Credentials arrive and L4 becomes reachable. Because you wrapped the official library rather than writing your own crypto, this is an integration-hardening window — not a three-month project.
- Import the real client ID, HMAC and AES material, and the
.p12 keystores. Point at production base URLs.
- Complete Security Server registration: submit CSRs, import and activate certificates, register the subsystem, await approval.
- F14 verify.gov.kh · F15 assurance mapping finalised against what CamDigiKey actually returns.
- F27 Signed and encrypted payloads — mandatory now, because government-derived claims are flowing to third parties.
- Recovery tier three: L4 users re-verify through CamDigiKey. L4 TTLs set from risk, fail-closed enforced.
Size the hardening honestly. Without development credentials your simulator encodes your reading of the documentation — your client and simulator can share the same misreading while every test passes. Wrapping the published library removes most of that risk, but first contact with production is still where you learn what the payloads really look like.
Done when An L4 badge exists that was granted by an authorised adapter and could never have been granted by a mock.