Law and the Magnetic Signature

Ampère’s Law states that every electric current generates a magnetic field proportional to its intensity. Ohm’s Law determines the current intensity (I) flowing through a circuit for a given voltage (U), and Ampère’s Law translates that current into a measurable magnetic field.

DeliveryTag application (Layer 3, Magnetic + Frequency): Fluxgate magnetometers measure the facility’s actual magnetic-field signature (branded the “Nodal Pulse”). The protocol does not trust the utility meter (which can be hacked or simulated), it measures the actual magnetic field generated by electrons in motion. Additionally, frequency analyzers sample the local 50/60 Hz voltage waveform. Because grid frequency is uniform across a synchronous area, a single facility’s curtailment does not produce a locally distinguishable frequency deviation; the frequency channel is instead used to confirm the site is energised and synchronised to its interconnection, to time-align the signed sensor record against reference grid-frequency data (an electric-network-frequency check that resists replay of previously recorded bundles), and to capture local waveform and harmonic changes when large equipment switches off. This combined measurement, magnetic field intensity plus waveform behaviour, corroborates that current actually flowed, or stopped flowing, at the monitored feeder.

3. PTDFs: Ohm’s Law Applied to the Grid

The Power Transfer Distribution Factors (PTDFs) used to compute the “Virtual Cable” (in plain terms, the PTDF-weighted delivery path between generator and buyer node) are the mathematical resolution of Ohm’s Law across a complex network. Electricity distributes across all available paths inversely proportional to impedance (Kirchhoff's Laws).

DeliveryTag application (PTDF Binding): By modifying the load at a precise node, the distribution of power flows across the network changes according to Kirchhoff’s and Ohm’s Laws. The DeliveryTag certificate evidences that physical corridor capacity was freed by acting on the global impedance of the system.

Why This Is the Anti-Greenwashing Argument

An energy trader works with LMPs (Locational Marginal Prices), which are economic signals. DeliveryTag couples those signals to physical measurements taken at the facility.

The physics cross-check. A market price can be manipulated or misreported; a physical signature has to be produced by real equipment. By coupling certificates to the thermal and magnetic signatures measured at the facility, DeliveryTag attaches a “physical receipt” to each claim. Falsifying a curtailment on paper would require simultaneously reproducing consistent electrical, thermal, magnetic, and acoustic readings, each signed at source inside sealed hardware. This is what is designed to make the DeliveryTag certificate resistant to greenwashing: not absolute certainty, but a materially higher cost of forgery, bounded by the adversary model and residual risks stated in Appendix A.

4. Mechanical Vibration and the Acoustic Signature

Operating industrial equipment (arc furnaces, compressors, turbines) produces characteristic vibro-acoustic signatures generated by the mechanical forces at work inside it. Those signatures disappear when the machinery stops.

DeliveryTag application (Layer 4, Acoustic): Decibel monitoring arrays at the flex load facility detect the disappearance of the equipment’s operating acoustic signature when it shuts down during curtailment, measured against a calibrated site baseline that accounts for ambient and neighbouring-equipment noise. A facility claiming curtailment while its machinery keeps running would have to suppress this signature and keep it consistent with the electrical, thermal, and magnetic layers simultaneously; the cross-check is designed to detect that inconsistency.

5. Lavoisier’s Law and the Emissions Signature

Lavoisier’s Law (Conservation of Mass) states that in any chemical reaction, mass is neither created nor destroyed. In combustion: carbon in fuel = carbon in exhaust. This principle underpins emissions verification.

DeliveryTag application (Layer 6, Emissions): By measuring the mass balance of combustion inputs and outputs at the marginal generator, DeliveryTag verifies that emissions displacement actually occurred. When a flex curtailment displaces a fossil generator, Lavoisier’s Law provides an independent physical confirmation that the carbon was not emitted; the fuel was not burned, therefore the CO₂ was not produced.

The Economic Baseline: Why Financial Sacrifice Matters

Physical verification alone is necessary but not sufficient. A facility that shuts down because spot prices dropped below its marginal cost has not made a sacrifice; it has simply exited the market. For freed transmission capacity to be credible and tradeable, the protocol must prove that curtailment was a deliberate economic sacrifice, that the facility was forgoing real revenue by curtailing.

DeliveryTag application (Layer 7, Economic): The Opportunity Cost Oracle compares the facility’s real-time revenue potential (based on spot prices, the facility’s marginal cost, and its production schedule) against the curtailment cost. If the oracle confirms that the facility was profitable at the moment of curtailment, the sacrifice is genuine and the freed capacity becomes a credible, sellable asset. If the facility was already losing money, the curtailment is flagged as a market exit and the freed capacity claim is rejected. This economic baseline is the final gatekeeper that transforms a physical event into a trustworthy financial instrument.

From Accounting Promise to Physical Proof

Principle Measurable Effect Validation Layer What It Proves
Joule Effect
P = R × I²
Heat dissipation in conductors Layer 2, Thermal (FLIR) Equipment actually powered down
Ampère’s Law
∮ B · dl = μ₀I
Magnetic field around conductors Layer 3, Magnetic (Fluxgate) Current actually stopped flowing
Waveform & Synchronism
f = 50/60 Hz
Local AC voltage-waveform and harmonic behaviour Layer 3, Frequency channel Site energised and synchronised to its interconnection; record time-aligned against reference grid-frequency data (anti-replay)
Kirchhoff + Ohm
V = Z × I (network)
Power flow redistribution PTDF Binding Corridor capacity physically freed
Mechanical Vibration
Vibro-acoustic signature
Acoustic vibration cessation Layer 4, Acoustic (dB arrays) Industrial machinery actually stopped
Lavoisier’s Law
Conservation of Mass
Carbon mass balance in combustion Layer 6, Emissions (mass balance) Emissions displacement physically verified
Economic Baseline
Opportunity Cost
Revenue potential vs. curtailment cost Layer 7, Economic (Oracle) Curtailment was sacrifice, not market exit

4.10b The Seven-Step Certification Pipeline

From grid physics to immutable certificate: seven steps transform raw sensor data into a verifiable, auditable DeliveryTag anchored on the Hedera Guardian ledger.

1 DETECT

Grid congestion detected via PTDF analysis and satellite multispectral imagery. Corridor saturation identified at the transmission node.

2 CURTAIL

Flex load portfolio curtails demand at the congested node, freeing PTDF-weighted corridor capacity for clean energy delivery.

3 VERIFY

The seven-layer validation stack (§4.9) confirms curtailment via five physical principles plus an economic baseline: Kirchhoff/Ohm (electrical), Joule effect (thermal), Ampère (magnetic), mechanical vibration (acoustic), conservation of mass (emissions), and the Opportunity Cost Oracle (economic).

4 SIGN

Post-Quantum Cryptographic (PQC) signature (CRYSTALS-Dilithium) seals the proof object at the edge gateway. Quantum-resistant integrity.

5 ANCHOR

Signed proof anchored to Hedera Guardian ledger, producing a public, immutable, timestamped record verifiable by any auditor.

6 AUDIT

Accredited Signer (qualified under ISAE 3000) certifies proof integrity and compliance.

7 ISSUE

Upon Accredited Signer certification, the Integrity Protocol Foundation issues the DeliveryTag certificate as an extension attribute on a standard EnergyTag Granular Certificate.

Accredited Signer Independence. The Accredited Signer operates independently of the Integrity Protocol Foundation and the flex load operator. Accredited Signer auditors have read-only access to the Hedera-anchored proof chain and sensor telemetry. Their certification is a prerequisite for DeliveryTag issuance: no certificate can be issued without third-party verification.

4.11 The Physical Integrity Node (PIN), Supply-side and Demand-side

DeliveryTag uses a dual-PIN architecture: a Supply-side PIN (S-PIN) at the generation or flex-load facility, and a Demand-side PIN (D-PIN) at the buyer’s consumption point. Together they close the forensic chain end-to-end. The S-PIN proves the MWh was produced or curtailed; the D-PIN proves it was consumed at the node claimed on the certificate. Without the D-PIN, cancellation would depend on a human-audited utility meter, which is the same weak link DeliveryTag removes on the supply side.

4.11.1 Supply-side PIN (S-PIN)

The S-PIN is a tamper-evident, industrially sealed hardware unit installed at the point of interconnection (busbar) of each generation or flex-load facility. It is the physical root of trust for issuance-side seven-layer validation data.

Definition. The S-PIN is an industrial “black box” sealed at the busbar, combining sensor fusion, cryptographic signing, and secure uplink in a single enclosure. It is designed so that any access, modification, or bypass by the facility operator breaks the tamper-evident seal, which invalidates all subsequent certificates.

Sensor fusion. The S-PIN aggregates four real-time sensor streams at the point of measurement:

  • Electrical: Revenue-grade IEC 62053-22 Class 0.2S current/voltage measurement at 15-min intervals
  • Magnetic + Frequency: Fluxgate magnetometer measuring magnetic field (Ampère’s Law) + frequency analyzer sampling the 50/60 Hz voltage waveform (synchronism, harmonics, and anti-replay time alignment) at the flex load facility feeder conductors
  • Thermal: FLIR infrared sensor capturing the Joule-effect thermal signature (Ohm’s Law) at the flex load facility equipment
  • Acoustic: Decibel array monitoring mechanical vibration of industrial equipment

Post-Quantum Cryptographic (PQC) signing at the source. Every 15-minute sensor bundle is signed inside the S-PIN using CRYSTALS-Dilithium (NIST FIPS 204), a lattice-based digital signature algorithm resistant to both classical and quantum adversaries. The private key is generated and stored in the S-PIN’s secure element and never leaves the device.

Why sign at the source? If sensor data were signed at a cloud server or registry, the path between the physical measurement and the cryptographic proof would be vulnerable to man-in-the-middle manipulation. By signing inside the sealed PIN at the busbar, DeliveryTag is designed so that no data exists in unsigned form outside the hardware enclosure. The chain of custody is: physics, sensor, PQC signature, Hedera anchor. No software layer touches raw data.

4.11.2 Demand-side PIN (D-PIN)

The D-PIN is the mirror-image hardware unit installed at the point of interconnection of the buyer’s consumption site, typically the main busbar or service entrance of a hyperscaler data center, industrial facility, or aggregated flex-load pool. Its role is the cancellation counterpart to the S-PIN’s issuance proof.

The D-PIN performs three functions:

  1. Consumption measurement. Revenue-grade IEC 62053-22 Class 0.2S metering at 15-min intervals, signed inside the D-PIN with CRYSTALS-Dilithium and anchored on Hedera.
  2. Node binding proof. The D-PIN’s device certificate is registered to a specific transmission node in the Guardian policy and is cryptographically bound to the buyer’s TSO interconnection agreement. A DeliveryTag issued for node X can only be cancelled against a D-PIN registered at node X. Node identity rests on the witnessed physical install and the AssuranceAccreditation VC, backed by registry-level binding and hardware-level PQC signing; spoofing a node therefore requires defeating both the physical attestation and the device key, which the protocol is designed to make impractical within the adversary model of Appendix A (post-install relocation is treated as an explicit threat there).
  3. Counterbalance check. The D-PIN signs a cancellation certificate that goes onto Hedera alongside the issuance certificate. The Guardian policy rejects any second cancellation against the same consumption hour on the same D-PIN, enforcing the “no direct counterbalancing reverse transactions” clause from WRI Alternate Methodology 2 (see Section 3.4).

D-PIN sensor stack. Unlike the S-PIN, which carries the full seven-layer validation stack to prove curtailment events, the D-PIN answers a narrower question: “did this buyer consume N kWh at this node during this hour?” This requires only three sensor channels drawn from the seven-layer stack (Electrical, plus the magnetic and frequency channels of the Magnetic + Frequency layer), with a fourth (Thermal) optional for reasonable-assurance engagements.

#LayerSensorPurposeStatus
1ElectricalIEC 62053-22 Class 0.2S revenue-grade meter (CT + VT) at the main busbar, 15-min intervalsMeasure kWh consumedRequired
2MagneticFluxgate magnetometer clamped on the feeder conductorProve current physically flowed (Ampère’s Law), not a meter-only figureRequired
3Frequency50/60 Hz grid-frequency analyzer sampling the voltage waveformConfirm the site is energised and synchronised to its interconnection, and time-align the signed record against reference grid-frequency data (anti-replay). Frequency is uniform within a synchronous area, so this channel corroborates liveness and timing; it does not by itself prove nodal locationRequired
4ThermalFLIR infrared pointed at the main transformer or server hallCorroborate real load via Joule effect (heat = consumption)Optional, recommended for ISAE 3000 reasonable assurance

Layers 5 (Spatial/SAR), 6 (Emissions), and 7 (Opportunity Cost Oracle) are not applicable to the D-PIN. They are S-PIN-specific proofs of curtailment and generation events.

Every D-PIN shares the same cryptographic core as the S-PIN: a secure element generating and storing a CRYSTALS-Dilithium private key that never leaves the device, a tamper-evident seal that zeroises the key if broken, a GPS-disciplined UTC time source for 15-min interval alignment, and a hardened uplink to the Guardian relay. The lighter sensor set means D-PIN CapEx is materially lower than S-PIN CapEx, which is what makes Tier 1 deployment practical at hyperscaler scale.

Why a D-PIN, not just a trusted utility meter? A buyer’s 24/7 CFE claim is only as strong as its weakest proof. Hardware-verified issuance signed by the S-PIN, then cancelled against a software-reported utility-meter value, is not hardware-verified end-to-end. The D-PIN closes that gap. For ISAE 3000 reasonable-assurance engagements, dual-PIN is the architecture designed to remove trusted third parties from the entire proof chain.

Why the D-PIN is structurally required for multi-buyer nodes. Most practical grid nodes serve several buyers simultaneously (urban substations, 345 kV collector buses, industrial zones, hyperscaler co-location campuses). Without a D-PIN per buyer, per-buyer attribution depends on disclosure of TSO settlement data, which (i) exposes commercial consumption between competing buyers, (ii) makes the TSO an active trust intermediary rather than a passive publisher, and (iii) is not typically granular or timely enough for hourly claims. A D-PIN resolves all three: each buyer signs its own consumption slice cryptographically, the TSO’s role is reduced to the network and flow data it already provides (published flow-based parameters plus model access under standing data-access agreements, §9), and privacy between competing buyers is preserved by construction. For any node with two or more DeliveryTag buyers, Tier 1 (D-PIN present) is the only architecture that works cleanly. See Section 4.5.1 for the claim-based allocation model this enables.

Deployment and Regulatory Footprint

The D-PIN is a passive measurement device installed on the buyer’s side of the utility revenue meter. It clamps non-invasively onto the buyer’s own conductors (CT/VT tap, fluxgate on the feeder), signs bundles inside the tamper-sealed enclosure, and pushes signed telemetry via an outbound uplink. It does not inject power, control loads, or interact with the grid operator’s equipment. Its regulatory category is identical to a commercial power-quality monitor, a tenant sub-meter, or a Building Energy Management System.

Required for deployment:

  • UL listing (US) or CE marking (EU) on the hardware, provided once by the manufacturer
  • Licensed electrician to perform the physical install (four to eight hours of work per site)
  • Local electrical inspector sign-off under the applicable electrical code (NEC in the US, national code in the EU); typical one-day turnaround

Not required:

  • Utility or transmission-operator approval
  • PUC or PSC filing (US state), or FERC notification (US federal)
  • TSO interconnection study (EU or US)
  • Any form of grid-operator sign-off

For Tier 1 (reasonable-assurance) deployment, the Accredited Signer additionally witnesses the install, verifies the CT/VT tap points and tamper seal, photographs the installation for the ISAE 3000 evidence file, and issues the AssuranceAccreditation VC that binds the device’s Dilithium public key to the claimed transmission node.

Strategic consequence. Because the D-PIN sits entirely on buyer-owned property, hyperscalers and large industrial buyers can deploy unilaterally, without negotiating with the serving utility or entering a regulatory docket. Time to deploy is measured in weeks per site, and sites can be onboarded in parallel across an entire portfolio.

Multi-POI and Multi-Source Configurations

A single buyer may operate multiple D-PINs under one Buyer DID when the site has redundant feeders (two POIs at the same node) or dual-fed service (two POIs at different transmission nodes). Each D-PIN registers against its own tso_interconnection_node. At cancellation, the Guardian policy matches each DT-F to the D-PIN whose node equals the certificate's node_of_attribution, and sums D-PIN-attested consumption when multiple feeders serve the same node. Certificate-level generator provenance (nuclear, wind, solar) is preserved by the DT-F's immutable fields (generator_did, generator_node_of_injection) and is independent of which D-PIN the certificate retires against: a nuclear-backed DT-F and a solar-backed DT-F can both retire against the same D-PIN in the same hour, provided the sum of retirements does not exceed the D-PIN's attested consumption and each certificate's node_of_attribution matches a registered D-PIN. Physically source-segregated internal loops (“green loops”, where a tenant or use case is fed only by specific generation types) can be served by dedicated sub-D-PINs registered under the same Buyer DID if the buyer requires loop-level claim attribution.

4.11.3 Deployment Tiers

Not every reporter requires a D-PIN in every deployment. The specification defines three cancellation tiers matching audience requirements:

TierD-PINCancellation ProofAssurance Level
Tier 1, Full Seven-LayerYesHardware-signed, end-to-end cryptographicISAE 3000 reasonable assurance (default for hyperscaler 24/7 CFE, regulated 45V hydrogen, externally assured corporate Scope 2)
Tier 2, Attested MeterNoUtility revenue meter, plus Accredited Signer attestation that the meter is located at the claimed nodeISAE 3000 limited assurance (transitional, smaller reporters; phase-out target 2028)
Tier 3, Registry-onlyNoTSO interconnection agreement, plus registry-level node bindingOperational claims only; not sufficient for Scope 2 or 24/7 CFE claims under the revised GHG Protocol

Tier 1 is the default for DeliveryTag-issued certificates. Tier 2 is available during the transition window (2026, 2028) to support buyers whose infrastructure cannot yet accommodate a D-PIN. Tier 3 covers operational or internal reporting only.

Part C
C

Economics & Governance

The market value of nodal granularity, the three cancellation tiers, and the Integrity Protocol Foundation governance designed to keep the standard vendor-neutral.

Sections 5 6

5. Benefits of Nodal Granularity

Physics Scope

What DeliveryTag Claims, and What It Does Not

DeliveryTag does not claim to track individual electrons. In an AC grid, electrons oscillate in place and are fungible once injected; tracing a specific particle from a generator to a load is not physically meaningful. What DeliveryTag provides is auditable deliverability inference under network-flow physics, evidence that the MWh attributed to a buyer’s node was causally dispatched, routed through the claimed corridor, and registered at the claimed meter within the claimed interval, at a level of rigor suitable for ISAE 3000 attestation.

01
Corridor Attribution
A PTDF-based corridor-headroom check verifies the network could accommodate the attributed transfer from the named generator, or the relief from the named curtailment, to the buyer’s node. Kirchhoff compliance.
02
Causal Dispatch
TSO merit-order logs place the named asset within the dispatch stack that cleared the interval. Not a post-hoc paper trade.
03
Seven-Layer Validation
Seven-layer sensor stack (dual-PIN + Tri-Sensor) attests the event occurred at the claimed site and time. Not inferred from invoices.

5.1 Grid Physics (Kirchhoff Compliance)

Electricity flows according to physical laws of the network, not the legal structure of contracts. A GC without nodal binding can attest to clean production during an hour in which the clean MWh could not physically reach the consumer due to corridor saturation. Nodal binding resolves this by requiring that the certificate be issued only when the PTDF-based corridor-headroom check confirms the network could physically accommodate the attributed transfer from the named generator (or the relief from the named curtailment) to the buyer’s node, with attributed MWh capped at the buyer’s metered consumption. This is Kirchhoff compliance.

5.2 Carbon Accounting (Locational Marginal Emissions)

The emissions impact of 1 MWh of clean energy depends entirely on which generator it displaces. Displacing a lignite plant at a congested Polish node avoids ~1,000 kgCO₂e/MWh; displacing a gas plant at an uncongested Spanish node avoids ~350 kgCO₂e/MWh. The EnergyTag GC framework supports grid-average or market-wide emissions valuation; DeliveryTag supplements this with optional node-specific Locational Marginal Emissions derived from the TSO dispatch log, for use cases that require finer attribution. Peer-reviewed validation work using ERCOT wind-farm data has shown that dispatch-based locational marginal emissions models track real-world emissions impacts where average-emissions methods do not (Steinsultz et al., Validating locational marginal emissions models with wind generation, Environmental Research: Energy, 2024), and the accompanying industry analysis reports that nodal-resolution signals can differ from lower-resolution emissions models by up to roughly 50% (REsurety, 2024).

US: Third-Party LME (Mandatory)

Nodal pricing (LMP) enables settlement-grade LME computation. Accredited LME providers compute these values, deriving nodal marginal emissions from RTO final dispatch at T+30 to T+45. The LME value is the primary emissions metric on US DeliveryTags.

EU: Congestion + Counterfactual (Primary)

The EU grid uses bidding zones, not nodal LMP. Emissions impact is derived from congestion data (corridor utilization, published redispatch measures) and the counterfactual generator’s emissions factor, identified from ENTSO-E per-unit generation data and TSO dispatch records obtained under data-access agreements (§9). Public inputs available at D+1.

5.3 Flexibility Incentives (Virtual Transmission)

Because the DeliveryTag attributes corridor relief to specific flexible loads (heat pumps, electric boilers, electrolyzers, demand response, BESS, industrial furnaces), it creates a direct, auditable revenue path for flexibility services. A 100 MW flex pool dispatching in PTDF merit order to relieve a corridor earns DeliveryTag revenue proportional to the PTDF-weighted MW relieved, the corridor’s marginal price, and the buyer’s willingness to pay for verified 24/7 CFE. This is the commercial mechanism that enables “virtual transmission”, capacity expansion through flexibility rather than through new lines.

DSEE Computation, Equivalent Renewable Capacity (USPTO provisional application 64/023,803)

ERC(N, T) = ΔL(N, T) × [ LME(N, T) / LMEbaseline(N) ]
ERC, Equivalent Renewable Capacity (MWh of virtual clean generation)
ΔL, Verified Load Reduction at node N during interval T (hardware-verified via the seven-layer stack, §4.9)
LME(N,T), Locational Marginal Emissions rate at node N, interval T (tCO₂e/MWh)
LMEbaseline(N), 12-month rolling average marginal emissions at the node

When LME(N, T) > LMEbaseline(N), i.e. during high-carbon hours, the ERC exceeds the raw load reduction, reflecting the disproportionate emissions impact of curtailing during dirty hours.

US Input: settlement-grade LME

LME(N, T) = settlement-grade nodal marginal emissions, computed from RTO final dispatch at T+30 to T+45. The US LME methodology is proprietary to accredited third-party providers.

EU Input: Counterfactual Emissions Factor

LME(N, T) = emissions factor of the counterfactual generator identified from TSO merit-order logs + ENTSO-E congestion data. This computation is described in the DSEE provisional application (USPTO 64/023,803), positioning it as the European counterpart of the proprietary US LME methodology.

The DSEE formula is jurisdiction-agnostic. It accepts either a third-party LME value (US) or a counterfactual emissions factor derived from congestion + dispatch data (EU). The provisional application describes the computation method for both markets; enforceable rights would arise only from claims granted on the planned non-provisional filing.

5.4 Hydrogen (RED III Article 19 Compliance)

EU RED III Article 19 requires that renewable fuels of non-biological origin (RFNBOs) demonstrate temporal and geographic correlation with their renewable electricity input. The temporal correlation is addressed by EnergyTag GCs; the geographic correlation, currently handled at the bidding-zone level, is the dimension DeliveryTag adds finer resolution to via node-bound PTDF attestation, giving green-hydrogen producers a defensible certificate for regulatory filings and offtake contracts.

H₂ Producer
Electrolyzer
Renewable Input
Temporal ✓   Geographic ?
DeliveryTag
Temporal ✓
Geographic ✓
Physical ✓
RED III Art. 19
Compliant RFNBO
Assurance-ready proof

DeliveryTag closes the geographic correlation gap required by RED III Article 19 for green hydrogen certification.

5.5 Hyperscaler Trust

Hyperscale data-center operators are the archetypal buyer segment for deliverability evidence. Two have published hourly-matching commitments on the public record: Google (24/7 Carbon-Free Energy by 2030) and Microsoft (100/100/0 by 2030), see §12 References; other large operators (including Amazon, Meta, and Oracle) have published clean-energy procurement targets, generally on an annual-matching basis. Operators in this segment maintain internal auditing teams whose mandate is to verify that procurement claims reflect physical reality. The DeliveryTag provides such teams with a structured, externally verifiable proof object that can be audited without privileged market access. This reduces internal audit cost, regulatory exposure, and greenwashing risk.

Named companies are referenced solely for their published public commitments, as a description of the market segment. No commercial relationship with the DeliveryTag protocol or the Integrity Protocol Foundation is implied.

Temporal layer: EnergyTag GC
Hourly matching, registry, cancellation
Scoped to time
Spatial dimension addressed in complementary work
DeliveryTag Proof
PTDF + Sensor + PQC + Hedera
Nodal ✓ Physical ✓ Temporal ✓ Immutable ✓
Hyperscaler Outcomes
✓ Hourly + spatial coverage
✓ ISAE 3000 audit-ready evidence
✓ CSRD / SB 253 / RED III alignment
✓ No privileged access needed

Adding the spatial layer to the EnergyTag GC turns hourly clean-energy claims into evidence packs an auditor can independently cross-check against grid-physics inputs.

6. The Integrity Protocol Foundation

The Integrity Protocol Foundation is a Swiss Stiftung in formation, Canton of Zug. It does not yet legally exist; completing the formation is gating dependency D5 in Section 10 and a prerequisite for first issuance. Once formed, it is intended to operate as an open, non-profit standards body stewarding the DeliveryTag specification. Its mandate is to maintain alignment with EnergyTag on all temporal principles, develop the nodal-extension principles in public working groups, and coordinate pilot deployments with TSOs, hyperscalers, flex-pool operators, and accredited verification bodies. The intended entity structure, fee flows, and governance disclosures are set out in Section 6.4.

Working Groups

Mirroring the EnergyTag WG structure

WG1
Definitions & Principles

Maintains the DeliveryTag specification, coordinates with EnergyTag Secretariat on inherited principles, adjudicates nodal-extension disputes.

WG2
Dispatch Verification

Develops reference methodology for TSO dispatch log ingestion, PTDF matrix validation, and counterfactual LME calculation.

WG3
Registry Interoperability

Ensures DeliveryTag attribute sets are writable to existing EnergyTag-compatible registries (M-RETS, Energinet, GO hubs) without requiring schema forks.

WG4
Market Adoption

Designed for interoperability with market participants and GC infrastructure providers, publishes reference implementations, and maintains the public list of issuing and verification bodies.

Trader Neutrality & Independence

Why a neutral Foundation, not a trader-owned system.

For the DeliveryTag to function as a trusted market standard, the protocol must be operated by an entity structurally independent from energy trading participants. An energy trader that issues, verifies, and trades certificates faces inherent conflicts of interest, the same conflict that undermined confidence in credit-rating agencies before the 2008 financial crisis. The Integrity Protocol Foundation is being chartered as a non-profit (Swiss Stiftung in formation, Canton of Zug) with governance rules designed to prevent any single commercial participant from controlling issuance methodology, verification criteria, or registry access. Dispatch Verification Bodies are selected through an accreditation process managed by WG2, not appointed by market participants.

6.1 Market Defendability: Why Traders Cannot Replicate DeliveryTag

The DeliveryTag system is designed to be structurally unreplicable by energy trading participants. Three independent barriers protect the protocol:

Barrier 1: Conflict of Interest

An energy trader cannot simultaneously be the seller of electrons and the certifier of their delivery. A trader-issued certificate is a self-attestation, not an independent verification. This is the same structural conflict that undermined credit-rating agencies before the 2008 financial crisis: the entity being paid to rate the product has an economic incentive to inflate the rating. Only a structurally independent foundation can issue a DeliveryTag with market credibility; that is the role the Integrity Protocol Foundation is being formed to fill.

Barrier 2: Hardware Installation at Competitor Sites

To replicate the seven-layer forensic sensor stack, a trader would need to install Physical Integrity Nodes (PINs) at their competitors’ facilities. The flex pool in a DeliveryTag deployment includes refineries, steel mills, and factories operated by entities with no commercial relationship to the certifying trader. No industrial operator will grant a rival energy trader physical access to install sealed sensor hardware on their busbar. The PIN network is, by design, only deployable by a neutral foundation.

Barrier 3: Filed IP (Provisional Applications)

Two USPTO provisional applications establish priority over the core methodology:

DSEE (USPTO provisional application 64/023,803): The Demand-Side Emissions Equivalence computation, converting verified load reduction into equivalent renewable capacity using locational marginal emissions.
T-NAC (USPTO provisional application 64/023,364): The Mode B flex-load curtailment swap mechanism (§2), freeing PTDF-weighted corridor capacity through coordinated flex-pool curtailment.

Provisional applications are unexamined and confer no enforceable rights; they establish priority dates ahead of planned non-provisional conversion. If claims are granted, they will be offered under a FRAND (Fair, Reasonable, and Non-Discriminatory) licensing commitment to accredited registry operators and verification bodies. Filed IP is therefore a prospective barrier, contingent on grant; the operative barriers today are the conflict-of-interest constraint and the physical hardware network described in Barriers 1 and 2.

6.2 Protocol Revenue Model

In one metaphor, the DeliveryTag economic model is “electron refining”: in plain terms, the protocol charges a fee for transforming a raw commodity (unattested energy) into an assurance-ready product (a DeliveryTag-verified Granular Certificate). The protocol creates value for participants through distinct mechanisms in US and EU markets.

US Model: Buyer-Premium Driven

US: FROM CONGESTION-CURTAILED ENERGY TO CERTIFIED 24/7 CFE
Stranded Energy
Congestion-curtailed MWh
with no delivery proof
DeliveryTag Certification
PTDF + 7-layer validation
+ PQC + Hedera
Certified 24/7 CFE
Physics-backed certificate
with buyer premium

The existence and size of a buyer premium for physical certainty — proof of delivery, reduced greenwashing risk, assurance-ready evidence — is the central commercial hypothesis of the US model. It has not yet been validated by transacted volume; testing it through pilot price discovery is a primary objective of the Q4 2026 pilots.

EU Model: Three-Layer Revenue Stack

The EU protocol revenue model comprises three layers that create value for different market participants:

EU: THREE-LAYER PROTOCOL REVENUE STACK
Layer 1
TSO Avoided
Redispatch
Flex curtailment replaces gas peaker activation
+
Layer 2
EU NWA / PCI
Subsidy
Non-Wire Alternative subsidy for virtual transmission
+
Layer 3
24/7 CFE
Buyer Premium
Hourly matching certificate with physical proof

The EU model’s primary revenue source is the TSO avoided redispatch cost. When a gas peaker is activated for redispatch, the TSO bears the full activation cost. DeliveryTag offers an alternative: certified flex-pool curtailment that relieves the same congestion at lower cost, saving the TSO the difference per avoided peaker start. German congestion-management costs illustrate the scale of the underlying cost pool: approximately €4.2B in 2022 (the energy-crisis peak, up from €2.3B in 2021) and roughly €3.1B in 2023 (Bundesnetzagentur monitoring reports / SMARD). Two honesty notes apply. First, this is the TSO’s total cost, not the protocol’s capturable revenue: DeliveryTag would earn only a share of the spread between certified curtailment cost and the avoided activation cost, a fraction of the headline figure. Second, capturing any of it requires TSO procurement of flex-based congestion relief, which is jurisdiction-specific and not yet contracted; sizing that capturable fraction is an explicit objective of the EU pilot.

6.3 Cancellation Tier Economics

The three cancellation tiers (Principle 35) carry different CapEx and OpEx profiles. The figures below are order-of-magnitude production-scale estimates intended for capacity planning; exact prices vary by region, hardware vendor, and assurance-engagement scope.

TIER HARDWARE CAPEX (PER SITE) ANNUAL OPEX (PER SITE) ASSURANCE COST
Tier 1 (Full Seven-Layer) S-PIN ~$80k–$120k; D-PIN ~$15k–$25k depending on sensor configuration (Tri-Sensor baseline; optional Thermal layer at the upper end of the range) Guardian operation + SAR subscription (S-PIN) + Hedera fees: ~$5k–$15k ISAE 3000 reasonable-assurance engagement: scope-dependent, typically $50k–$250k annually per reporter
Tier 2 (Attested Meter) Existing utility revenue meter (no additional CapEx) Guardian operation + Hedera fees: ~$2k–$5k Accredited Signer attestation over meter: typically $10k–$40k annually per site
Tier 3 (Registry-only) None Guardian operation + Hedera fees only: <$1k Not audit-grade; not applicable for Scope 2 / 24/7 CFE claims

Illustrative protocol-fee scenario. All fee levels in this section are illustrative scenario parameters, not protocol constants or observed prices. No DeliveryTag has yet been sold; actual fee levels will be set by pilot price discovery (Q4 2026 onward). The scenario assumes a Mode A fee of $1–$8/MWh, a Mode B fee of ~$150/MWh, and an 80/20 uncongested/congested hour split — itself a scenario assumption, since congestion incidence varies widely by corridor. Under those assumptions the issuance-side blended fee is $31–$36/MWh (low case: $1×0.8 + $150×0.2 = $30.80; high case: $8×0.8 + $150×0.2 = $36.40), and it is sensitive to the congestion share: at a 95/5 split the same fee assumptions blend to roughly $8–$15/MWh. Who pays this fee and which entity receives it are set out in Section 6.4.

These levels are a willingness-to-pay hypothesis, not an observed market price. Section 3 records that annual-resolution voluntary REC prices collapsed to €2–5/MWh once the market judged the instrument’s credibility to be limited; a $31–$36/MWh blended fee is roughly an order of magnitude above that level, and the ~$150/MWh Mode B fee is one to two orders of magnitude above it. The argument for why the hypothesis may hold is scarcity and evidentiary value: deliverable node-hour volume is capped by physics (Principle 36), Mode B relief carries a real, oracle-verified curtailment cost that must be compensated, and the certificate is designed to survive assurance scrutiny that annual RECs could not. On the Mode A side, congestion status in uncongested hours is largely observable from public data; the Mode A fee therefore prices the assurance-ready evidence chain (hardware attestation, signer certification, anchored provenance), not congestion detection itself. Whether buyers will pay these levels is precisely what the pilots must establish; the fee schedule will be restated from transacted pilot prices in a subsequent revision.

Tier 1 hardware and assurance costs are cancellation-side and amortise across the reporter’s annual volume. For a hyperscaler data-center campus consuming 500 GWh/year under Tier 1 with a single D-PIN: total additional cancellation cost is on the order of $0.15–$0.60/MWh, roughly two orders of magnitude below the illustrative issuance fee and within the range of existing sustainability-assurance budgets. For smaller reporters below the GHG Protocol Scope 2 exemption threshold, Tier 2 is sufficient and Tier 1 hardware is not required.

Comparison with Battery Storage for 24/7 CFE

DIMENSION BATTERY (BESS) DELIVERYTAG™
Mechanism Time-shifts clean energy to fill gaps Verifies physical delivery + frees corridor capacity via flex curtailment
Deployment timeline 3–5 years ~6 months
CFE score achievable ~92% 97%+ (modeled; hourly simulation, methodology available on request)
Additionality proof None (time-shift only) Physical avoidance (seven-layer validated)
Audit trail Meter data PTDF + sensor + PQC + blockchain
Complementary use Standalone or paired with renewables Can be combined with BESS for hybrid architectures
Technical differentiation. Battery storage addresses the temporal gap by time-shifting clean energy, while DeliveryTag addresses the spatial gap by providing auditable deliverability evidence at the buyer’s node. The two approaches are complementary: a BESS fills generation shortfalls, and DeliveryTag supports the claim that the energy, whether direct or time-shifted, is deliverable to the consumption point under binding network-flow constraints.

Alignment with the Granular Certificate Ecosystem

The granular-certificate ecosystem (industry bodies, exchanges, and registries that collectively support hourly EAC trading) is building market infrastructure for time- and location-based carbon-free energy trading. DeliveryTag is designed to be natively compatible with the EnergyTag framework: every DeliveryTag certificate is a valid Granular Certificate with an additional nodal attribution and evidentiary attestation layer on top. As the ecosystem scales location-based CFE procurement, DeliveryTag adds an assurance-ready evidence layer that complements existing GC trading.

6.4 Entity Structure & Governance

A neutral non-profit standard cannot also be a fee-earning commercial business without recreating the conflict of interest this protocol exists to eliminate. The intended structure therefore separates two entities with distinct roles. Neither entity is fully constituted as of this publication; the descriptions below are the intended design, subject to formation counsel and final governing documents.

Integrity Protocol Foundation
Swiss Stiftung in formation, Canton of Zug · non-profit steward

Intended role: maintain the DeliveryTag specification and the 38 Principles, run the working groups (WG1–WG4), manage Dispatch Verification Body accreditation, and operate the public pilot index (Principle 29). As a Stiftung it will have no shareholders and cannot issue equity. It is not an investment vehicle. Formation is gating dependency D5 (Section 10); no DeliveryTag can be issued before it legally exists.

Commercial Operating Entity
Intended for-profit company · structure not yet finalized

Intended role: the capital-intensive and service functions — PIN hardware manufacture, deployment, and maintenance; oracle and data operations (dispatch-log ingestion, PTDF validation tooling, the Opportunity Cost Oracle); and issuance-services infrastructure. Its jurisdiction, name, and capital structure have not been finalized as of this publication. Any equity investment in the DeliveryTag effort would be in this operating entity, not the Foundation.

Who Pays, Who Receives

Consistent with the revenue descriptions in Sections 6.2 and 6.3, the intended fee flows are as follows. The issuance-side protocol fee (Mode A and Mode B; illustrative levels in Section 6.3) is charged per certified MWh at issuance and is expected to be borne economically by the certificate buyer, embedded in the price of the DT-verified GC on secondary markets (Section 4.6.2). In the EU model, part of the value pool is instead expected to come from TSO procurement of certified flex-based congestion relief (Section 6.2, Layer 1), where such procurement exists; it is not yet contracted anywhere. Out of the Mode B fee, the oracle-verified curtailment cost is intended to compensate the flex-load operator, with the balance covering verification operations. Cancellation-side costs (Tier hardware, Guardian operation, assurance; Section 6.3) are paid by the reporter, with assurance fees paid directly to the Accredited Signer to preserve signer independence (Section 4.10b).

Under the intended structure, fees for issuance services are received by the operating entity; the Foundation does not sell certificates and takes no per-MWh trading position. How the Foundation’s standards-maintenance work is funded (for example, accreditation fees, membership fees, or a fixed levy on issuance services) has not been finalized and will be settled in the formation documents, under the constraint that the Foundation’s neutrality must not depend on issuance volume.

Governance Disclosures

This document is a technical specification and names no individuals. Founder and advisor identities and credentials, the Foundation’s board composition, formation counsel and the formation date, and the operating entity’s capital plan (raise amount, use of funds, runway) are not disclosed here; they are shared with pilot counterparties and prospective investors through direct engagement (deliverytag.org/contact) and will be published as the formation completes. Nothing in this whitepaper constitutes an offer of securities.

Part D
D

Rules & Compliance

The 38 Principles (18 inherited from EnergyTag, 20 nodal extensions), and the clause-by-clause compatibility with the EnergyTag Granular Certificate framework.

Sections 7 8

7. The DeliveryTag Guidelines

7.1 Definitions

The following definitions supplement the EnergyTag definitions (which apply in full unless explicitly overridden).

Consumption Point
As defined by EnergyTag. A separately measured grid access point at which electricity is consumed.
Node of Attribution
A specific transmission busbar (typically 110 kV, 220 kV, 400 kV or higher) to which a Consumption Point is electrically connected, identified by an ISO-standard substation code (e.g. ENTSO-E EIC, NERC CA ID).
PTDF (Power Transfer Distribution Factor)
A signed, dimensionless sensitivity coefficient, typically in the range −1 to +1, defined per source–sink transfer and per monitored transmission element: the change in MW flow on a specific line or flowgate caused by a 1 MW transfer from the source node to the sink node, computed from a linearised (DC) power-flow model of the network. Negative values indicate counterflow (the transfer reduces loading on that element). A PTDF describes how a transfer distributes across parallel network paths under Kirchhoff’s laws; it is not a delivery fraction. For a defined source–sink transfer, the full transferred MW arrives at the sink (net of losses); the PTDF only determines how much of that transfer loads each individual line. DeliveryTag uses PTDFs as a corridor-headroom verification: the attributed transfer must not load any binding monitored element beyond its available capacity, and attributed MWh is capped at the minimum of (i) the buyer’s metered consumption, (ii) the named portfolio’s metered injection, and (iii) the transfer capability implied by the binding element’s headroom divided by the transfer’s PTDF on that element. PTDF matrices are recomputed as grid topology changes.
Causal Dispatch Proof
The structured data object (defined in §4.8) that binds a DeliveryTag to a TSO merit-order log entry.
Dispatch Verification Body
An independent entity responsible for validating the Causal Dispatch Proof.
Flexible Load
A grid-connected consumption asset capable of modulating demand in response to a dispatch signal within the certificate’s time resolution, and whose curtailment is sub-metered at revenue-grade resolution.
Locational Marginal Emissions (LME)
The tons of CO₂-equivalent displaced (or emitted) per additional MWh of generation or curtailment at a specific node, derived from the TSO merit-order log.
Counterfactual Generator
The marginal generator that would have cleared at the Node of Attribution during the certificate’s time interval in the absence of the DT-attested flex curtailment or clean injection.
Virtual Transmission
The use of flexible load curtailment, sub-metered and PTDF-weighted, to free corridor headroom, comparable in effect, for the attributed transfer, to incremental transmission capacity. It does not raise the corridor’s physical limit; it reallocates constrained capacity.

7.2 Market Diagram

The DeliveryTag market diagram extends the EnergyTag market diagram with a Dispatch Verification Body node and a PTDF data feed from the TSO.

Production Facility
Measurement Body
(EnergyTag)
TSO Dispatch
Log + PTDF Matrix
GC Issuer
(EnergyTag)
Flex Pool
SCADA Telemetry
↓ ↓ ↓
Dispatch Verification Body
DeliveryTag Extension
EnergyTag Registry
+ DeliveryTag Attributes
Consumption Point
Cancel DeliveryTag here

Figure: DeliveryTag Market Diagram, extending the EnergyTag architecture with a Dispatch Verification Body and nodal attribution.

7.3 Principles

The DeliveryTag principles are organized in two groups: Inherited (from EnergyTag, applied without modification) and Nodal Extensions (new).

7.3.1 Inherited Principles (EnergyTag GC Scheme Standard V2, 2024, applied in full)

1 Avoidance of Double Counting, A DeliveryTag cannot be attached to a GC that has already been cancelled.
2 Cancellation and Retirement, DeliveryTags shall be cancelled in a registry only against measured energy consumption at a Consumption Point.
3 Corrections, Corrections to issued DeliveryTags follow the same procedure as GC corrections.
4 Data Quality, DeliveryTag data inputs shall meet or exceed the EnergyTag data quality requirements.
5 Emissions, Grid-average emissions may be stated alongside LME; LME is reported additively, not as a replacement.
6 Energy Storage, Storage is treated as a dual-role Consumption Point + Production Facility, per EnergyTag.
7 Immutability, Once issued, DeliveryTag attribute sets are immutable in the registry.
8 Issuance, DeliveryTags are issued in accordance with EnergyTag issuance principles plus the DT-specific Causal Dispatch Proof requirement (§4.8).
9 Linking GCs with EACs, DeliveryTags may be linked to underlying GCs and to legacy RECs/GOs for traceability; linking does not create double-counting.
10 Period of Validity, DeliveryTags inherit the period of validity of their parent GC (typically ≤ 12 months from issuance).
11 Purpose, DeliveryTags are issued for the purpose of attesting nodal delivery; they shall not be used for any other purpose without explicit disclosure.
12 Quantity Resolution, DeliveryTag quantities are reported in kWh or MWh, aligned with the underlying GC resolution.
13 Reference to Another GC, A DeliveryTag references its parent GC by registry-scoped unique identifier.
14 Standardization, DeliveryTag schemas are maintained by the Integrity Protocol Foundation WG1.
15 Time Resolution, DeliveryTag time resolution shall be ≤ 1 hour and shall match or exceed the TSO settlement period.
16 Time Zones, UTC, per EnergyTag.
17 Transferability, DeliveryTags are transferable as extension attributes on their parent GCs.
18 Verifiability, DeliveryTags shall be independently verifiable by the Dispatch Verification Body.

7.3.2 Nodal Extension Principles (New)

19. Nodal Binding. Every DeliveryTag shall specify a single Node of Attribution, identified by an ISO-standard substation code. The DeliveryTag is cancelled only against Consumption Points electrically connected to that node.
20. Causal Dispatch Proof Requirement. Every DeliveryTag shall be issued with a Causal Dispatch Proof object, hashed and anchored in the registry. The proof shall reconcile the TSO merit-order log, the PTDF matrix row, the flex-curtailment telemetry, and the counterfactual LME calculation.
21. PTDF Attestation. The PTDF coefficients used in the Causal Dispatch Proof shall be computed by the Dispatch Verification Body from the network model in force for the certificate’s time interval, obtained under market-participant, CEII, or bilateral TSO data-access agreements (no TSO or RTO publishes full nodal PTDF matrices). Where published flow-based parameters cover the relevant network elements (e.g. the JAO Publication Tool’s zonal PTDFs and margins for Core CCR, or RTO binding-constraint and shadow-price feeds), the Dispatch Verification Body shall cross-validate its computed coefficients against those published values and shall attest, at issuance, the model version, the data provenance, and the validation result.
22. Counterfactual Disclosure. The DeliveryTag shall identify the counterfactual generator, the marginal unit that would have cleared the Node of Attribution during the certificate’s time interval in the absence of the attested flex curtailment or clean injection. The counterfactual shall be derived from the TSO merit-order log.
23. Flex Curtailment Auditability. When a DeliveryTag is issued against flex curtailment, the curtailed load shall be sub-metered at revenue-grade resolution (IEC 62053-22 Class 0.2S or equivalent) and its SCADA telemetry shall be retained by the Dispatch Verification Body for the DeliveryTag’s period of validity plus 7 years.
24. Nodal Exclusivity. A DeliveryTag is non-partitionable. Two offtakers on the same Node of Attribution cannot cancel two separate DeliveryTags against the same underlying dispatch event; the DeliveryTag issuance system shall enforce unique attribution per curtailment event.
25. Topology Transparency. The Node of Attribution’s topology, including the busbar share of the offtaker (offtaker load as a fraction of total load on the bus), shall be disclosed at issuance and updated annually.
26. Congestion Disclosure. The DeliveryTag shall disclose the corridor or interface that was congested during the certificate’s time interval and the marginal congestion price, as identified in published congestion data (JAO shadow prices per critical network element in Core CCR; RTO binding-constraint and shadow-price feeds; national redispatch publications).
27. Storage Nodal Binding. When storage is involved as a dual-role asset, the DeliveryTag shall specify the Node of Attribution for both the charge event (as Consumption Point) and the discharge event (as Production Facility). The two nodes may differ only if the storage asset is virtual-aggregated across multiple sites.
28. No Re-Scoping on Transfer. The Node of Attribution is immutable after issuance. Transfer of a DeliveryTag between accounts does not alter the node binding.
29. Pilot Transparency. During the pilot phase (through 2027), all issued DeliveryTags shall be registered in a public index maintained by the Integrity Protocol Foundation, to enable market-wide auditability and methodology improvement.
30. Settlement-Lag Accommodation. The DeliveryTag framework supports a two-state issuance lifecycle (Provisional DT-P and Final DT-F, per §4.3.1) to accommodate jurisdictional settlement timing. In EU markets, where ENTSO-E publishes generation and flow data at approximately D+1 and TSO dispatch data is delivered under data-access agreements at D+1 to D+7, DT-F may be minted directly without a DT-P phase. In US RTO/ISO markets that rely on third-party Locational Marginal Emissions (accredited third-party providers) whose methodology is bounded by RTO final settlement at T+30 to T+45 days, DT-P shall be issued at D+1 to D+7 for operational use and automatically promoted to DT-F upon LME attestation. The DT-P → DT-F promotion window shall not exceed 60 days; a DT-P not promoted within this window is automatically voided.
31. Emissions Methodology Disclosure. Every DeliveryTag shall disclose: (i) the emissions data provider or methodology used (accredited third-party LME provider for US markets, counterfactual generator identification for EU markets), (ii) the settlement vintage of the underlying dispatch data, (iii) the nodal granularity of the emissions product, and (iv) whether the value is an ex-ante estimate, a provisional settlement value, or a final settlement-grade value. In US jurisdictions where third-party LME providers (accredited third-party providers) use proprietary methodologies, the DeliveryTag discloses the provider identity and accreditation status rather than the computation formula itself. Buyers rely on the provider’s accreditation by the Dispatch Verification Body and their market reputation. In EU jurisdictions, emissions impact is derived from the counterfactual generator’s known emissions factor; the identification draws on public data (ENTSO-E per-unit generation, published redispatch measures) and on TSO dispatch records obtained under data-access agreements. Reproducibility from public data alone is achievable to the extent the counterfactual is observable in published feeds; where confidential TSO data is load-bearing, the DeliveryTag discloses the data source and access regime rather than the underlying records.
32. Economic Additionality (Mode B only). This principle applies exclusively to Mode B certificates, where flex-load curtailment is required to free congested corridor capacity. It does not apply to Mode A (Nodal Attribution) certificates, where the corridor is uncongested and renewable generation flows through on PTDF verification alone. Every flex-load curtailment attested in a Mode B DeliveryTag shall be accompanied by an Opportunity Cost Proof demonstrating that the load reduction represented a genuine economic sacrifice for the facility operator, not a market exit, a scheduled maintenance event, or a demand trough. The proof shall include: (i) the real-time market price or PPA strike price at the moment of curtailment, (ii) the facility’s production schedule showing that output was planned during the curtailed interval, and (iii) the foregone revenue or margin calculated from (i) and (ii). A curtailment that coincides with a period where the facility would have been idle regardless (e.g. negative spot prices below the operator’s marginal cost) does not qualify for DeliveryTag issuance under Mode B. This principle ensures that every MW of corridor relief credited in a DeliveryTag certificate was purchased at a real cost, not harvested from naturally occurring demand fluctuations.
33. Accredited Signer (ISAE 3000). Every DeliveryTag shall carry the countersignature of an Accredited Signer, defined as a party qualified to issue a reasonable-assurance opinion under International Standard on Assurance Engagements 3000 (ISAE 3000) or equivalent. Accredited Signers include major international assurance practices qualified under ISAE 3000 and certification bodies accredited under ISO 14065 or the IAF Multilateral Agreement; no specific signer has been engaged as of this publication, and engagements will be disclosed once in place. The Accredited Signer operates independently of the Integrity Protocol Foundation, the facility operator, the buyer, and the Dispatch Verification Body. Its countersignature is a prerequisite for DeliveryTag issuance under Tier 1 and Tier 2 cancellation paths.
34. Dual-PIN Physical Root of Trust. DeliveryTag employs a dual-PIN architecture: a Supply-side PIN (S-PIN) at the generation or flex-load facility, and a Demand-side PIN (D-PIN) at the buyer’s consumption point. Each PIN is a tamper-evident hardware unit that generates and stores a CRYSTALS-Dilithium private key (NIST FIPS 204) inside a secure element; breaking the tamper seal zeroises the key. The S-PIN carries the full seven-layer validation stack (§4.9); the D-PIN carries a Tri-Sensor stack (Electrical, Magnetic, Frequency) with optional Thermal. Together the two PINs close the forensic chain end-to-end, from generation event to cancellation, without trusted third parties in the measurement path. See §4.11.
35. Cancellation Tiers. The specification defines three cancellation tiers, differentiated by the cryptographic strength of the demand-side proof. Tier 1 (Full Seven-Layer) requires a registered D-PIN at the buyer’s consumption point; cancellation is hardware-signed end-to-end and supports ISAE 3000 reasonable assurance. Tier 2 (Attested Meter) accepts a revenue-grade utility meter reading with Accredited Signer attestation of the meter’s node binding; supports ISAE 3000 limited assurance. Tier 3 (Registry-only) accepts a TSO interconnection agreement plus registry-level node binding; supports operational claims only and is not sufficient for Scope 2 or 24/7 CFE claims under the revised GHG Protocol. Tier 1 is the default for hyperscaler 24/7 CFE, regulated 45V hydrogen, and externally assured corporate Scope 2 reporting.
36. Total Node Issuance Cap. The Guardian policy shall reject any DeliveryTag issuance that would push the total issued volume at a given (Node of Attribution, hour) above the node-hour deliverability cap: the minimum of metered injection by the named portfolio, aggregate metered consumption at the node, and the PTDF-implied transfer capability of the binding corridor (§7.1). The transfer capability is not a TSO-published product; it is computed by the Dispatch Verification Body from its PTDF model (Principle 21) together with the corridor loading observable in published flow and constraint data (JAO flow-based margins for Core CCR; RTO binding-constraint feeds), and the computation inputs are hashed into the Causal Dispatch Proof so the cap is independently re-derivable. Scarcity at the node is enforced at the source, not post hoc. See §4.5.1.
37. Claim-Based Allocation. At nodes serving multiple buyers, per-buyer attribution is resolved via claim-based allocation under two cryptographic constraints: (i) total DeliveryTags issued at (node, hour) shall not exceed the node-hour deliverability cap (Principle 36), and (ii) each buyer’s retired volume shall not exceed its D-PIN-attested consumption at the node-hour under Tier 1, or its Accredited-Signer-attested meter value under Tier 2. Scarce node-hour DeliveryTags are priced on compatible EAC secondary markets. The protocol enforces the constraints and lets the market resolve the distribution, without disclosure of buyer-level consumption data between competing offtakers.
38. Cryptographic Counterbalance Enforcement. The prohibition on direct counterbalancing reverse transactions (WRI GHG Protocol Scope 2 revision, Alternate Methodology 2) shall be enforced by the Guardian policy at the cryptographic layer. A second cancellation against the same (corridor, hour, MWh) triple or against the same D-PIN for the same consumption hour is rejected at the policy level and cannot be recorded on the ledger. This enforcement is ex ante rather than post hoc, and does not depend on human-audited registry bookkeeping.
8. Compliance with
EnergyTag

A DeliveryTag is, by construction, an EnergyTag Granular Certificate with additional attributes. The following table maps the DeliveryTag components to the EnergyTag principles catalogue.

ENERGYTAG PRINCIPLE DELIVERYTAG INHERITANCE DELIVERYTAG EXTENSION
Time Resolution ≤ 1 hInherited in fullDeliveryTag matches TSO settlement (15 min where available)
Cancellation at Consumption PointInherited in fullRestricted to nodally connected Consumption Points
Measurement Body independenceInherited in fullDispatch Verification Body added
Registry immutabilityInherited in fullDeliveryTag attributes join the immutable record
UTC time zonesInherited in full-
Storage dual-roleInherited in fullPlus storage nodal binding (Principle 27)
VerifiabilityInherited in fullPlus PTDF + dispatch log verification
Avoidance of double countingInherited in fullPlus nodal exclusivity (Principle 24)
Data qualityInherited in fullPlus flex curtailment sub-metering (Principle 23)
ImmutabilityInherited in fullPlus no re-scoping on transfer (Principle 28)
Period of validityInherited in fullDeliveryTag validity ≤ parent GC validity
IssuanceInherited in fullPlus Causal Dispatch Proof requirement
TransferabilityInherited in fullPlus nodal binding preservation
EmissionsInherited in fullLME reported additively with methodology disclosure
DomainExtendedDomain = Node of Attribution, not market/country
Issuance timingExtendedTwo-state lifecycle (DT-P/DT-F) for EU D+1 and US D+30–45
Verification authorityExtendedAccredited Signer under ISAE 3000 replaces legacy VVB framing; major assurance practices or ISO 14065 bodies (Principle 33)
Hardware root of trustNewDual-PIN: S-PIN (full seven-layer stack) at supply, D-PIN (Tri-Sensor, optional Thermal) at demand; CRYSTALS-Dilithium PQC signing at source (Principle 34)
Demand-side measurementNewCancellation Tier 1 requires D-PIN at buyer POI; Tier 2 attested utility meter; Tier 3 registry-only (Principle 35)
Issuance scarcityNewTotal-node issuance cap: Guardian policy enforces total issued at (node, hour) ≤ the node-hour deliverability cap (Principle 36)
Multi-buyer attributionNewClaim-based allocation under two cryptographic constraints; market resolves distribution without exposing competing consumption data (Principle 37)
Counterbalance enforcementStrengthenedEx ante cryptographic rejection at Guardian policy layer, not post-hoc audit (Principle 38); satisfies WRI Alternate Methodology 2 anti-gaming clause
8.1 Live Regulatory
Tracking

DeliveryTag is a living protocol positioned against a rapidly moving regulatory surface. The principles in Section 7 and the compliance table in Section 8 represent a snapshot at the time of publication. The authoritative, continuously updated view of the regulatory signals DeliveryTag tracks and responds to is maintained publicly at deliverytag.org/regulatory-watch. This section summarises the active signals at v1.3 publication.

Regulatory Signals, Q2 2026

STATUS KEY: Binding · Adopted (non-binding) · In consultation · Directional · Lost / expected to return. No mapping in this table implies formal acceptance of DeliveryTag by the issuing body.

Instrument Status · Date DeliveryTag Mapping
EC Recommendation on PPAs
C(2026) 2676
Adopted (non-binding)
22 April 2026
Recommends — as a non-binding instrument — GO issuance at 15-min market time unit + bidding zone + storage discharge + cross-border, referencing EN 16325:2025. Point 10(c) bidding-zone criterion maps directly to DeliveryTag's PTDF deliverability layer.
GHG Protocol Scope 2 Revision 2nd consultation
Final late 2027
Introduces temporal + deliverability pillars. DeliveryTag satisfies Alternate Methodology 2 anti-gaming clause via ex-ante cryptographic counterbalance (Principle 38). Comment submitted Jan 2026.
IRA §45V Clean Hydrogen
IRS Final Rule, Jan 2025
Live
Hourly from 2028
Three-pillar rule (incrementality, temporal matching, deliverability). DeliveryTag's PTDF corridor attribution is a candidate reference approach for the deliverability pillar under PJM / ERCOT / CAISO; acceptance is evaluated case by case by the auditor of record.
EU CBAM
Regulation 2023/956
Binding phase
1 January 2026
APAC exporters (~33% of EU imports) need defensible clean-electricity provenance for embedded-emissions calculation. DeliveryTag provides a verifiable, auditor-checkable clean-electricity provenance chain for the embedded-emissions calculation.
Colorado SB26-102
Hourly matching for data centers
Lost — postponed indefinitely
11 May 2026
First US state-level hourly-matching bill targeting data centers; postponed indefinitely by the Senate Transportation & Energy Committee (9–0, 11 May 2026). Tracked as a directional signal only — similar measures are expected in future sessions. EnergyTag US Policy testified in the hearings: "100% annually matched via solar can equate to 40% hourly."
EU RED III Article 19 In force
Transposition 2025+
Renewable Fuels of Non-Biological Origin (RFNBO) criteria for hydrogen electrolysers: additionality, temporal correlation, geographical correlation. DeliveryTag satisfies all three; Section 5.4.
EU CSRD (post-Omnibus) + IFRS S2 + California SB 253/261 Staged 2026-2029 Mandatory assured Scope 2 disclosure for CSRD-scoped entities — scope reduced ~90% by the Omnibus I directive (adopted 24 February 2026) to companies >1,000 employees and >€450M turnover — plus global IFRS S2 adopters and companies covered by California SB 253 (first Scope 1–2 reports due 2026; SB 261 enforcement stayed pending Ninth Circuit ruling). The federal SEC climate rule was stayed in 2024 and the SEC ended its defense in March 2025; California is now the live US disclosure driver. Accredited Signer framework (Principle 33) routes the claim to ISAE 3000 Accredited Signer countersignature.

How the Protocol Responds

Three commitments govern the protocol's regulatory posture:

  1. Standards-first, not standards-adjacent. DeliveryTag inherits in full from EnergyTag principles (Section 8), maps to EN 16325:2025, and extends rather than replaces. Regulatory acceptance is a product of fidelity, not branding.
  2. Active consultation participation. Formal comments submitted to GHG Protocol Scope 2 (January 2026), state-level hourly-matching initiatives tracked (Colorado SB26-102, postponed indefinitely May 2026), ongoing engagement with CEN-CLC/JTC 14 (WG 5) on EN 16325:2025. Working Groups disclosed in Section 6.
  3. Open regulatory watch. The live tracker at deliverytag.org/regulatory-watch publishes every signal, its status, and its mapping onto protocol principles, accessible to accredited signers, regulators, and standards bodies without credentials.
Reference Live regulatory watch: deliverytag.org/regulatory-watch.html. Updated continuously. The version of record for regulatory status and protocol-mapping interpretation.
Part E
E

Deployment

Two continental reference architectures, EU zonal and US nodal, plus the pilot acceptance criteria and milestones that translate the specification into operational certificates.

Sections 9 10
9.1 EU Architecture: Zonal Market
500 MW DC in Southern Europe • 800 MW wind + 400 MW solar portfolio • National TSO
Nodal Precision in a Zonal Market. Southern European markets operate within the EU’s zonal framework. Under zonal rules, all generators and consumers within a bidding zone are treated as if they share a single price node, ignoring internal transmission constraints. In reality, 400 kV corridors connecting renewable-rich regions to load centers are frequently congested. DeliveryTag brings nodal precision (physical, busbar-level) to a zonal market (administrative, country-level), using national TSO dispatch data and ENTSO-E Transparency Platform APIs as the authoritative data sources.
Data Sources for EU Deployment

The EU architecture integrates three classes of data, distinguished by access regime:

  • Public, no agreement required: ENTSO-E Transparency Platform (Regulation (EU) 543/2013): per-unit actual generation, load, scheduled and physical cross-border flows, outages; JAO Publication Tool: daily day-ahead flow-based parameters (zonal PTDFs, remaining available margins, shadow prices per critical network element) for the Core capacity-calculation region; national redispatch publications where available (in Germany, plant-level redispatch measures on netztransparenz.de, updated daily).
  • Registered access: ENTSO-E Transparency Platform API (free registration); power-exchange and market-participant data feeds under standard market terms.
  • Bilateral agreement required: network models sufficient for nodal PTDF computation, intra-zonal corridor loading, and unit-level dispatch records held by national TSOs. These are confidential in the EU; the Dispatch Verification Body obtains them under TSO data-access agreements (gating dependency D3, §10) and cross-validates its nodal PTDF computation against the published JAO zonal factors.

Unlike US deployments where third-party LME is mandatory, the EU architecture derives emissions impact from the counterfactual generator’s known emissions factor. The counterfactual unit is identified from ENTSO-E per-unit generation data, published redispatch records, and TSO dispatch data obtained under the agreements above; where only public data is available, the identification is disclosed as inference from public data rather than as a TSO-confirmed dispatch record. This approach is described in the DSEE provisional application (USPTO 64/023,803). Counterfactual: Regional CCGT.

Data Sources by Market: Dataset, Cadence, Access Regime

The protocol’s verifiability rests on the following datasets. None of them is a nodal PTDF matrix; nodal PTDFs are computed by the Dispatch Verification Body (Principle 21) and validated against the published values below.

MarketDatasetPublisherCadence / lagAccess regimeRole in protocol
EU (Core CCR)Actual generation per unit, load, physical cross-border flowsENTSO-E Transparency Platform (Reg. (EU) 543/2013)Hourly / sub-hourly; ~D+1Public (free API registration)Counterfactual identification; flow reconciliation
Day-ahead flow-based parameters: zonal PTDFs, RAM, shadow prices per CNECJAO Publication ToolDaily, day-aheadPublicCross-validation of DVB PTDF model; congestion-state input
Redispatch measures (plant-level, quarter-hourly)German TSOs via netztransparenz.de (equivalents vary by member state)Updated dailyPublicMode B congestion evidence; counterfactual confirmation
Network model, intra-zonal corridor loading, unit dispatch recordsNational TSOPer agreementConfidential; bilateral TSO data-access agreementNodal PTDF computation (Principle 21)
PJMReal-time 5-minute and day-ahead hourly LMPs, all busesPJM Data Miner 25-min / hourly; near-real-timePublic (account for API)Congestion-state and price input
Transmission constraints with 5-minute shadow pricesPJM Data Miner 25-min, when bindingPublicBinding-corridor identification
Network model, DFAX / shift factorsPJM (member tools); planning models CEII under FERC Form 715Per agreementMember / CEII-NDA (18 CFR § 388.113)Nodal PTDF computation and validation
ERCOTSettlement point prices, SCED binding constraints and shadow pricesERCOT market reports5-min / hourly; near-real-timePublicCongestion-state and price input
Unit-level offer curves, telemetry, dispatch (60-Day SCED Disclosure, NP3-965-ER)ERCOTDaily files at 60-day lagPublic, laggedEx-post counterfactual and dispatch verification for DT-F
Network operations model, CRR modelERCOTPer agreementMarket participant / NDANodal PTDF computation (Principle 21)

Execution status of the registrations, CEII requests, and bilateral agreements in the “per agreement” rows is gating dependency D3 (§10); none is asserted as executed in this document. Where a dataset is lagged (e.g. ERCOT 60-day disclosure), the corresponding verification step is performed at DT-F finalization, not at provisional issuance.

Physical Topology

The 400 kV substation serves the 500 MW campus as the primary load. The campus connects via a 400 kV corridor carrying the bulk of regional renewable generation to load centers. PTDF of the portfolio→campus transfer onto the binding 400 kV corridor: 0.58, meaning each MW of attributed transfer places 0.58 MW of flow on the constrained corridor (the remainder distributes across parallel paths). All figures in this architecture are illustrative; the corridor rating is taken as 1,000 MW for the worked example.

Flex Pool: Nearby Industrial Cluster

The flex pool comprises nearby industrial flex assets totalling ~300 MW:

Refinery (~120 MW) Chemical Terminal (~45 MW) Pulp Mill (~80 MW) Chemicals Plant (~35 MW) Cold Storage Facility (~20 MW)
~300 MW
Collective flex capacity
~174 MW
Max corridor-flow relief at full curtailment (300 × 0.58)
97%+
Modeled target CFE (hourly simulation, Mode A + B)
Renewables Portfolio 1.2 GW 800 MW wind + 400 MW solar Flex Pool ~300 MW curtails Corridor Bottleneck Regional 400 kV Corridor PTDF path 500 MW AI DC 24/7 CFE @ Node
24-Hour Dispatch Profile at Campus Node

Four illustrative operating configurations for the 500 MW campus. In every hour, attributed MWh = min(metered campus consumption, portfolio metered output, corridor-headroom transfer cap). Corridor utilization shown is loading from all other schedules, before the campus-attributed transfer.

Noon (12:00 UTC)
Solar + Wind Peak, Corridor Clear
Portfolio output 760 MW (wind 400 + solar 360).
Headroom check: a 500 MW transfer adds 500 × 0.58 = 290 MW of corridor flow; corridor at 35% — clears. Mode A.
Attributed: 500 MW, capped at campus load. Hour CFE 100%.
Counterfactual: Regional CCGT (displaced). LME avoided: ~380 kgCO₂e/MWh.
Dusk (18:00 UTC)
Solar Declining, Corridor Congesting
Portfolio output 480 MW. Corridor at 85%: headroom 150 MW caps the transfer at ~259 MW.
Flex pool curtails 180 MW → corridor relief 180 × 0.58 = 104 MW → cap rises to ~439 MW. Mode A+B.
Attributed: 439 MW of 500 MW load. Hour CFE 88%.
Counterfactual: Regional CCGT.
Night (02:00 UTC)
Wind Only, Full Flex Curtailment
Wind output 320 MW. Corridor at 96%: headroom 40 MW caps the transfer at ~69 MW.
Flex pool curtails 250 MW → corridor relief 250 × 0.58 = 145 MW → cap rises to ~319 MW. Mode B: seven-layer validation + PQC.
Attributed: min(320 MW output, 319 MW cap) = 319 MW. Hour CFE 64%.
Counterfactual: Regional CCGT.
Dawn (06:00 UTC)
Solar Ramping, Corridor Clearing
Portfolio output 600 MW. Corridor at 55%: headroom 450 MW; a 500 MW transfer adds 290 MW of flow — clears.
Flex pool releasing back to normal operation. Mode B→A transition.
Attributed: 500 MW, capped at campus load. Hour CFE 100%.
Counterfactual: Regional CCGT.
TIME PORTFOLIO OUTPUT CORRIDOR FLEX POOL CORRIDOR RELIEF TRANSFER CAP ATTRIBUTED (≤ 500 MW LOAD) HOUR CFE MODE
12:00 760 MW 35% Idle - >1,000 MW 500 MW 100% A
18:00 480 MW 85% 180 MW curtails 104 MW ~259 → ~439 MW 439 MW 88% A+B
02:00 320 MW 96% 250 MW curtails 145 MW ~69 → ~319 MW 319 MW 64% B
06:00 600 MW 55% Releasing - ~776 MW 500 MW 100% B→A
Reading the profile: The portfolio→campus transfer loads the binding 400 kV corridor at PTDF 0.58: each MW of attributed transfer places 0.58 MW of flow on the constrained corridor, with the remainder distributing across parallel paths. PTDF is a corridor-loading sensitivity, not a delivery fraction; a MWh attributed to the campus is a full MWh at the campus meter, and no hour may attribute more than the campus’s metered consumption. Per hour, attributed MWh = min(metered campus consumption, portfolio metered output, corridor headroom ÷ 0.58), against an illustrative 1,000 MW corridor rating. The flex pool’s consumption transits the same corridor (PTDF 0.58), so curtailing L MW reduces corridor flow by 0.58 × L MW and raises the transfer cap by L MW. Mode B does not raise the corridor’s physical limit; it reallocates constrained corridor capacity to the campus’s attributed transfer while the marginal generator at the campus side (Regional CCGT) backs down. The four snapshots deliberately include stress hours (88% and 64%). The 97%+ figure is a modeled annual target derived from an hourly (8,760-hour) simulation of the portfolio, load, and corridor series, not from these four snapshots; methodology available on request.
Issuance Timing

Because the facility sits in the EU/ENTSO-E domain and the Causal Dispatch Proof can be constructed from ENTSO-E Transparency Platform generation and flow data (~D+1), JAO-published flow-based parameters (day-ahead), and national TSO dispatch and settlement data delivered under the D3 data-access agreements, DeliveryTags for this architecture are issued directly in their final (DT-F) state without a provisional phase, subject to the contracted TSO data-delivery schedule.

9.2 US Architecture: Nodal Market (PJM)
500 MW DC near nuclear station • PJM region • 1.5–2 GW nuclear + 200 MW solar
US Nodal Market Advantage. Unlike the EU zonal model, PJM operates with full nodal pricing (Locational Marginal Pricing). Each node provides settlement-grade LMP data, enabling precise attribution. Settlement-grade LME is mandatory for DT-F issuance; the two-state DT-P/DT-F lifecycle applies per §4.3.1 and Principle 30. DOE IRA §45Y clean electricity production credit applies.
Physical Topology

The campus connects at a 500 kV substation adjacent to a nuclear generating station (1.5–2 GW baseload). A 200 MW solar portfolio is located within the same PJM zone. PTDF of the nuclear + solar → campus transfer onto the binding monitored flowgate: 0.60 (share of each attributed MW of transfer flowing on the constrained element; illustrative). As in §9.1, attributed MWh per hour is capped at min(metered campus consumption, portfolio metered output, flowgate headroom ÷ 0.60). Counterfactual: Regional coal/gas plant.

Flex Pool: Regional Industrial DR

The flex pool comprises regional industrial demand-response assets totalling ~170 MW:

Quarry Operations (~40 MW) Heavy Equipment Mfg (~25 MW) Utility Industrial DR (~60 MW) University Load Flex (~30 MW) Municipal Pumping (~15 MW)
~170 MW
Collective flex capacity
~102 MW
Max flowgate-flow relief at full curtailment (170 × 0.60)
97%+
Modeled target CFE (hourly simulation, Mode A + B)
Grid Nuclear 1.5-2 GW + 200 MW Nuclear + Solar Flex Pool ~170 MW curtails PJM Congestion PJM Zone PTDF path 500 MW AI DC 24/7 CFE @ Node
US Issuance Cycle
1
D+1 to D+7
Provisional DeliveryTag (DT-P) issued based on PJM Initial Settlement, preliminary PTDF, ex-ante LME estimate.
2
D+30 to D+45
Accredited LME providers publish settlement-grade nodal LME. DT-P promoted to Final DeliveryTag (DT-F).
3
D+55
PJM Final Billing (~D+55). DT-F locked in registry. Designed for ISAE 3000 reasonable assurance. IRA §45Y eligible.
10. Next Steps

The publication of this whitepaper opens the public consultation phase of the DeliveryTag specification. The Integrity Protocol Foundation invites comment from:

  • the EnergyTag Secretariat and its working group chairs,
  • national TSOs and regional system operators,
  • hyperscaler procurement and sustainability teams,
  • flex pool operators and aggregators,
  • accredited verification bodies and ISAE 3000-qualified assurance practices,
  • regulators in jurisdictions implementing RED III, 45V, and Scope 2 market-based method revisions,
  • academic institutions in power-systems, market-design, and carbon-accounting disciplines.
Reference Implementation

A v4 reference Guardian policy, implementing the full seven-layer validation pipeline, post-quantum signatures, and Hedera HCS anchoring described in Sections 4.9–4.11, is published on Managed Guardian Service (testnet) and publicly inspectable without credentials:

indexer.guardianservice.app, DeliveryTag v4 reference policy

The reference policy demonstrates the full Accredited Signer workflow, Mode A / Mode B discrimination, flex-load binding, and two-state issuance (DT-P / DT-F) against a live Hedera testnet deployment.

Target Milestones (Gated)

The dates below are gated targets, not commitments. Each milestone is contingent on the gating dependencies listed after the table; a milestone slips if its dependencies are not closed.

TIMELINEMILESTONE
Q3 2026Public comment period closes. v1.3 draft circulated to working groups.
Q4 2026First EU pilot and first US pilot go live; first DeliveryTags issued and registered. Gated on D1–D5 below.
Q1 2027v1.4 specification published, incorporating pilot learnings and public comments. Gated on pilots having produced learnings (D1–D5).
Q2 2027Formal coordination agreement proposed to the EnergyTag Secretariat for DeliveryTag as an official EnergyTag GC extension profile. Proposal only; acceptance is the Secretariat's decision.
2027Additional pilots proposed in ERCOT (Texas AI data centers), MISO (North Dakota wind corridor), NordPool (offshore wind + Scandinavian hyperscalers), and CAISO (California solar + storage campuses). Proposed markets; no counterparties are engaged in these regions as of publication.

Gating dependencies. As of this publication, none of the following has been completed; each is a prerequisite for the pilot milestones above:

  • D1, Pilot counterparties. Signed pilot agreements with a generator host, a buyer, and (where applicable) a flex pool operator for each reference architecture.
  • D2, Hardware certification and manufacture. S-PIN and D-PIN units manufactured, safety-certified for the deployment jurisdictions, and installed at pilot sites.
  • D3, TSO / ISO data access. Executed data-access arrangements covering the network-model, dispatch, and settlement feeds each architecture requires; see the “Data Sources by Market” table in §9 for which datasets are public and which require these agreements.
  • D4, Assurance engagement. A signed ISAE 3000 engagement with a qualified Accredited Signer; no engagement is in place as of publication.
  • D5, Foundation formation. Completion of the Integrity Protocol Foundation's Swiss Stiftung formation, so the issuing entity legally exists before first issuance.
Pilot Acceptance Criteria

A pilot is considered successful when the following criteria are met within the target pilot window (Q4 2026 to Q2 2027) and confirmed by the engaged Accredited Signer in a written reasonable-assurance opinion. Criterion 7 presupposes dependency D4 above: an assurance engagement must be executed before the pilot window opens, and no such engagement exists as of publication.

#DimensionMetricThreshold
1Seven-layer validation pass rateFraction of issuance attempts where all seven S-PIN layers return PASS≥ 95%
2D-PIN deployment timePhysical install to first signed bundle on Hedera≤ 4 weeks per site
3PTDF attribution accuracyDVB-computed PTDF values vs the applicable reference for the same interval: zonal flow-based PTDFs published via the JAO Publication Tool (EU pilot) or TSO/RTO-provided shift factors obtained under the D3 data-access agreements (US pilot)within ±2%
4Counterbalance rejectionAttempted second cancellations on same (corridor, hour, MWh) or same (D-PIN, hour) triple, rejected by Guardian policy100%
5Issuance cap enforcementAttempted issuance above the node-hour deliverability cap at (node, hour), rejected by Guardian policy100%
6Cancellation tier distributionSplit of retirements by Tier 1 / Tier 2 / Tier 3Tier 1 ≥ 50% in at least one reference architecture by end of pilot
7Assurance opinionISAE 3000 reasonable-assurance opinion issued over the pilot Guardian policy by the engaged Accredited Signer (dependency D4)Issued within pilot window
8Pilot volumeTotal DT-F issued and retired during pilot≥ 10,000 MWh per reference architecture
9End-to-end latencyS-PIN sensor bundle to DT-F minted and Hedera-anchored≤ D+7 for DT-P, ≤ D+45 for DT-F
10Public indexabilityAll pilot DT-Fs discoverable without credentials via the MGS Indexer100%

A pilot that meets all ten criteria triggers promotion of the reference architecture from pilot status to reference implementation status in v1.4 of the specification.

The DeliveryTag is a complement, not a replacement. Its design goal is to honor the EnergyTag framework in full and to close the one dimension, nodal delivery, that the EnergyTag standards leave for future work. The Integrity Protocol Foundation commits to maintaining this alignment as the primary design principle for all future versions of the specification.
11. Glossary

Key terms used throughout this specification. EnergyTag terminology is applied in full unless explicitly extended here.

TermDefinition
24/7 CFE24/7 Carbon-Free Energy. A corporate procurement commitment that electricity consumption is matched hour-by-hour with clean-energy generation, delivered through a physically verified path.
Accredited SignerA party qualified to issue a reasonable-assurance opinion under ISAE 3000 or equivalent. Intended scope includes major international assurance practices and ISO 14065 / IAF-MLA accredited validation bodies. Countersigns DeliveryTags and witnesses hardware installs. No signer is engaged as of this publication; engagements are contractual and will be disclosed once in place. Replaces the legacy CDM-era "VVB" label. Principle 33.
AssuranceAccreditationThe verifiable credential (VC) schema that records an Accredited Signer's attestation over a PIN device, binding its Dilithium public key to a specific grid node.
Cancellation TierOne of three demand-side proof configurations: Tier 1 (D-PIN present, hardware-signed, ISAE 3000 reasonable assurance), Tier 2 (attested utility meter, limited assurance), Tier 3 (registry-only, operational claims only). Principle 35.
Causal Dispatch ProofStructured data object (§4.8) binding a DeliveryTag to a TSO merit-order log entry, a PTDF matrix row, flex-curtailment telemetry, and a counterfactual LME calculation.
Claim-Based AllocationPer-buyer attribution mechanism at multi-buyer nodes, resolved under two cryptographic constraints (issuance ≤ the node’s corridor-headroom deliverability cap, cancellation ≤ D-PIN-attested consumption) plus market-priced secondary trading. §4.5.1 and Principle 37.
Consumption PointA separately measured grid access point at which electricity is consumed (EnergyTag definition).
Counterfactual GeneratorThe marginal generator that would have cleared at the Node of Attribution during the certificate's time interval in the absence of the DT-attested flex curtailment or clean injection.
CRYSTALS-DilithiumNIST FIPS 204 lattice-based post-quantum digital signature algorithm used inside every PIN to sign sensor bundles at the source.
D-PINDemand-side PIN. Tamper-evident hardware at the buyer's point of interconnection. Tri-Sensor stack (Electrical, Magnetic, Frequency) with optional Thermal. Signs cancellation bundles with Dilithium. §4.11.2 and Principle 34.
Dispatch Verification Body (DVB)Independent entity validating the TSO dispatch log, PTDF matrix, and flex-curtailment telemetry. Candidates include TSOs (ENTSO-E for EU) and grid analytics firms (accredited LME providers for North America).
DT-FFinal DeliveryTag. Final state, designed for ISAE 3000 reasonable assurance. Issued at D+1–7 in EU or D+30–45 in US after third-party LME attestation.
DT-PProvisional DeliveryTag. Issued at D+1–7 with preliminary dispatch data. Must promote to DT-F within 60 days or is voided. Applies wherever dispatch or settlement data at issuance is provisional (in practice US RTO/ISO markets, where LME attestation arrives at T+30–45); EU markets with D+1 final data may mint DT-F directly without a DT-P phase (§4.3.1, Principle 30).
EACEnergy Attribute Certificate. Covers RECs (US), Guarantees of Origin (EU), I-RECs, and EnergyTag Granular Certificates.
ENTSO-EEuropean Network of Transmission System Operators for Electricity. Its Transparency Platform (Regulation (EU) 543/2013) publishes the per-unit generation, load, and cross-border flow data DeliveryTag uses. ENTSO-E does not publish PTDF matrices; zonal flow-based PTDFs for Core CCR are published separately via the JAO Publication Tool.
Flexible LoadGrid-connected consumption asset capable of modulating demand within the certificate's time resolution, sub-metered at revenue-grade resolution.
FRANDFair, Reasonable, and Non-Discriminatory. The licensing commitment applying to any claims granted on DeliveryTag's USPTO provisional applications (DSEE and T-NAC) following planned non-provisional conversion.
GC (Granular Certificate)EnergyTag-defined EAC with time resolution ≤ 1 hour, issued against measured generation and cancelled against measured consumption at a Consumption Point.
GuardianOpen-source Hedera-based policy engine for verifiable credential workflows. Hosts the DeliveryTag policy that validates issuance, cancellation, and counterbalance rules cryptographically.
HederaDistributed ledger anchoring DeliveryTag proofs. HCS for consensus, HTS for tokenized transfer.
Hepta-ValidationBrand name for the seven-layer validation stack: the forensic sensor stack on the S-PIN comprising Electrical, Thermal, Magnetic+Frequency, Acoustic, Spatial/SAR, Emissions, and Economic Oracle layers. Referred to in this document as the seven-layer validation stack. §4.9.
ISAE 3000International Standard on Assurance Engagements 3000. The reasonable- or limited-assurance framework used by major assurance practices for non-financial assurance engagements, including corporate sustainability.
LMELocational Marginal Emissions. Tons of CO₂e displaced per additional MWh of generation or curtailment at a specific node. Derived from counterfactual-generator identification using ENTSO-E data and TSO dispatch records (EU), or attested by an accredited LME provider (US).
MGSManaged Guardian Service. Hedera-hosted managed deployment with public indexer; DeliveryTag's reference policy is published on MGS testnet, inspectable without credentials.
Mode ANodal Attribution. Uncongested corridor hours. PTDF-based corridor-headroom check verifies deliverability, no curtailment. $1–$8/MWh, an illustrative scenario parameter pending pilot price discovery (§6.3).
Mode BFlex-load curtailment swap (branded “Physical Electron Swap”, §2). Congested corridor hours. Flex-load curtailment frees PTDF-weighted headroom. Full seven-layer validation plus Opportunity Cost Oracle. ~$150/MWh, an illustrative scenario parameter pending pilot price discovery (§6.3).
Node of AttributionSpecific transmission busbar (110 kV, 220 kV, 400 kV or higher) to which a Consumption Point is electrically connected. Identified by ISO-standard substation code (ENTSO-E EIC, NERC CA ID).
Opportunity Cost OracleLayer 7 of the seven-layer validation stack (§4.9). Compares flex-load's real-time revenue to its curtailment cost, evidencing deliberate financial sacrifice. Mode B only.
PINPhysical Integrity Node. Tamper-evident hardware signing sensor bundles at the source with Dilithium. S-PIN at supply, D-PIN at demand. Principle 34.
PQCPost-Quantum Cryptography. Resistant to classical and quantum attacks. DeliveryTag uses CRYSTALS-Dilithium throughout.
PTDFPower Transfer Distribution Factor. Signed sensitivity coefficient, typically in [−1, +1], defined per source–sink transfer and per monitored line: the change in MW flow on that line per 1 MW of transfer. Negative values indicate counterflow. Not a delivery fraction; used in DeliveryTag as a corridor-headroom check that caps attributed MWh. See §7.1.
S-PINSupply-side PIN. Full seven-layer validation stack at generator POI or flex-load busbar. §4.11.1.
Tri-SensorD-PIN sensor configuration: the Electrical layer plus the magnetic and frequency channels of the Magnetic+Frequency layer of the seven-layer validation stack (§4.9). Optional Thermal channel for reasonable-assurance engagements.
TSOTransmission System Operator. High-voltage grid operator. Authoritative source for dispatch and redispatch records, network models, and interconnection agreements; network models and unit-level dispatch data are typically confidential and obtained under data-access agreements (§9).
Verifiable Credential (VC)W3C-standardised cryptographic credential format. DeliveryTag uses VCs for AssuranceAccreditation, DeviceRegistration, DeliveryProof, and CancellationProof schemas.
12. References

Sources for the statistics, standards, and regulatory instruments cited in this document. Figures described in the text as “illustrative” or as “scenario parameters” are the Foundation’s modeling assumptions, not external sources, and are labeled as such where they appear.

  1. Association of Issuing Bodies (AIB). AIB membership and EECS Hub statistics. 2026. aib-net.org/facts/aib-member-countries-regions/aib-members
  2. Bundesnetzagentur. Monitoringbericht (annual electricity-market monitoring report); congestion-management cost data via SMARD. 2022–2024. smard.de
  3. CEN-CENELEC (CEN-CLC/JTC 14, WG 5). EN 16325:2025, Guarantees of origin related to energy. 2025. cencenelec.eu/news-events/news/2025/eninthespotlight/2025-08-14_en16325_energyorigin/
  4. Clean Energy Buyers Association (CEBA). Letter to the GHG Protocol Independent Standards Board, signed by CEO Rich Powell, 23 May 2025; accompanying public statement. cebuyers.org/blog/ceba-calls-for-immediate-changes-to-greenhouse-gas-protocols-scope-2-revision-process/
  5. Council of the European Union. “Omnibus I” directive simplifying CSRD/CSDDD sustainability-reporting requirements; adopted 24 February 2026, published in the Official Journal 26 February 2026. consilium.europa.eu/en/press/press-releases/2026/02/24/council-signs-off-simplification-of-sustainability-reporting-and-due-diligence-requirements-to-boost-eu-competitiveness/
  6. Department for Energy Security and Net Zero (UK). Low Carbon Hydrogen Standard, version 3. 2023.
  7. EnergyTag. EnergyTag and granular energy certificates: Accelerating the transition to 24/7 clean power (whitepaper). 2021. energytag.org/wp-content/uploads/2023/09/EnergyTag-Whitepaper.pdf
  8. EnergyTag. Granular Certificate Scheme Standard, Version 1. March 2022. energytag.org/wp-content/uploads/2022/03/20220329-GC-Scheme-Standard.pdf
  9. EnergyTag. Granular Certificate Scheme Standard, Version 2. December 2024. energytag.org/wp-content/uploads/2024/12/EnergyTag_Granular-Certificate-Scheme-Standard-V2.pdf
  10. EnergyTag. Granular Certificate Matching Standard, Version 1. 2024. energytag.org/wp-content/uploads/2024/03/Granular-Certificate-Matching-Standard_V1.pdf
  11. EnergyTag. “EnergyTag Accredits First Granular Certificate Issuers.” 2025. energytag.org/energytag-accredits-first-granular-certificate-issuers-marking-a-major-milestone-for-hourly-clean-energy-tracking/
  12. ENTSO-E. Transparency Platform (Regulation (EU) No 543/2013). transparency.entsoe.eu
  13. European Commission. Commission Recommendation C(2026) 2676 on removing barriers to the development of power purchase agreements (non-binding instrument, Art. 288 TFEU). 22 April 2026. energy.ec.europa.eu/news/commission-recommendation-facilitate-power-purchase-agreement-take-2026-04-22_en
  14. European Union. Regulation (EU) 2023/956 establishing a carbon border adjustment mechanism (CBAM). eur-lex.europa.eu/eli/reg/2023/956/oj
  15. European Union. Directive (EU) 2023/2413 (RED III), Article 19. eur-lex.europa.eu/eli/dir/2023/2413/oj
  16. GHG Protocol (WRI/WBCSD). Scope 2 Guidance (2015) and Scope 2 revision public-consultation materials (2025–2026). ghgprotocol.org/blog/upcoming-scope-2-public-consultation-hourly-matching-and-deliverability
  17. Google. 24/7 by 2030: Realizing a Carbon-free Future (whitepaper). September 2020. sustainability.google/reports/247-carbon-free-energy/
  18. IAASB. ISAE 3000 (Revised), Assurance Engagements Other than Audits or Reviews of Historical Financial Information.
  19. JAO. Publication Tool: Core flow-based market-coupling parameters (zonal PTDFs for CNECs). publicationtool.jao.eu
  20. Microsoft. “Made to measure: Sustainability commitment progress and updates” (100/100/0 by 2030 commitment). 14 July 2021. blogs.microsoft.com/blog/2021/07/14/made-to-measure-sustainability-commitment-progress-and-updates/
  21. Morrison Foerster. “Proposed Changes to GHG Protocol Scope 2 Guidelines Threaten to Reshape Corporate Clean Energy Procurement” (practitioner survey). June 2025. mofo.com/resources/insights/250626-proposed-changes-to-ghg-protocol-scope-2-guidelines
  22. National Energy System Operator (NESO). Annual Balancing Costs Report 2025 (GB constraint and balancing costs, FY 2023/24–2024/25). June 2025. neso.energy/industry-information/balancing-costs
  23. NIST. FIPS 204, Module-Lattice-Based Digital Signature Standard (CRYSTALS-Dilithium). 2024. csrc.nist.gov/pubs/fips/204/final
  24. Nixon Peabody. “California climate disclosure laws — SB 253 and SB 261 status update” (SB 253 first Scope 1–2 reports due 2026; SB 261 enforcement stayed by Ninth Circuit injunction of 18 November 2025). March 2026. nixonpeabody.com/insights/alerts/2026/03/02/california-climate-disclosure-laws-update
  25. Potomac Economics (ERCOT Independent Market Monitor). 2024 State of the Market Report for the ERCOT Electricity Markets. June 2025. potomaceconomics.com/wp-content/uploads/2025/06/2024-State-of-the-Market-Report.pdf
  26. REsurety. “Quantifying the Accuracy of Commonly Used Marginal Emissions Data.” 2024. resurety.com/quantifying-the-accuracy-of-marginal-emissions-data/
  27. State of Colorado. SB26-102, hourly-matching provisions for data centers (postponed indefinitely, 11 May 2026). 2026. leg.colorado.gov/bills/sb26-102
  28. Steinsultz, N., P. Christian, J. Cofield, G. McCormick, and S. Sofia. “Validating locational marginal emissions models with wind generation.” Environmental Research: Energy 1(3). 2024. doi.org/10.1088/2753-3751/ad72f6
  29. U.S. Department of the Treasury / Internal Revenue Service. Final regulations, Credit for Production of Clean Hydrogen (Section 45V). Federal Register, January 2025.
  30. U.S. Securities and Exchange Commission climate-related disclosure rule: adopted March 2024, stayed April 2024; the Commission voted to end its defense of the rule in March 2025 and has since proposed rescission (see Duane Morris client alert, June 2026). duanemorris.com/alerts/sec_proposes_rescind_climate_disclosure_rules_practical_steps_companies_can_take_now_0626.html
  31. WattTime. Public comments on the GHG Protocol Scope 2 revision. 2025. (Direct link to be confirmed at publication.)
Appendix A, Threat Model

The following threat model describes plausible attacks against DeliveryTag integrity and the mitigations designed into the protocol. The structure is designed to support ISAE 3000 reasonable-assurance engagements and independent cybersecurity reviews; each threat maps to the control that addresses it.

ThreatAttack PathMitigation
PIN private-key compromisePhysical extraction of the Dilithium key from a secure elementKey generated inside secure element, never exported; tamper seal zeroises key on breach; lost key invalidates all subsequent signed bundles; key rotation requires a new AssuranceAccreditation VC from an Accredited Signer
Sensor spoofing at S-PINFake thermal, magnetic, or acoustic signals fed to the PIN sensorsSeven-layer validation cross-check: a falsified single layer is inconsistent with the other six (electrical, thermal, magnetic+frequency, acoustic, spatial, emissions, economic oracle). Guardian policy rejects any issuance where layer disagreement exceeds calibrated thresholds.
Sensor spoofing at D-PINFake current or magnetic signals at the buyer POITri-Sensor cross-check (electrical / magnetic / frequency): magnetic corroboration of metered current (Ampère's Law) plus voltage-waveform/harmonic analysis and anti-replay time alignment against reference grid-frequency data. Layer 4 (Thermal, optional) adds Joule-effect corroboration. A spoofed channel must remain consistent with the others beyond calibrated thresholds to pass.
Node-identity spoofingA D-PIN claims to be at Node X when it is physically at Node YNode identity rests on the AssuranceAccreditation VC issued by an Accredited Signer after a witnessed physical install, plus registry-level binding of the device key to the node. Grid frequency is uniform within a synchronous area, so the frequency channel confirms interconnection membership and record timing but cannot by itself distinguish nodes; the binding control is attestational, not sensor-based. Post-install relocation is treated as a separate threat below.
Post-install device relocationA correctly attested D-PIN is physically moved from Node X to Node Y after the witnessed install, while continuing to sign bundles under its Node X registrationRelocation requires disconnecting the CT/VT taps and uplink, producing a discontinuity in the signed telemetry stream (gap in the monotonic sequence and metering record) that flags the device. Detection is procedural rather than sensor-based, no D-PIN channel can independently prove nodal location within a synchronous area, so this is a residual risk to be bounded during pilots via telemetry-continuity monitoring and periodic physical re-inspection by the Accredited Signer.
Double-claim / counterbalanceTwo buyers attempt to cancel against overlapping consumption at a multi-buyer nodePrinciple 38: Guardian policy enforces ex ante rejection of second cancellation against same (corridor, hour, MWh) or same (D-PIN, hour). Cryptographic, not post-hoc audit.
Issuance above node capacityGenerator issues more DT-Fs at a node-hour than the node’s deliverability cap allowsPrinciple 36: total-node-issuance-check-block in Guardian sums issuances at (node, hour) and rejects any issuance that would exceed the corridor-headroom deliverability cap for that interval (min of metered injection, metered consumption, and PTDF-implied transfer capability).
Registry compromiseA compromised EAC registry (M-RETS, AIB Hub, GREXEL) corrupts or deletes DeliveryTag recordsRegistry holds only a pointer (hedera_proof_id); the proof itself lives on Hedera HCS and is independently verifiable. Registry compromise does not invalidate the DT-F.
Guardian-policy denial of serviceSustained DoS against the Guardian API blocking new issuances or cancellationsGuardian is open-source; multiple independent Guardian instances can be run (local docker-compose, MGS, third-party). Pilot architecture uses both local and MGS redundancy. DT-Ps can queue and promote once Guardian availability is restored.
Accredited Signer collusionAn Accredited Signer issues a fraudulent AssuranceAccreditation VC or Tier 2 attestationAccredited Signer's credential chain is public; revocation flows from the accreditation body (ISO 14065 / IAF-MLA) to Guardian in the event of misconduct. Any Tier 2 attestation is checkable against the Signer's public scope of accreditation.
Quantum attack on signaturesA cryptographically-relevant quantum computer breaks classical RSA or ECDSADeliveryTag uses CRYSTALS-Dilithium (NIST FIPS 204), a lattice-based PQC algorithm resistant to known quantum algorithms. Migration to newer PQC standards is planned as NIST evolves the suite.
Supply-chain attack on PIN hardwareMalicious modification of PIN hardware during manufacture or shipmentPIN hardware is UL-listed / CE-marked; tamper seal integrated at factory; Accredited Signer physical inspection at install commissioning detects pre-installation tampering. AssuranceAccreditation VC is issued only after install-time verification.
Replay of HCS messagesAn attacker replays old signed sensor bundles to forge new DT-F issuancesEvery bundle carries a UTC timestamp from the PIN's GPS-disciplined clock and a monotonic sequence number; Guardian policy rejects duplicates by (PIN_id, timestamp, sequence).

This threat model is maintained by the Integrity Protocol Foundation's security working group and updated with each specification revision. Additional threat scenarios identified during pilot operations (Q4 2026 onward) will be incorporated in v1.4.

DeliveryTag
Auditable Deliverability Verification for 24/7 CFE
Steward
Integrity Protocol Foundation
Correspondence:
Baarerstrasse 135
6300 Zug
Switzerland
Swiss Stiftung in formation, Canton of Zug
© Copyright Integrity Protocol Foundation 2026
Patent Filings & Licensing
USPTO Prov. Appl. 64/023,803 (DSEE)
USPTO Prov. Appl. 64/023,364 (T-NAC)
FRAND Licensing Commitment
Contact: deliverytag.org/contact www.deliverytag.org
WHITEPAPER ACCESS

Read DeliveryTag Whitepaper v1.3

Enter your details to access the full technical specification.

By submitting, you agree to our Privacy Policy.