3. Background
From RECs to GCs to DeliveryTags
3.1 The Annual REC Era (2001–2022)
For two decades, the global market for voluntary renewable-energy procurement ran on annual-resolution Renewable Energy Certificates: one certificate per MWh of clean generation, with no time stamp finer than a calendar year, and no spatial binding below the market or country level. A corporate buyer could claim “100% renewable” while consuming coal-generated electricity in the dead of night or during a calm, cloudy winter afternoon. The market recognized the shortcoming: voluntary REC prices collapsed to €2–5/MWh, reflecting limited credibility.
3.2 The EnergyTag Era (2022–present)
The EnergyTag Initiative, launched in 2020, published its foundational whitepaper in 2021 and codified the framework in the Granular Certificate Scheme Standard (V1, March 2022; V2, December 2024). The standard defines the Granular Certificate (GC): an EAC with time resolution ≤ 1 hour, issued by an EAC Issuing Body against measured generation and cancelled against measured consumption at a Consumption Point. The EnergyTag framework introduced formal roles, Measurement Body, GC Issuer, Registry, Consumption Verification Body, and a detailed principles catalogue (avoidance of double counting, immutability, verifiability, energy storage dual-role handling, UTC time zones, and more).
EnergyTag’s impact is now visible across the industry: Google’s 24/7 CFE program, Microsoft’s 100/100/0 pledge, M-RETS’s hourly certificate pilot in North America, Energinet’s Origin Hub in Denmark, TenneT’s CertiQ roadmap in the Netherlands. The GC Scheme Standard V2 (December 2024) and the GC Matching Standard V1 (2024) are the canonical normative references for temporal granularity in clean-energy attribution, and EnergyTag accredited its first Granular Certificate issuers in 2025.
3.3 The Spatial Layer
The EnergyTag whitepaper is explicit about its scope: temporal granularity. It defines “Domain” as the geographic region in which GCs are issued and cancelled, typically mapped to a market or country. It does not address transmission congestion, corridor saturation, Power Transfer Distribution Factors, nodal pricing, or Locational Marginal Emissions. These are, by design, left for future work or for complementary frameworks.
In practice, this creates a structural limitation. On a congested grid, a GC can be issued for wind energy that was generated in one region but curtailed at the corridor interface, never reaching the consumption region. A buyer in a congested zone can cancel a GC against a clean MWh produced several PTDF-distant nodes away, while the marginal generator actually serving their busbar remains a coal or gas plant. The temporal principle is satisfied; the physical delivery is not.
Three Forces Making the Spatial Layer Load-Bearing
-
Hyperscaler scale. A single 100–500 MW AI data center on a single 400 kV bus is large enough to move the marginal generator at that node. Diffuse matching at the country level no longer reflects the buyer’s actual grid impact.
-
Regulatory tightening. EU RED III Article 19 (renewable fuel of non-biological origin criteria for hydrogen), the Inflation Reduction Act Section 45V hydrogen tax credit rules, and the GHG Protocol Scope 2 Market-Based Method revision all push toward geographic + temporal additionality. Nodal proof is becoming a compliance requirement, not a marketing differentiator.
-
Available telemetry. Grid data transparency has improved materially, though unevenly. What is genuinely public: ENTSO-E’s Transparency Platform (Regulation (EU) 543/2013) publishes per-unit actual generation, load, and cross-border physical flows; the JAO Publication Tool publishes the daily day-ahead flow-based parameters, zonal PTDFs and remaining available margins per critical network element, for the Core capacity-calculation region; the four German TSOs publish plant-level redispatch measures on netztransparenz.de; and US RTOs publish nodal LMPs and binding-constraint shadow prices (PJM Data Miner 2 at 5-minute resolution; ERCOT market reports, with unit-level dispatch and offer data disclosed at a 60-day lag). What remains restricted: full nodal PTDF matrices, network models, and real-time unit-level dispatch data, treated as CEII in the US (18 CFR § 388.113) and as confidential by EU TSOs. DeliveryTag therefore does not assume a public nodal-PTDF product: the Dispatch Verification Body computes nodal PTDFs from network models obtained under market-participant and TSO data-access agreements and cross-validates them against the published zonal factors and constraint data (§9, Data Sources; Principles 21 and 36).
3.4 The Market Mandate (GHG Protocol Scope 2 Public Consultation, 2025–2026)
Between 20 October 2025 and 31 January 2026, the World Resources Institute and the GHG Protocol Secretariat ran the first round of public consultation on the revised Scope 2 Standard. The draft revision makes two things mandatory for corporate reporting: hourly temporal correlation (Quality Criterion 4) and deliverability (Quality Criterion 5). Criterion 5 is satisfied through one of three approved pathways, zonal market boundaries, price-differential deliverability, or physical-delivery deliverability.
The third pathway, Alternate methodology 2, is the clause that operationalises physical delivery. Verbatim (consultation document, Section 5.1.2, p. 24):
"A reporting entity may claim consumption of power delivered from any point in an interconnected transmission system if it demonstrates the existence of exclusive rights allocating to the reporting entity or its energy provider the transmission capacity necessary to deliver power bundled with associated energy attributes from the point of generation to the point of consumption. […] Delivery of power and attributes must be demonstrated on an hourly or more frequent basis with no direct counterbalancing reverse transactions."
This clause did not exist in the 2015 Scope 2 Guidance. Its appearance in the 2025 draft reflects a convergence of integrity-camp demand and regulator recognition that annual matching, even layered over high-quality EACs, no longer maps to physical flows.
3.4.1 The Feasibility Gap the Market Identified
The first-round consultation surfaced a consistent objection. The Clean Energy Buyers Association (CEBA), in its 23 May 2025 letter to the Independent Standards Board signed by CEO Rich Powell, stated: "mandatory matching is infeasible in many markets and would hinder energy buyers' efforts to procure carbon emissions-free electricity." WattTime's public position is that the proposed requirements will be "considerably more complex, and in most cases far more expensive." Morrison Foerster's practitioner survey found "nearly 80% of respondents lack confidence in their ability to procure time-matched clean electricity within smaller market boundaries" and "70% stated that their current procurement contracts would no longer be eligible."
These concerns are empirically correct for today's infrastructure. They describe the gap between what the Standard now requires and what market participants can currently prove. They do not describe a permanent limitation, they describe the absence of purpose-built physical-verification infrastructure.
3.4.2 DeliveryTag Maps Clause-by-Clause to Alternate Methodology 2
DeliveryTag v1.3 is calibrated against the published proposed text. The mapping is deliberate, not coincidental:
| WRI Alternate Methodology 2 Clause | DeliveryTag Component |
| Exclusive rights over transmission capacity | PTDF-weighted corridor allocation; Mode B tokenised capacity (T-NAC, USPTO provisional application 64/023,364) |
| Recognition by transmission operators | Deliverability computed from TSO/RTO-published flow and constraint data (JAO flow-based parameters, PJM constraint feeds) and validated against them; network models obtained under TSO/RTO data-access agreements (§9) |
| Mutually compatible tracking systems | EnergyTag overlay, DT-F extends the standard GC, does not replace it |
| Hourly or more frequent proof | IEC 62053-22 Class 0.2S metering at 15-min resolution; DT-P at D+1–7, DT-F at D+30–45 |
| No direct counterbalancing reverse transactions | Guardian policy enforces cryptographically via CRYSTALS-Dilithium signatures (DSEE, USPTO provisional application 64/023,803) |
DeliveryTag does not ask the Secretariat to invent a new category, it supplies the technology the category presupposes.
3.4.3 Protection for Buyers and Sellers Against Greenwashing
The anti-gaming clause, "no direct counterbalancing reverse transactions", is the load-bearing anti-greenwashing provision in the entire deliverability regime. Human-audited registries enforce this post hoc. DeliveryTag enforces it ex ante: a second certificate claiming the reverse flow on the same corridor-hour-MWh triple is rejected by the Guardian policy at the cryptographic layer and cannot be recorded.
For buyers, this means a 24/7 CFE claim is substantiated by the TSO's own operational data, signed hardware, and an Accredited Signer opinion under ISAE 3000, not a self-reported attestation.
For sellers (clean generators, flex loads), it means delivery proof is independently verifiable and designed to resist forgery by a competitor or arbitrageur. This hardware-verified proof layer protects both sides of the transaction.
The 2025–2026 Scope 2 consultation describes the regulatory destination. DeliveryTag is the infrastructure that makes arriving there feasible today.
3.4.4 Alignment with Adjacent Frameworks (SBTi, IFRS S2, CSRD, RED III, 45V)
The WRI GHG Protocol revision is the upstream source, but corporate reporters are bound by a broader set of frameworks that inherit from or reference Scope 2 methodology. DeliveryTag maps to each:
| Framework | DeliveryTag Contribution |
| SBTi (Science-Based Targets initiative) | SBTi's CNZ and FLAG criteria require hourly-matched 24/7 CFE reporting by 2030 for near-term targets. DeliveryTag satisfies the physical-deliverability requirement that SBTi's forthcoming Scope 2 criteria are expected to inherit verbatim from the revised GHG Protocol. Tier 1 assurance maps directly to SBTi's external-verification expectation. |
| IFRS S2 (ISSB climate-related disclosures) | IFRS S2 requires disclosure of Scope 2 emissions with location-based and market-based methodologies, specifying underlying assumptions and data quality. The DeliveryTag causal_dispatch_proof and cancellation_tier attributes are structured to surface in IFRS S2 disclosure templates without additional transformation. |
| EU CSRD / ESRS E1 (Corporate Sustainability Reporting Directive) | ESRS E1-6 requires gross Scope 2 emissions under both methods, plus GHG removals and mitigation projects. DeliveryTag cancellations are designed to feed the market-based method line with assurance-ready traceability and to satisfy the ESRS double-materiality evidence chain for purchased electricity. |
| EU RED III Article 19 (RFNBO hydrogen temporal + geographic correlation) | RED III requires hourly matching and same-bidding-zone geographic correlation, with a tightening pathway to higher granularity. DeliveryTag's PTDF-based nodal attribution exceeds the bidding-zone requirement by a full order of magnitude and is future-proof against tightening geographic criteria. |
| IRA Section 45V (US clean hydrogen tax credit) | 45V requires three pillars: incrementality, deliverability (same region), temporal matching (annual, hourly by 2028). DeliveryTag's Mode A nodal attribution and Mode B flex-load curtailment swap satisfy deliverability at a resolution below the 45V region boundary and are natively compatible with the 2028 hourly transition. |
DeliveryTag is framework-agnostic by design: the same DT-F certificate serves GHG Protocol Scope 2, SBTi, IFRS S2, CSRD, RED III, and 45V reporting without re-issuance or re-verification, because it carries the union of their evidence requirements natively.
3.4.5 UK Market Context, Existing Flex Infrastructure Meets Nodal Verification
The UK is a distinctive case. As an island system with a single system operator (NESO, the National Energy System Operator, established October 2024) and a well-developed DNO / DSO flexibility layer, it has the institutional surface for nodal-level attribution but has approached the problem from the opposite direction, dispatch first, verification second. DeliveryTag slots into that stack as the verification-first complement, not as a competing marketplace.
The demand backdrop is public record. Google has committed to operating on 24/7 Carbon-Free Energy by 2030 across its operations, including the UK (see §12 References), and other hyperscale operators are expanding UK data-centre capacity against the same shareholder and reporting pressure. NESO's connections queue contains a large and growing volume of prospective data-centre demand. DESNZ's AI Growth Zones framework and the Clean Power 2030 programme both treat locational signals as load-bearing. (Companies are named here as public-record market context only; no commercial relationship is implied.)
Constraint economics are already material. GB network constraint costs ran just over £1.5bn in the 2023/24 financial year and are trending higher, with balancing costs rising a further ~10% in 2024/25 (NESO, Annual Balancing Costs Report, 2025). The Scottish B5 / B6 transmission boundary alone accounts for a material fraction, driven by constrained-off Scottish wind that cannot physically reach southern demand. Every constrained MWh is a nodal-delivery question: the GC timestamp matches but the electrons do not arrive. This is the textbook geography for DeliveryTag's virtual-transmission mechanism (see §5.3): a flexible load served across B5 / B6 that curtails demand reduces loading on the boundary in proportion to its PTDF, and the resulting corridor relief raises the deliverability cap at the buyer's node, with attributed MWh always capped at the buyer's metered consumption.
Regulatory trajectory is convergent. DESNZ's Low-Carbon Hydrogen Standard v3 already requires both temporal and geographic correlation for RFNBO eligibility, aligning UK hydrogen policy with EU RED III Article 19. Ofgem's REMA (Review of Electricity Market Arrangements) and NESO's Strategic Spatial Energy Plan both move toward locational pricing signals. The direction of travel is identical to the GHG Protocol Scope 2 deliverability clause, spatial granularity is no longer a US-nodal curiosity.
UK DNO / DSO flex marketplaces are complementary, not competitive.
GB's fourteen DNO licence areas (operated by six distribution groups, several now running DSO functions) already host flexibility marketplaces, with Electron and Pico as the principal software platforms. Those platforms handle dispatch, clearing, and settlement. DeliveryTag does not. DeliveryTag is the authentication layer on top: PIN-signed sensor evidence that a specific flex event produced the claimed corridor relief and node-hour attribution, carrying an Accredited Signer's ISAE 3000 opinion over the Guardian policy. One marketplace, two layers, no overlap. Flex dispatched by Electron or Pico, attested by DeliveryTag.
The UK does not need a new flex marketplace. It needs an interoperable authentication standard that lets UK-dispatched flex service a Scottish wind corridor relief event for a London hyperscaler in a way that survives CSRD and IFRS S2 assurance. That is the gap DeliveryTag fills.
The DeliveryTag is the framework that closes this gap by extending the Granular Certificate with a spatial proof layer.
4. Components of a DeliveryTag System
A DeliveryTag system preserves the EnergyTag component architecture and adds two roles: the Dispatch Verification Body and the Nodal Attribution Registry extension.
4.1 Account Holding
Identical to EnergyTag. Producers, traders, and consumers hold accounts in an EnergyTag-compliant registry. DeliveryTag certificates are issued, held, transferred, and cancelled within these same accounts as extension attributes on standard GCs.
4.2 Avoidance of Double Counting
DeliveryTag inherits the EnergyTag double-counting avoidance principle in full. A DeliveryTag attribute set can only be attached to a GC that is itself non-duplicated within the registry. Additionally, because the DeliveryTag binds the certificate to a specific node, the same clean MWh cannot simultaneously be claimed as "delivered" at two different nodes. The nodal binding is exclusive.
§ 4.2, Nodal Exclusivity
How It Works, Atomic Nodal Binding
One physical dispatch event, one supply of tokens, two nodal buyers. HTS atomicity, enforced at the Hedera layer, guarantees that the same MWh cannot be credited to two different nodes, nor re-scoped after issuance.
Illustrative worked example. Buyer A and Buyer B are hypothetical parties; no commercial relationship with any real company is implied.
SOURCE EVENT
Nuclear Plant produces 1,000 MWh @ 14:00 UTC
Smart contract mints exactly 1,000 tokens. Not 1,001.
DT-F-001, 500 MWh
Buyer: Buyer A (hyperscale data-center operator, illustrative)
Node: Ashburn, VA
PTDF path: Plant → 345kV → Ashburn
→ HTS token transferred to Buyer A
DT-F-002, 500 MWh
Buyer: Buyer B (hyperscale data-center operator, illustrative)
Node: Chicago, IL
PTDF path: Plant → 345kV → Chicago
→ HTS token transferred to Buyer B
Enforced, Not Promised
Buyer A cannot acquire a certificate that asserts delivery to Buyer B’s node. The Node of Attribution is set at issuance and cannot be re-scoped (Principle 28). The HTS token is atomic: once transferred, the seller’s balance is zero for that token. “Same MWh to two nodes” is blocked at the protocol layer on Hedera rather than being caught in a post-hoc audit.
Tradability on EAC secondary markets. DeliveryTags are transferable between accounts (Principle 17) but the Node of Attribution is immutable. A DeliveryTag for Node A can be resold to another buyer at Node A, but never re-scoped to Node B. On EAC secondary markets, buyers filter by their node; the marketplace matches sellers who hold certificates attributed to that specific node. This creates node-specific liquidity pools rather than a single fungible market, reflecting the physical reality of grid delivery.
4.3 Issuance
Structural independence
DeliveryTag is structurally independent of any matching platform, ETRM provider, or registry. This independence is required by ISAE 3000: an attestation source cannot be the same entity that produces the management assertion. The Accredited Signer audits the DeliveryTag evidence chain (hardware-signed sensor data, PTDF computation, Hedera anchoring) as a source independent of any commercial matching engine that consumes the certificate downstream.
ETRM and portfolio-management platforms (Granular Energy, Power Ledger, and others) consume DeliveryTag attestations as inputs to their hourly matching, allocation, and reporting workflows. They do not replace the attestation. This separation of roles, measurement, attestation, matching, prevents the judge-and-party conflict that ISAE 3000 and ISO 14065 are designed to eliminate.
A DeliveryTag is issued by the Integrity Protocol Foundation upon certification by an Accredited Signer, a party qualified to issue a reasonable-assurance opinion under ISAE 3000 (or equivalent). Intended scope includes major international assurance practices and ISO 14065 / IAF-MLA accredited validation bodies. No assurance engagement is in place as of this publication. Executing a signed engagement is a gating dependency for Tier 1 and Tier 2 issuance and a pilot acceptance criterion (Section 10); until a reasonable-assurance opinion is issued, the DT-F assurance level is a design target, not an attested status. Engagements will be disclosed once in place. Issuance requires the following independent inputs:
- a valid underlying GC (produced and metered under the EnergyTag framework),
- a TSO dispatch log entry (merit-order data covering the issuance time interval),
- a Power Transfer Distribution Factor attestation from the Dispatch Verification Body, confirming that the named generator or flex curtailment physically relieved the buyer’s node during the interval,
- for US RTO/ISO jurisdictions (MISO, PJM, ERCOT, CAISO, SPP, NYISO), a third-party Locational Marginal Emissions (LME) attestation from an accredited LME provider, quantifying the fossil-marginal emissions displaced by the clean injection or flex curtailment at the specific node and hour (for EU bidding-zone jurisdictions, ENTSO-E and national TSO dispatch data is used instead, as described in the subsection below), and
- an Accredited Signer certification confirming proof integrity and compliance with the DeliveryTag standard.
Issuance timing is jurisdiction-dependent and is bounded by the availability of final settlement data:
D+1 to D+7
EU Jurisdictions (ENTSO-E)
LME is not mandatory. The EU grid uses bidding zones, not nodal pricing. Deliverability is computed from public flow and congestion data (ENTSO-E Transparency Platform, JAO flow-based parameters, national redispatch publications) plus TSO network and dispatch data under data-access agreements (§9). Emissions impact is derived from the counterfactual generator's known emissions factor. Settlement at D+1.
T+30 to T+45
US Jurisdictions (RTO/ISO + LME)
LME is mandatory. US RTOs use nodal pricing (LMP). Settlement-grade LME is supplied by accredited third-party providers. LME reconciles RTO final settlement dispatch, ex-post generator attribution, and congestion components. Published on month-end batch cycle. DeliveryTag issuance in MISO, PJM, ERCOT, CAISO, SPP, NYISO.
4.3.1 Provisional and Final Issuance States
To support the two-speed timing of EU and US markets without forcing buyers to wait 30–45 days for a certificate, the DeliveryTag specification defines two issuance states:
Provisional DeliveryTag (DT-P). A DeliveryTag issued with preliminary dispatch data and a candidate LME estimate. DT-P is valid for internal reporting, PPA settlement, and buyer-side accruals, but is not ISAE 3000 attestable as a final certificate. DT-P is issued at D+1 to D+7.
Final DeliveryTag (DT-F). A DeliveryTag issued after final settlement data and third-party LME attestation are received. DT-F supersedes the DT-P with identical registry serial (same parent GC, same Node of Attribution) and carries the full Causal Dispatch Proof object. DT-F is issued at D+30 to D+45 in US jurisdictions and at D+1 to D+7 in EU jurisdictions where no third-party LME settlement is required.
A DT-P that is not promoted to DT-F within the maximum window (60 days) is automatically voided in the registry and cannot be used for cancellation. A DT-F that materially diverges from its DT-P predecessor (>10% on PTDF relief or >15% on LME) triggers a mandatory correction notice to the offtaker and the Dispatch Verification Body.
This two-state lifecycle mirrors the provisional/final structure already used in RTO settlement accounting (e.g. MISO’s Initial Settlement Statement at T+5 days and Final Settlement Statement at T+55 days) and preserves the EnergyTag principle of cancellation against measured consumption without blocking near-real-time operational workflows.
4.4 Transfer
DeliveryTag certificates transfer as extension attributes on their parent GCs. Transfer between accounts follows EnergyTag transfer semantics. However, transfer does not break the nodal binding: a DeliveryTag continues to attest to its original node of attribution regardless of which account holds it. Buyers may transfer DeliveryTags to affiliates or aggregators but may not re-scope the node of attribution.
4.5 Cancellation and Retirement
DeliveryTags cancel against measured consumption at a specific Consumption Point in accordance with the EnergyTag cancellation principle. Additionally, the DeliveryTag can only be cancelled against consumption that is electrically connected to the node of attribution specified in the certificate. A DeliveryTag issued for node X cannot be cancelled against consumption at node Y, even if the timestamps match.
The node-binding check is enforced cryptographically through the Demand-side PIN (D-PIN) installed at the buyer’s consumption point, which is registered to a specific transmission node in the Guardian policy and signs the cancellation certificate with CRYSTALS-Dilithium before Hedera anchoring. This makes the “node X ≠ node Y” rule a computational constraint, not a procedural one. See Section 4.11.2 for the D-PIN architecture and the three cancellation tiers (Tier 1 full seven-layer validation with D-PIN; Tier 2 attested meter; Tier 3 registry-only).
4.5.1 Claim-Based Allocation at Multi-Buyer Nodes
Most practical grid nodes serve several consumers simultaneously (urban substations, 345 kV collector buses, industrial zones, hyperscaler co-location campuses). When a node’s deliverable clean capacity at hour H, capped by the corridor-headroom check (§7.1), is less than the aggregate demand of the buyers connected to that node, a resolution rule is required. DeliveryTag uses a market-driven, claim-based allocation with two cryptographic constraints, enforced at the Guardian policy layer:
Issuance constraint. The Guardian policy rejects any DT-F issuance that would push the total issued at (node, hour) above the node-hour deliverability cap: the minimum of the named portfolio’s metered injection, the aggregate metered consumption at the node, and the transfer capability implied by the binding corridor’s available headroom and the transfer’s PTDF on that corridor. This is enforced by the total-node-issuance-check-block against the applicable PTDF matrix and corridor-loading data. Scarcity at the node is enforced at the source, not post hoc.
Cancellation constraint. Each buyer can only retire DT-Fs against its own verified consumption at the node. In Tier 1 this is enforced cryptographically: the buyer’s D-PIN signs a cancellation bundle and the Guardian policy compares the retired volume against the D-PIN’s attested consumption for the hour. A buyer cannot retire more than it consumed, and cannot retire against another buyer’s consumption. In Tier 2 the same constraint is enforced by an Accredited Signer attestation over the buyer’s metered consumption.
Market allocation. Scarce node-hour DT-Fs are traded on the EAC-compatible secondary markets. Price allocates scarce capacity to the highest willingness-to-pay, naturally serving the most demanding 24/7 CFE commitments first. The protocol does not set the allocation; it enforces the two constraints and lets the market resolve the distribution.
The combination of headroom-capped issuance, D-PIN-enforced cancellation, and market-priced allocation makes multi-buyer node attribution fully decentralised, cryptographically verifiable, and privacy-preserving between competing buyers. No buyer needs to disclose its consumption data to another, and the TSO remains a passive publisher of PTDF and dispatch data rather than an active data intermediary.
4.6 Registration
DeliveryTags register in an EnergyTag-compatible registry (e.g. M-RETS, Guarantee of Origin hub, Hedera Guardian topic). Proof data is anchored on Hedera (HCS for consensus, HTS for tokenized certificates). Certificates carrying DeliveryTag proofs trade on the EAC-compatible secondary markets, where buyers access verified 24/7 CFE instruments. The extension attributes required for DeliveryTag registration are:
| Attribute |
Description |
| node_of_attribution |
ISO-standard transmission substation identifier |
| ptdf_relief_mw |
Numeric, MW of corridor headroom freed |
| dispatch_log_hash |
Cryptographic hash of TSO merit-order log covering the interval |
| counterfactual_lme |
Locational marginal emissions displaced, tCO₂e/MWh |
| flex_curtailment_ids |
Array of sub-metered flexible-load SCADA identifiers |
4.6.1 Registry-Independent Integrity
The DeliveryTag proof chain survives independently of any certificate registry. The proof lives on Hedera, not in the registry. The registry stores only a pointer (hedera_proof_id) to the immutable proof on the public ledger.
The registry is the filing cabinet. Hedera is the notary. Certificates can move between registries (M-RETS, AIB Hub, GREXEL, Hedera Guardian). The notarial stamp (Hedera anchoring + PQC signature + Accredited Signer countersign) remains identical and independently verifiable, forever.
Accredited Signer audit trails are registry-independent. The audit follows the same 7-step path regardless of which registry holds the certificate:
1
Receive Hedera proof ID
2
Query Hedera HCS for signed bundle
3
Verify PQC signature (PIN hardware)
4
Check all 7 validation-layer sensor readings
5
Verify PTDF against TSO data
6
Confirm Oracle verdict (Mode B)
7
Issue Accredited Signer certification (ISAE 3000)
This architecture is strictly stronger than traditional GO integrity. If a registry is compromised or deletes a record, the Hedera proof survives. The HTS token is atomic: the same certificate cannot exist in two registries simultaneously.
| Phase | Approach | Registries |
| 2026 | Direct API | M-RETS (US), Hedera Guardian |
| 2027 | Secondary-market API | EAC trading venues |
| 2027+ | AIB Hub bridge | AIB Hub EECS member registries (~30 issuing bodies across 36 European countries; AIB, 2026) |
§4.6.2, Marketplace Integration
The Math Meets the Market
DeliveryTag does not operate its own exchange. Verified certificates trade on EAC-compatible secondary markets. DeliveryTag provides the physics layer; the secondary market provides the liquidity layer.
01, SCHEMA
Metadata Extension
A single field (dt_proof_id) added to the GC schema. Zero changes to matching engine or settlement.
02, API
API Bridge
DeliveryTag API returns verification status in real time. GCs display a “DT Verified” badge in the order book.
03, FEED
Exchange Data Feed
Verification data published alongside price data on exchange-connected terminals. Banks and utilities see sensor confidence and PTDF attribution in their existing workflow.
Physics-backed certainty, priced accordingly. A DT-verified GC bundles nodal PTDF attribution, dual-PIN attestation, and an evidence chain designed for ISAE 3000 assurance. The design thesis is that buyers pursuing externally assured 24/7 CFE, hydrogen, and Scope 2 claims will treat that evidence as a material input and price it as one; the pilots exist to test that thesis.
4.7 Nodal Attribution (New Component)
The Dispatch Verification Body, an independent entity distinct from the GC Issuer and the Measurement Body, is responsible for validating that the TSO dispatch log and the flex-curtailment telemetry are consistent and that the PTDF-weighted relief attested in the DeliveryTag is mathematically sound. Candidate entities include national TSOs, regional system operators (ENTSO-E for the EU), independent grid analytics firms (accredited LME providers for North America), and accredited third-party auditors.
4.8 Causal Dispatch Proof (New Component)
Each DeliveryTag carries a causal dispatch proof: a structured data object containing:
- (i) the TSO merit-order log for the interval,
- (ii) the PTDF matrix row covering the node of attribution,
- (iii) the flexible-load SCADA telemetry that was curtailed or dispatched, and
- (iv) the counterfactual LME calculation.
This object is hashed and anchored in the registry.
4.9 Hepta-Validation™: The Forensic Proof Stack
To ensure verifiability and raise the cost of replication by pure software traders, the DeliveryTag protocol anchors each Causal Dispatch Proof in seven independent Hardware-Verified Event layers, branded Hepta-Validation and referred to throughout this document by its plain name, the seven-layer validation stack: six observational layers grounded in physical measurement, plus one economic baseline:
| Layer |
Sensor / Source |
Verification Target |
| 1. Electrical |
Revenue-grade IEC 62053-22 Class 0.2S metering |
kWh consumed / curtailed at 15-min interval resolution |
| 2. Thermal |
FLIR infrared sensors |
Equipment cooldown signature proving physical load reduction, not meter manipulation |
| 3. Magnetic + Freq |
Fluxgate magnetometers + frequency analyzers |
Current flow cessation at feeder level (Ampère’s Law) + 50/60 Hz voltage-waveform and harmonic analysis confirming synchronous operation and time-aligning the record against reference grid-frequency data (anti-replay) |
| 4. Acoustic |
Decibel monitoring arrays |
Mechanical cessation of industrial equipment (arc furnaces, compressors, turbines) |
| 5. Spatial |
Satellite multispectral / SAR imagery |
Upstream generation restart confirmation; wind turbine restart verification post-curtailment |
| 6. Emissions |
Mass balance sensors (Lavoisier’s Law) |
Carbon in fuel = carbon in exhaust; emissions displacement verified via conservation of mass |
| 7. Economic |
Opportunity Cost Oracle |
Economic baseline: real-time comparison of facility revenue potential vs. curtailment cost distinguishes deliberate sacrifice from market exit (rationale in §4.10, Layer 7) |
Layers 1–4 are collected at the edge gateway installed at the flex load facility (not on grid infrastructure). Layer 5 is sourced from independent satellite providers using multispectral imagery. Layer 6 applies Lavoisier’s conservation of mass to verify emissions displacement. Layer 7 is computed from real-time market prices and the facility’s production schedule (economic-baseline rationale in §4.10).
Each seven-layer validation event is signed with a Post-Quantum Cryptographic (PQC) signature (CRYSTALS-Dilithium) at the edge gateway, ensuring tamper-resistance against both classical and quantum adversaries. The signed proof object is then anchored to a Hedera Guardian topic, producing a public, immutable, timestamped record that can be independently verified by any auditor without privileged access. The combination of hardware-verified sensor data, PQC-signed proof objects, and Hedera’s distributed ledger creates a hardware-rooted evidence chain that software-only certificate systems are not designed to provide.
4.10 Physical Principles as Verification Infrastructure
DeliveryTag grounds its sensor stack in five physical principles, Kirchhoff’s and Ohm’s Laws (electrical and thermal via the Joule effect), Ampère’s Law (magnetic), mechanical vibration (acoustic), and conservation of mass (emissions inference), plus an economic baseline (Layer 7), deployed across the seven validation layers of Section 4.9. Physical sensor corroboration is designed to make paper-only falsification detectable: a claimed curtailment must simultaneously reproduce consistent electrical, thermal, magnetic, and acoustic signatures, each independently signed at source and cross-checked against calibrated thresholds. Appendix A specifies the adversary model and residual risks.
1. Ohm’s Law and the Thermal Signature (Joule Effect)
Ohm’s Law is inseparable from the Joule effect: P = R × I². When current (I) flows through a cable or machine, resistance (R) converts part of the energy into heat.
DeliveryTag application (Layer 2, Thermal): FLIR infrared sensors measure this thermal signature. When a refinery or data center curtails load, Ohm’s Law dictates that conductor temperature must drop. If a trader attempts to falsify a curtailment on paper, the equipment remains hot. The FLIR sensor is the “lie detector” grounded in Ohm’s Law.
2. Ampère’s Law and the Magnetic Signature
Ampère’s Law states that every electric current generates a magnetic field proportional to its intensity. Ohm’s Law determines the current intensity (I) flowing through a circuit for a given voltage (U), and Ampère’s Law translates that current into a measurable magnetic field.
DeliveryTag application (Layer 3, Magnetic + Frequency): Fluxgate magnetometers measure the facility’s actual magnetic-field signature (branded the “Nodal Pulse”). The protocol does not trust the utility meter (which can be hacked or simulated), it measures the actual magnetic field generated by electrons in motion. Additionally, frequency analyzers sample the local 50/60 Hz voltage waveform. Because grid frequency is uniform across a synchronous area, a single facility’s curtailment does not produce a locally distinguishable frequency deviation; the frequency channel is instead used to confirm the site is energised and synchronised to its interconnection, to time-align the signed sensor record against reference grid-frequency data (an electric-network-frequency check that resists replay of previously recorded bundles), and to capture local waveform and harmonic changes when large equipment switches off. This combined measurement, magnetic field intensity plus waveform behaviour, corroborates that current actually flowed, or stopped flowing, at the monitored feeder.
3. PTDFs: Ohm’s Law Applied to the Grid
The Power Transfer Distribution Factors (PTDFs) used to compute the “Virtual Cable” (in plain terms, the PTDF-weighted delivery path between generator and buyer node) are the mathematical resolution of Ohm’s Law across a complex network. Electricity distributes across all available paths inversely proportional to impedance (Kirchhoff's Laws).
DeliveryTag application (PTDF Binding): By modifying the load at a precise node, the distribution of power flows across the network changes according to Kirchhoff’s and Ohm’s Laws. The DeliveryTag certificate evidences that physical corridor capacity was freed by acting on the global impedance of the system.
Why This Is the Anti-Greenwashing Argument
An energy trader works with LMPs (Locational Marginal Prices), which are economic signals. DeliveryTag couples those signals to physical measurements taken at the facility.
The physics cross-check. A market price can be manipulated or misreported; a physical signature has to be produced by real equipment. By coupling certificates to the thermal and magnetic signatures measured at the facility, DeliveryTag attaches a “physical receipt” to each claim. Falsifying a curtailment on paper would require simultaneously reproducing consistent electrical, thermal, magnetic, and acoustic readings, each signed at source inside sealed hardware. This is what is designed to make the DeliveryTag certificate resistant to greenwashing: not absolute certainty, but a materially higher cost of forgery, bounded by the adversary model and residual risks stated in Appendix A.
4. Mechanical Vibration and the Acoustic Signature
Operating industrial equipment (arc furnaces, compressors, turbines) produces characteristic vibro-acoustic signatures generated by the mechanical forces at work inside it. Those signatures disappear when the machinery stops.
DeliveryTag application (Layer 4, Acoustic): Decibel monitoring arrays at the flex load facility detect the disappearance of the equipment’s operating acoustic signature when it shuts down during curtailment, measured against a calibrated site baseline that accounts for ambient and neighbouring-equipment noise. A facility claiming curtailment while its machinery keeps running would have to suppress this signature and keep it consistent with the electrical, thermal, and magnetic layers simultaneously; the cross-check is designed to detect that inconsistency.
5. Lavoisier’s Law and the Emissions Signature
Lavoisier’s Law (Conservation of Mass) states that in any chemical reaction, mass is neither created nor destroyed. In combustion: carbon in fuel = carbon in exhaust. This principle underpins emissions verification.
DeliveryTag application (Layer 6, Emissions): By measuring the mass balance of combustion inputs and outputs at the marginal generator, DeliveryTag verifies that emissions displacement actually occurred. When a flex curtailment displaces a fossil generator, Lavoisier’s Law provides an independent physical confirmation that the carbon was not emitted; the fuel was not burned, therefore the CO₂ was not produced.
The Economic Baseline: Why Financial Sacrifice Matters
Physical verification alone is necessary but not sufficient. A facility that shuts down because spot prices dropped below its marginal cost has not made a sacrifice; it has simply exited the market. For freed transmission capacity to be credible and tradeable, the protocol must prove that curtailment was a deliberate economic sacrifice, that the facility was forgoing real revenue by curtailing.
DeliveryTag application (Layer 7, Economic): The Opportunity Cost Oracle compares the facility’s real-time revenue potential (based on spot prices, the facility’s marginal cost, and its production schedule) against the curtailment cost. If the oracle confirms that the facility was profitable at the moment of curtailment, the sacrifice is genuine and the freed capacity becomes a credible, sellable asset. If the facility was already losing money, the curtailment is flagged as a market exit and the freed capacity claim is rejected. This economic baseline is the final gatekeeper that transforms a physical event into a trustworthy financial instrument.
From Accounting Promise to Physical Proof
| Principle |
Measurable Effect |
Validation Layer |
What It Proves |
Joule Effect P = R × I² |
Heat dissipation in conductors |
Layer 2, Thermal (FLIR) |
Equipment actually powered down |
Ampère’s Law ∮ B · dl = μ₀I |
Magnetic field around conductors |
Layer 3, Magnetic (Fluxgate) |
Current actually stopped flowing |
Waveform & Synchronism f = 50/60 Hz |
Local AC voltage-waveform and harmonic behaviour |
Layer 3, Frequency channel |
Site energised and synchronised to its interconnection; record time-aligned against reference grid-frequency data (anti-replay) |
Kirchhoff + Ohm V = Z × I (network) |
Power flow redistribution |
PTDF Binding |
Corridor capacity physically freed |
Mechanical Vibration Vibro-acoustic signature |
Acoustic vibration cessation |
Layer 4, Acoustic (dB arrays) |
Industrial machinery actually stopped |
Lavoisier’s Law Conservation of Mass |
Carbon mass balance in combustion |
Layer 6, Emissions (mass balance) |
Emissions displacement physically verified |
Economic Baseline Opportunity Cost |
Revenue potential vs. curtailment cost |
Layer 7, Economic (Oracle) |
Curtailment was sacrifice, not market exit |
4.10b The Seven-Step Certification Pipeline
From grid physics to immutable certificate: seven steps transform raw sensor data into a verifiable, auditable DeliveryTag anchored on the Hedera Guardian ledger.
1
DETECT
Grid congestion detected via PTDF analysis and satellite multispectral imagery. Corridor saturation identified at the transmission node.
2
CURTAIL
Flex load portfolio curtails demand at the congested node, freeing PTDF-weighted corridor capacity for clean energy delivery.
3
VERIFY
The seven-layer validation stack (§4.9) confirms curtailment via five physical principles plus an economic baseline: Kirchhoff/Ohm (electrical), Joule effect (thermal), Ampère (magnetic), mechanical vibration (acoustic), conservation of mass (emissions), and the Opportunity Cost Oracle (economic).
4
SIGN
Post-Quantum Cryptographic (PQC) signature (CRYSTALS-Dilithium) seals the proof object at the edge gateway. Quantum-resistant integrity.
5
ANCHOR
Signed proof anchored to Hedera Guardian ledger, producing a public, immutable, timestamped record verifiable by any auditor.
6
AUDIT
Accredited Signer (qualified under ISAE 3000) certifies proof integrity and compliance.
7
ISSUE
Upon Accredited Signer certification, the Integrity Protocol Foundation issues the DeliveryTag certificate as an extension attribute on a standard EnergyTag Granular Certificate.
Accredited Signer Independence. The Accredited Signer operates independently of the Integrity Protocol Foundation and the flex load operator. Accredited Signer auditors have read-only access to the Hedera-anchored proof chain and sensor telemetry. Their certification is a prerequisite for DeliveryTag issuance: no certificate can be issued without third-party verification.
4.11 The Physical Integrity Node (PIN), Supply-side and Demand-side
DeliveryTag uses a dual-PIN architecture: a Supply-side PIN (S-PIN) at the generation or flex-load facility, and a Demand-side PIN (D-PIN) at the buyer’s consumption point. Together they close the forensic chain end-to-end. The S-PIN proves the MWh was produced or curtailed; the D-PIN proves it was consumed at the node claimed on the certificate. Without the D-PIN, cancellation would depend on a human-audited utility meter, which is the same weak link DeliveryTag removes on the supply side.
4.11.1 Supply-side PIN (S-PIN)
The S-PIN is a tamper-evident, industrially sealed hardware unit installed at the point of interconnection (busbar) of each generation or flex-load facility. It is the physical root of trust for issuance-side seven-layer validation data.
Definition. The S-PIN is an industrial “black box” sealed at the busbar, combining sensor fusion, cryptographic signing, and secure uplink in a single enclosure. It is designed so that any access, modification, or bypass by the facility operator breaks the tamper-evident seal, which invalidates all subsequent certificates.
Sensor fusion. The S-PIN aggregates four real-time sensor streams at the point of measurement:
- Electrical: Revenue-grade IEC 62053-22 Class 0.2S current/voltage measurement at 15-min intervals
- Magnetic + Frequency: Fluxgate magnetometer measuring magnetic field (Ampère’s Law) + frequency analyzer sampling the 50/60 Hz voltage waveform (synchronism, harmonics, and anti-replay time alignment) at the flex load facility feeder conductors
- Thermal: FLIR infrared sensor capturing the Joule-effect thermal signature (Ohm’s Law) at the flex load facility equipment
- Acoustic: Decibel array monitoring mechanical vibration of industrial equipment
Post-Quantum Cryptographic (PQC) signing at the source. Every 15-minute sensor bundle is signed inside the S-PIN using CRYSTALS-Dilithium (NIST FIPS 204), a lattice-based digital signature algorithm resistant to both classical and quantum adversaries. The private key is generated and stored in the S-PIN’s secure element and never leaves the device.
Why sign at the source? If sensor data were signed at a cloud server or registry, the path between the physical measurement and the cryptographic proof would be vulnerable to man-in-the-middle manipulation. By signing inside the sealed PIN at the busbar, DeliveryTag is designed so that no data exists in unsigned form outside the hardware enclosure. The chain of custody is: physics, sensor, PQC signature, Hedera anchor. No software layer touches raw data.
4.11.2 Demand-side PIN (D-PIN)
The D-PIN is the mirror-image hardware unit installed at the point of interconnection of the buyer’s consumption site, typically the main busbar or service entrance of a hyperscaler data center, industrial facility, or aggregated flex-load pool. Its role is the cancellation counterpart to the S-PIN’s issuance proof.
The D-PIN performs three functions:
- Consumption measurement. Revenue-grade IEC 62053-22 Class 0.2S metering at 15-min intervals, signed inside the D-PIN with CRYSTALS-Dilithium and anchored on Hedera.
- Node binding proof. The D-PIN’s device certificate is registered to a specific transmission node in the Guardian policy and is cryptographically bound to the buyer’s TSO interconnection agreement. A DeliveryTag issued for node X can only be cancelled against a D-PIN registered at node X. Node identity rests on the witnessed physical install and the
AssuranceAccreditation VC, backed by registry-level binding and hardware-level PQC signing; spoofing a node therefore requires defeating both the physical attestation and the device key, which the protocol is designed to make impractical within the adversary model of Appendix A (post-install relocation is treated as an explicit threat there).
- Counterbalance check. The D-PIN signs a cancellation certificate that goes onto Hedera alongside the issuance certificate. The Guardian policy rejects any second cancellation against the same consumption hour on the same D-PIN, enforcing the “no direct counterbalancing reverse transactions” clause from WRI Alternate Methodology 2 (see Section 3.4).
D-PIN sensor stack. Unlike the S-PIN, which carries the full seven-layer validation stack to prove curtailment events, the D-PIN answers a narrower question: “did this buyer consume N kWh at this node during this hour?” This requires only three sensor channels drawn from the seven-layer stack (Electrical, plus the magnetic and frequency channels of the Magnetic + Frequency layer), with a fourth (Thermal) optional for reasonable-assurance engagements.
| # | Layer | Sensor | Purpose | Status |
| 1 | Electrical | IEC 62053-22 Class 0.2S revenue-grade meter (CT + VT) at the main busbar, 15-min intervals | Measure kWh consumed | Required |
| 2 | Magnetic | Fluxgate magnetometer clamped on the feeder conductor | Prove current physically flowed (Ampère’s Law), not a meter-only figure | Required |
| 3 | Frequency | 50/60 Hz grid-frequency analyzer sampling the voltage waveform | Confirm the site is energised and synchronised to its interconnection, and time-align the signed record against reference grid-frequency data (anti-replay). Frequency is uniform within a synchronous area, so this channel corroborates liveness and timing; it does not by itself prove nodal location | Required |
| 4 | Thermal | FLIR infrared pointed at the main transformer or server hall | Corroborate real load via Joule effect (heat = consumption) | Optional, recommended for ISAE 3000 reasonable assurance |
Layers 5 (Spatial/SAR), 6 (Emissions), and 7 (Opportunity Cost Oracle) are not applicable to the D-PIN. They are S-PIN-specific proofs of curtailment and generation events.
Every D-PIN shares the same cryptographic core as the S-PIN: a secure element generating and storing a CRYSTALS-Dilithium private key that never leaves the device, a tamper-evident seal that zeroises the key if broken, a GPS-disciplined UTC time source for 15-min interval alignment, and a hardened uplink to the Guardian relay. The lighter sensor set means D-PIN CapEx is materially lower than S-PIN CapEx, which is what makes Tier 1 deployment practical at hyperscaler scale.
Why a D-PIN, not just a trusted utility meter? A buyer’s 24/7 CFE claim is only as strong as its weakest proof. Hardware-verified issuance signed by the S-PIN, then cancelled against a software-reported utility-meter value, is not hardware-verified end-to-end. The D-PIN closes that gap. For ISAE 3000 reasonable-assurance engagements, dual-PIN is the architecture designed to remove trusted third parties from the entire proof chain.
Why the D-PIN is structurally required for multi-buyer nodes. Most practical grid nodes serve several buyers simultaneously (urban substations, 345 kV collector buses, industrial zones, hyperscaler co-location campuses). Without a D-PIN per buyer, per-buyer attribution depends on disclosure of TSO settlement data, which (i) exposes commercial consumption between competing buyers, (ii) makes the TSO an active trust intermediary rather than a passive publisher, and (iii) is not typically granular or timely enough for hourly claims. A D-PIN resolves all three: each buyer signs its own consumption slice cryptographically, the TSO’s role is reduced to the network and flow data it already provides (published flow-based parameters plus model access under standing data-access agreements, §9), and privacy between competing buyers is preserved by construction. For any node with two or more DeliveryTag buyers, Tier 1 (D-PIN present) is the only architecture that works cleanly. See Section 4.5.1 for the claim-based allocation model this enables.
Deployment and Regulatory Footprint
The D-PIN is a passive measurement device installed on the buyer’s side of the utility revenue meter. It clamps non-invasively onto the buyer’s own conductors (CT/VT tap, fluxgate on the feeder), signs bundles inside the tamper-sealed enclosure, and pushes signed telemetry via an outbound uplink. It does not inject power, control loads, or interact with the grid operator’s equipment. Its regulatory category is identical to a commercial power-quality monitor, a tenant sub-meter, or a Building Energy Management System.
Required for deployment:
- UL listing (US) or CE marking (EU) on the hardware, provided once by the manufacturer
- Licensed electrician to perform the physical install (four to eight hours of work per site)
- Local electrical inspector sign-off under the applicable electrical code (NEC in the US, national code in the EU); typical one-day turnaround
Not required:
- Utility or transmission-operator approval
- PUC or PSC filing (US state), or FERC notification (US federal)
- TSO interconnection study (EU or US)
- Any form of grid-operator sign-off
For Tier 1 (reasonable-assurance) deployment, the Accredited Signer additionally witnesses the install, verifies the CT/VT tap points and tamper seal, photographs the installation for the ISAE 3000 evidence file, and issues the AssuranceAccreditation VC that binds the device’s Dilithium public key to the claimed transmission node.
Strategic consequence. Because the D-PIN sits entirely on buyer-owned property, hyperscalers and large industrial buyers can deploy unilaterally, without negotiating with the serving utility or entering a regulatory docket. Time to deploy is measured in weeks per site, and sites can be onboarded in parallel across an entire portfolio.
Multi-POI and Multi-Source Configurations
A single buyer may operate multiple D-PINs under one Buyer DID when the site has redundant feeders (two POIs at the same node) or dual-fed service (two POIs at different transmission nodes). Each D-PIN registers against its own tso_interconnection_node. At cancellation, the Guardian policy matches each DT-F to the D-PIN whose node equals the certificate's node_of_attribution, and sums D-PIN-attested consumption when multiple feeders serve the same node. Certificate-level generator provenance (nuclear, wind, solar) is preserved by the DT-F's immutable fields (generator_did, generator_node_of_injection) and is independent of which D-PIN the certificate retires against: a nuclear-backed DT-F and a solar-backed DT-F can both retire against the same D-PIN in the same hour, provided the sum of retirements does not exceed the D-PIN's attested consumption and each certificate's node_of_attribution matches a registered D-PIN. Physically source-segregated internal loops (“green loops”, where a tenant or use case is fed only by specific generation types) can be served by dedicated sub-D-PINs registered under the same Buyer DID if the buyer requires loop-level claim attribution.
4.11.3 Deployment Tiers
Not every reporter requires a D-PIN in every deployment. The specification defines three cancellation tiers matching audience requirements:
| Tier | D-PIN | Cancellation Proof | Assurance Level |
| Tier 1, Full Seven-Layer | Yes | Hardware-signed, end-to-end cryptographic | ISAE 3000 reasonable assurance (default for hyperscaler 24/7 CFE, regulated 45V hydrogen, externally assured corporate Scope 2) |
| Tier 2, Attested Meter | No | Utility revenue meter, plus Accredited Signer attestation that the meter is located at the claimed node | ISAE 3000 limited assurance (transitional, smaller reporters; phase-out target 2028) |
| Tier 3, Registry-only | No | TSO interconnection agreement, plus registry-level node binding | Operational claims only; not sufficient for Scope 2 or 24/7 CFE claims under the revised GHG Protocol |
Tier 1 is the default for DeliveryTag-issued certificates. Tier 2 is available during the transition window (2026, 2028) to support buyers whose infrastructure cannot yet accommodate a D-PIN. Tier 3 covers operational or internal reporting only.
5. Benefits of Nodal Granularity
Physics Scope
What DeliveryTag Claims, and What It Does Not
DeliveryTag does not claim to track individual electrons. In an AC grid, electrons oscillate in place and are fungible once injected; tracing a specific particle from a generator to a load is not physically meaningful. What DeliveryTag provides is auditable deliverability inference under network-flow physics, evidence that the MWh attributed to a buyer’s node was causally dispatched, routed through the claimed corridor, and registered at the claimed meter within the claimed interval, at a level of rigor suitable for ISAE 3000 attestation.
01
Corridor Attribution
A PTDF-based corridor-headroom check verifies the network could accommodate the attributed transfer from the named generator, or the relief from the named curtailment, to the buyer’s node. Kirchhoff compliance.
02
Causal Dispatch
TSO merit-order logs place the named asset within the dispatch stack that cleared the interval. Not a post-hoc paper trade.
03
Seven-Layer Validation
Seven-layer sensor stack (dual-PIN + Tri-Sensor) attests the event occurred at the claimed site and time. Not inferred from invoices.
5.1 Grid Physics (Kirchhoff Compliance)
Electricity flows according to physical laws of the network, not the legal structure of contracts. A GC without nodal binding can attest to clean production during an hour in which the clean MWh could not physically reach the consumer due to corridor saturation. Nodal binding resolves this by requiring that the certificate be issued only when the PTDF-based corridor-headroom check confirms the network could physically accommodate the attributed transfer from the named generator (or the relief from the named curtailment) to the buyer’s node, with attributed MWh capped at the buyer’s metered consumption. This is Kirchhoff compliance.
5.2 Carbon Accounting (Locational Marginal Emissions)
The emissions impact of 1 MWh of clean energy depends entirely on which generator it displaces. Displacing a lignite plant at a congested Polish node avoids ~1,000 kgCO₂e/MWh; displacing a gas plant at an uncongested Spanish node avoids ~350 kgCO₂e/MWh. The EnergyTag GC framework supports grid-average or market-wide emissions valuation; DeliveryTag supplements this with optional node-specific Locational Marginal Emissions derived from the TSO dispatch log, for use cases that require finer attribution. Peer-reviewed validation work using ERCOT wind-farm data has shown that dispatch-based locational marginal emissions models track real-world emissions impacts where average-emissions methods do not (Steinsultz et al., Validating locational marginal emissions models with wind generation, Environmental Research: Energy, 2024), and the accompanying industry analysis reports that nodal-resolution signals can differ from lower-resolution emissions models by up to roughly 50% (REsurety, 2024).
US: Third-Party LME (Mandatory)
Nodal pricing (LMP) enables settlement-grade LME computation. Accredited LME providers compute these values, deriving nodal marginal emissions from RTO final dispatch at T+30 to T+45. The LME value is the primary emissions metric on US DeliveryTags.
EU: Congestion + Counterfactual (Primary)
The EU grid uses bidding zones, not nodal LMP. Emissions impact is derived from congestion data (corridor utilization, published redispatch measures) and the counterfactual generator’s emissions factor, identified from ENTSO-E per-unit generation data and TSO dispatch records obtained under data-access agreements (§9). Public inputs available at D+1.
5.3 Flexibility Incentives (Virtual Transmission)
Because the DeliveryTag attributes corridor relief to specific flexible loads (heat pumps, electric boilers, electrolyzers, demand response, BESS, industrial furnaces), it creates a direct, auditable revenue path for flexibility services. A 100 MW flex pool dispatching in PTDF merit order to relieve a corridor earns DeliveryTag revenue proportional to the PTDF-weighted MW relieved, the corridor’s marginal price, and the buyer’s willingness to pay for verified 24/7 CFE. This is the commercial mechanism that enables “virtual transmission”, capacity expansion through flexibility rather than through new lines.
DSEE Computation, Equivalent Renewable Capacity (USPTO provisional application 64/023,803)
ERC(N, T) = ΔL(N, T) × [ LME(N, T) / LMEbaseline(N) ]
ERC, Equivalent Renewable Capacity (MWh of virtual clean generation)
ΔL, Verified Load Reduction at node N during interval T (hardware-verified via the seven-layer stack, §4.9)
LME(N,T), Locational Marginal Emissions rate at node N, interval T (tCO₂e/MWh)
LMEbaseline(N), 12-month rolling average marginal emissions at the node
When LME(N, T) > LMEbaseline(N), i.e. during high-carbon hours, the ERC exceeds the raw load reduction, reflecting the disproportionate emissions impact of curtailing during dirty hours.
US Input: settlement-grade LME
LME(N, T) = settlement-grade nodal marginal emissions, computed from RTO final dispatch at T+30 to T+45. The US LME methodology is proprietary to accredited third-party providers.
EU Input: Counterfactual Emissions Factor
LME(N, T) = emissions factor of the counterfactual generator identified from TSO merit-order logs + ENTSO-E congestion data. This computation is described in the DSEE provisional application (USPTO 64/023,803), positioning it as the European counterpart of the proprietary US LME methodology.
The DSEE formula is jurisdiction-agnostic. It accepts either a third-party LME value (US) or a counterfactual emissions factor derived from congestion + dispatch data (EU). The provisional application describes the computation method for both markets; enforceable rights would arise only from claims granted on the planned non-provisional filing.
5.4 Hydrogen (RED III Article 19 Compliance)
EU RED III Article 19 requires that renewable fuels of non-biological origin (RFNBOs) demonstrate temporal and geographic correlation with their renewable electricity input. The temporal correlation is addressed by EnergyTag GCs; the geographic correlation, currently handled at the bidding-zone level, is the dimension DeliveryTag adds finer resolution to via node-bound PTDF attestation, giving green-hydrogen producers a defensible certificate for regulatory filings and offtake contracts.
→
Renewable Input
Temporal ✓ Geographic ?
→
DeliveryTag
Temporal ✓
Geographic ✓
Physical ✓
→
RED III Art. 19
Compliant RFNBO
Assurance-ready proof
DeliveryTag closes the geographic correlation gap required by RED III Article 19 for green hydrogen certification.
5.5 Hyperscaler Trust
Hyperscale data-center operators are the archetypal buyer segment for deliverability evidence. Two have published hourly-matching commitments on the public record: Google (24/7 Carbon-Free Energy by 2030) and Microsoft (100/100/0 by 2030), see §12 References; other large operators (including Amazon, Meta, and Oracle) have published clean-energy procurement targets, generally on an annual-matching basis. Operators in this segment maintain internal auditing teams whose mandate is to verify that procurement claims reflect physical reality. The DeliveryTag provides such teams with a structured, externally verifiable proof object that can be audited without privileged market access. This reduces internal audit cost, regulatory exposure, and greenwashing risk.
Named companies are referenced solely for their published public commitments, as a description of the market segment. No commercial relationship with the DeliveryTag protocol or the Integrity Protocol Foundation is implied.
Temporal layer: EnergyTag GC
Hourly matching, registry, cancellation
Scoped to time
Spatial dimension addressed in complementary work
→
DeliveryTag Proof
PTDF + Sensor + PQC + Hedera
Nodal ✓
Physical ✓
Temporal ✓
Immutable ✓
→
Hyperscaler Outcomes
✓ Hourly + spatial coverage
✓ ISAE 3000 audit-ready evidence
✓ CSRD / SB 253 / RED III alignment
✓ No privileged access needed
Adding the spatial layer to the EnergyTag GC turns hourly clean-energy claims into evidence packs an auditor can independently cross-check against grid-physics inputs.
6. The Integrity Protocol Foundation
The Integrity Protocol Foundation is a Swiss Stiftung in formation, Canton of Zug. It does not yet legally exist; completing the formation is gating dependency D5 in Section 10 and a prerequisite for first issuance. Once formed, it is intended to operate as an open, non-profit standards body stewarding the DeliveryTag specification. Its mandate is to maintain alignment with EnergyTag on all temporal principles, develop the nodal-extension principles in public working groups, and coordinate pilot deployments with TSOs, hyperscalers, flex-pool operators, and accredited verification bodies. The intended entity structure, fee flows, and governance disclosures are set out in Section 6.4.
Working Groups
Mirroring the EnergyTag WG structure
WG1
Definitions & Principles
Maintains the DeliveryTag specification, coordinates with EnergyTag Secretariat on inherited principles, adjudicates nodal-extension disputes.
WG2
Dispatch Verification
Develops reference methodology for TSO dispatch log ingestion, PTDF matrix validation, and counterfactual LME calculation.
WG3
Registry Interoperability
Ensures DeliveryTag attribute sets are writable to existing EnergyTag-compatible registries (M-RETS, Energinet, GO hubs) without requiring schema forks.
WG4
Market Adoption
Designed for interoperability with market participants and GC infrastructure providers, publishes reference implementations, and maintains the public list of issuing and verification bodies.
Trader Neutrality & Independence
Why a neutral Foundation, not a trader-owned system.
For the DeliveryTag to function as a trusted market standard, the protocol must be operated by an entity structurally independent from energy trading participants. An energy trader that issues, verifies, and trades certificates faces inherent conflicts of interest, the same conflict that undermined confidence in credit-rating agencies before the 2008 financial crisis. The Integrity Protocol Foundation is being chartered as a non-profit (Swiss Stiftung in formation, Canton of Zug) with governance rules designed to prevent any single commercial participant from controlling issuance methodology, verification criteria, or registry access. Dispatch Verification Bodies are selected through an accreditation process managed by WG2, not appointed by market participants.
6.1 Market Defendability: Why Traders Cannot Replicate DeliveryTag
The DeliveryTag system is designed to be structurally unreplicable by energy trading participants. Three independent barriers protect the protocol:
Barrier 1: Conflict of Interest
An energy trader cannot simultaneously be the seller of electrons and the certifier of their delivery. A trader-issued certificate is a self-attestation, not an independent verification. This is the same structural conflict that undermined credit-rating agencies before the 2008 financial crisis: the entity being paid to rate the product has an economic incentive to inflate the rating. Only a structurally independent foundation can issue a DeliveryTag with market credibility; that is the role the Integrity Protocol Foundation is being formed to fill.
Barrier 2: Hardware Installation at Competitor Sites
To replicate the seven-layer forensic sensor stack, a trader would need to install Physical Integrity Nodes (PINs) at their competitors’ facilities. The flex pool in a DeliveryTag deployment includes refineries, steel mills, and factories operated by entities with no commercial relationship to the certifying trader. No industrial operator will grant a rival energy trader physical access to install sealed sensor hardware on their busbar. The PIN network is, by design, only deployable by a neutral foundation.
Barrier 3: Filed IP (Provisional Applications)
Two USPTO provisional applications establish priority over the core methodology:
DSEE (USPTO provisional application 64/023,803): The Demand-Side Emissions Equivalence computation, converting verified load reduction into equivalent renewable capacity using locational marginal emissions.
T-NAC (USPTO provisional application 64/023,364): The Mode B flex-load curtailment swap mechanism (§2), freeing PTDF-weighted corridor capacity through coordinated flex-pool curtailment.
Provisional applications are unexamined and confer no enforceable rights; they establish priority dates ahead of planned non-provisional conversion. If claims are granted, they will be offered under a FRAND (Fair, Reasonable, and Non-Discriminatory) licensing commitment to accredited registry operators and verification bodies. Filed IP is therefore a prospective barrier, contingent on grant; the operative barriers today are the conflict-of-interest constraint and the physical hardware network described in Barriers 1 and 2.
6.2 Protocol Revenue Model
In one metaphor, the DeliveryTag economic model is “electron refining”: in plain terms, the protocol charges a fee for transforming a raw commodity (unattested energy) into an assurance-ready product (a DeliveryTag-verified Granular Certificate). The protocol creates value for participants through distinct mechanisms in US and EU markets.
US Model: Buyer-Premium Driven
US: FROM CONGESTION-CURTAILED ENERGY TO CERTIFIED 24/7 CFE
Stranded Energy
Congestion-curtailed MWh
with no delivery proof
→
DeliveryTag Certification
PTDF + 7-layer validation
+ PQC + Hedera
→
Certified 24/7 CFE
Physics-backed certificate
with buyer premium
The existence and size of a buyer premium for physical certainty — proof of delivery, reduced greenwashing risk, assurance-ready evidence — is the central commercial hypothesis of the US model. It has not yet been validated by transacted volume; testing it through pilot price discovery is a primary objective of the Q4 2026 pilots.
EU Model: Three-Layer Revenue Stack
The EU protocol revenue model comprises three layers that create value for different market participants:
EU: THREE-LAYER PROTOCOL REVENUE STACK
Layer 1
TSO Avoided
Redispatch
Flex curtailment replaces gas peaker activation
+
Layer 2
EU NWA / PCI
Subsidy
Non-Wire Alternative subsidy for virtual transmission
+
Layer 3
24/7 CFE
Buyer Premium
Hourly matching certificate with physical proof
The EU model’s primary revenue source is the TSO avoided redispatch cost. When a gas peaker is activated for redispatch, the TSO bears the full activation cost. DeliveryTag offers an alternative: certified flex-pool curtailment that relieves the same congestion at lower cost, saving the TSO the difference per avoided peaker start. German congestion-management costs illustrate the scale of the underlying cost pool: approximately €4.2B in 2022 (the energy-crisis peak, up from €2.3B in 2021) and roughly €3.1B in 2023 (Bundesnetzagentur monitoring reports / SMARD). Two honesty notes apply. First, this is the TSO’s total cost, not the protocol’s capturable revenue: DeliveryTag would earn only a share of the spread between certified curtailment cost and the avoided activation cost, a fraction of the headline figure. Second, capturing any of it requires TSO procurement of flex-based congestion relief, which is jurisdiction-specific and not yet contracted; sizing that capturable fraction is an explicit objective of the EU pilot.
6.3 Cancellation Tier Economics
The three cancellation tiers (Principle 35) carry different CapEx and OpEx profiles. The figures below are order-of-magnitude production-scale estimates intended for capacity planning; exact prices vary by region, hardware vendor, and assurance-engagement scope.
| TIER |
HARDWARE CAPEX (PER SITE) |
ANNUAL OPEX (PER SITE) |
ASSURANCE COST |
| Tier 1 (Full Seven-Layer) |
S-PIN ~$80k–$120k; D-PIN ~$15k–$25k depending on sensor configuration (Tri-Sensor baseline; optional Thermal layer at the upper end of the range) |
Guardian operation + SAR subscription (S-PIN) + Hedera fees: ~$5k–$15k |
ISAE 3000 reasonable-assurance engagement: scope-dependent, typically $50k–$250k annually per reporter |
| Tier 2 (Attested Meter) |
Existing utility revenue meter (no additional CapEx) |
Guardian operation + Hedera fees: ~$2k–$5k |
Accredited Signer attestation over meter: typically $10k–$40k annually per site |
| Tier 3 (Registry-only) |
None |
Guardian operation + Hedera fees only: <$1k |
Not audit-grade; not applicable for Scope 2 / 24/7 CFE claims |
Illustrative protocol-fee scenario. All fee levels in this section are illustrative scenario parameters, not protocol constants or observed prices. No DeliveryTag has yet been sold; actual fee levels will be set by pilot price discovery (Q4 2026 onward). The scenario assumes a Mode A fee of $1–$8/MWh, a Mode B fee of ~$150/MWh, and an 80/20 uncongested/congested hour split — itself a scenario assumption, since congestion incidence varies widely by corridor. Under those assumptions the issuance-side blended fee is $31–$36/MWh (low case: $1×0.8 + $150×0.2 = $30.80; high case: $8×0.8 + $150×0.2 = $36.40), and it is sensitive to the congestion share: at a 95/5 split the same fee assumptions blend to roughly $8–$15/MWh. Who pays this fee and which entity receives it are set out in Section 6.4.
These levels are a willingness-to-pay hypothesis, not an observed market price. Section 3 records that annual-resolution voluntary REC prices collapsed to €2–5/MWh once the market judged the instrument’s credibility to be limited; a $31–$36/MWh blended fee is roughly an order of magnitude above that level, and the ~$150/MWh Mode B fee is one to two orders of magnitude above it. The argument for why the hypothesis may hold is scarcity and evidentiary value: deliverable node-hour volume is capped by physics (Principle 36), Mode B relief carries a real, oracle-verified curtailment cost that must be compensated, and the certificate is designed to survive assurance scrutiny that annual RECs could not. On the Mode A side, congestion status in uncongested hours is largely observable from public data; the Mode A fee therefore prices the assurance-ready evidence chain (hardware attestation, signer certification, anchored provenance), not congestion detection itself. Whether buyers will pay these levels is precisely what the pilots must establish; the fee schedule will be restated from transacted pilot prices in a subsequent revision.
Tier 1 hardware and assurance costs are cancellation-side and amortise across the reporter’s annual volume. For a hyperscaler data-center campus consuming 500 GWh/year under Tier 1 with a single D-PIN: total additional cancellation cost is on the order of $0.15–$0.60/MWh, roughly two orders of magnitude below the illustrative issuance fee and within the range of existing sustainability-assurance budgets. For smaller reporters below the GHG Protocol Scope 2 exemption threshold, Tier 2 is sufficient and Tier 1 hardware is not required.
Comparison with Battery Storage for 24/7 CFE
| DIMENSION |
BATTERY (BESS) |
DELIVERYTAG™ |
| Mechanism |
Time-shifts clean energy to fill gaps |
Verifies physical delivery + frees corridor capacity via flex curtailment |
| Deployment timeline |
3–5 years |
~6 months |
| CFE score achievable |
~92% |
97%+ (modeled; hourly simulation, methodology available on request) |
| Additionality proof |
None (time-shift only) |
Physical avoidance (seven-layer validated) |
| Audit trail |
Meter data |
PTDF + sensor + PQC + blockchain |
| Complementary use |
Standalone or paired with renewables |
Can be combined with BESS for hybrid architectures |
Technical differentiation.
Battery storage addresses the temporal gap by time-shifting clean energy, while DeliveryTag addresses the spatial gap by providing auditable deliverability evidence at the buyer’s node. The two approaches are complementary: a BESS fills generation shortfalls, and DeliveryTag supports the claim that the energy, whether direct or time-shifted, is deliverable to the consumption point under binding network-flow constraints.
Alignment with the Granular Certificate Ecosystem
The granular-certificate ecosystem (industry bodies, exchanges, and registries that collectively support hourly EAC trading) is building market infrastructure for time- and location-based carbon-free energy trading. DeliveryTag is designed to be natively compatible with the EnergyTag framework: every DeliveryTag certificate is a valid Granular Certificate with an additional nodal attribution and evidentiary attestation layer on top. As the ecosystem scales location-based CFE procurement, DeliveryTag adds an assurance-ready evidence layer that complements existing GC trading.
6.4 Entity Structure & Governance
A neutral non-profit standard cannot also be a fee-earning commercial business without recreating the conflict of interest this protocol exists to eliminate. The intended structure therefore separates two entities with distinct roles. Neither entity is fully constituted as of this publication; the descriptions below are the intended design, subject to formation counsel and final governing documents.
Integrity Protocol Foundation
Swiss Stiftung in formation, Canton of Zug · non-profit steward
Intended role: maintain the DeliveryTag specification and the 38 Principles, run the working groups (WG1–WG4), manage Dispatch Verification Body accreditation, and operate the public pilot index (Principle 29). As a Stiftung it will have no shareholders and cannot issue equity. It is not an investment vehicle. Formation is gating dependency D5 (Section 10); no DeliveryTag can be issued before it legally exists.
Commercial Operating Entity
Intended for-profit company · structure not yet finalized
Intended role: the capital-intensive and service functions — PIN hardware manufacture, deployment, and maintenance; oracle and data operations (dispatch-log ingestion, PTDF validation tooling, the Opportunity Cost Oracle); and issuance-services infrastructure. Its jurisdiction, name, and capital structure have not been finalized as of this publication. Any equity investment in the DeliveryTag effort would be in this operating entity, not the Foundation.
Who Pays, Who Receives
Consistent with the revenue descriptions in Sections 6.2 and 6.3, the intended fee flows are as follows. The issuance-side protocol fee (Mode A and Mode B; illustrative levels in Section 6.3) is charged per certified MWh at issuance and is expected to be borne economically by the certificate buyer, embedded in the price of the DT-verified GC on secondary markets (Section 4.6.2). In the EU model, part of the value pool is instead expected to come from TSO procurement of certified flex-based congestion relief (Section 6.2, Layer 1), where such procurement exists; it is not yet contracted anywhere. Out of the Mode B fee, the oracle-verified curtailment cost is intended to compensate the flex-load operator, with the balance covering verification operations. Cancellation-side costs (Tier hardware, Guardian operation, assurance; Section 6.3) are paid by the reporter, with assurance fees paid directly to the Accredited Signer to preserve signer independence (Section 4.10b).
Under the intended structure, fees for issuance services are received by the operating entity; the Foundation does not sell certificates and takes no per-MWh trading position. How the Foundation’s standards-maintenance work is funded (for example, accreditation fees, membership fees, or a fixed levy on issuance services) has not been finalized and will be settled in the formation documents, under the constraint that the Foundation’s neutrality must not depend on issuance volume.
Governance Disclosures
This document is a technical specification and names no individuals. Founder and advisor identities and credentials, the Foundation’s board composition, formation counsel and the formation date, and the operating entity’s capital plan (raise amount, use of funds, runway) are not disclosed here; they are shared with pilot counterparties and prospective investors through direct engagement (deliverytag.org/contact) and will be published as the formation completes. Nothing in this whitepaper constitutes an offer of securities.