How this is measured, and what it refuses to say.

The ladder is not a score

A single grade is comparable but opaque; separate axes are honest but do not travel. A ladder is both — Stage 1 fits in a memo, and every requirement behind it stays a binary question a stranger can re-check.

Stage 0 — The gate is observable.

Stage 1 — Credential substance is checked and the terms are stated.

Stage 2 — Refusals are durable and exit is proven.

The rules this obeys

no stage is not stage zero. A token whose gate could not be observed gets NO STAGE. Stage 0 is an achievement; 'we could not look' is not.
unknown blocks a stage. An unknown requirement blocks the stage exactly as a failure does, but is reported separately, because they are different facts.
out of scope excluded. Plain ERC-20s are listed and ungraded. They never claimed the standard, and counting them would inflate every ratio.
the ruler is graded too. Each vector carries its own grade — observed on live data, and under fault injection. A vector never shown able to fail is labelled, not hidden.
rows are not coverage. Rows count deployments; implementations count distinct code. Most of these tokens come from a factory, so a passing row is evidence about one contract repeated, not about many.
fabrication is disclosed. Where a gate could only be driven by fabricating a BALANCE on a local fork for an address that already held a real A-Pass, the row says so. A credential was never fabricated. A reader who distrusts the method can discard exactly those rows.
networks are named exactly. Every network is named from the chain id the sweep recorded. These are testnets, and the table says so, because 'Base' and 'Base Sepolia' are not interchangeable claims.

What this cannot tell you