Cookie Preferences

    We use cookies to ensure our website functions properly and to improve your experience. Essential cookies are always active. You can choose to enable other categories below. Review our cookie policy

    Published Standard, v2.3

    Think Earlier.

    The quantum problem starts before the quantum computer arrives.

    QCI-QS1

    Quantum Readiness and Post-Quantum Cryptography Governance Standard

    The authoritative framework for quantum-related cryptographic risk governance, inventory, scoring, and board reporting. Free to download, cite, and adopt.

    Document QCI-QS1Version 2.3Status ActiveEffective September 23, 2026

    23 documents, 2.4 MB. No form required.

    Executive Summary

    Quantum computers will break the cryptographic infrastructure securing digital identity, financial transactions, and confidential communications. The threat is not theoretical. The timeline is real. Organizations that begin migration planning now will spend months doing it. Organizations that wait will spend years: under pressure, at cost, and under scrutiny.

    QCI-QS1 defines what organizations must govern, measure, and report to address this risk. It establishes five integrated components: a governance and accountability framework (QRAF), a crypto dependency inventory standard (QASI), a comparable readiness scoring method (Q-Risk Score), a vendor roadmap request pack for third-party crypto risk, and a governing-body briefing insert for quarterly oversight. Clause 1 governs conformance claims and distinguishes self-assessment from independent assessment.

    Version 2.3 fixes a single scoring profile, requires 95 percent validated coverage of both critical systems and critical data flows, removes the exception route through the supplier gate, moves the Defensible readiness band to 81 to 100, and gives every requirement a stable QCI identifier. Scores from earlier editions are not directly comparable without restatement.

    This standard is designed to be citeable by auditors, referenced in risk registers, and presented to boards. It is free, complete, and carries no strings. The organizations that adopt it early will be the ones regulators and peers point to when the timeline compresses.

    QCI-QS1 defines the requirements. The QCI Practitioner Handbook V2.3, the public practitioner companion, provides the 90-day establishment sequence, scoring calibration, the crypto agility test, worked inventory examples, and new chapters on selecting tools and governing migration across domains to get your program started. Organizations requiring assessment support should contact QCI to discuss an engagement.

    How QCI helps

    Book a scoping conversation

    Start here

    One document for your role. The rest can wait.

    Standards Index

    Current publication status of all QCI governance standards and supplements.

    DocumentVersionStatusLast UpdatedActions
    Core Standard & Companions

    QCI-QS1

    Quantum Readiness and Post-Quantum Cryptography Governance Standard

    v2.3ActiveSeptember 23, 2026

    QCI-QS1 v2.2

    Superseded, retained for edition transition under QCI-1.3-01

    v2.2SupersededJune 8, 2026

    QCI Practitioner Handbook

    Practitioner Handbook: Calibration, Agility Test and Establishment Sequence

    V2.3ActiveSeptember 23, 2026
    Sector Supplements (US)

    QCI-QS1-S1

    Financial Institutions Supplement

    v1.2ActiveSeptember 23, 2026

    QCI-QS1-S2

    Healthcare Supplement

    v1.2ActiveSeptember 23, 2026

    QCI-QS1-S3

    State & Local Government Supplement

    v1.2ActiveSeptember 23, 2026

    QCI-QS1-S4

    Critical Infrastructure Supplement

    v1.2ActiveSeptember 23, 2026

    QCI-QS1-S5

    Insurance Carrier Supplement

    v1.2ActiveSeptember 23, 2026
    Regional Supplements (EU)

    QCI-QS1-S6

    EU Financial Entities: DORA Alignment

    v1.2ActiveSeptember 23, 2026

    QCI-QS1-S7

    EU Critical Infrastructure: NIS2 Alignment

    v1.2ActiveSeptember 23, 2026

    QCI-QS1-S8

    EU Digital Identity Wallet: eIDAS 2.0 Alignment

    v1.1ActiveSeptember 23, 2026
    Position Notes

    QCI-PN-01

    Position Note: Quantum Key Distribution (QKD)

    v1.1ActiveSeptember 23, 2026
    Methods & Assessment

    QCI-M1

    Migration Governance Method: Governing post-quantum migration across every cryptographic domain

    v1.0ActiveSeptember 23, 2026

    QCI-P1

    Independent Assessment under QCI-QS1: What an independently assessed result means

    v1.0ActiveSeptember 23, 2026

    QCI-R1

    Post-Quantum Capability Register: Specification, inclusion criteria and listing format

    v1.0ActiveSeptember 23, 2026
    Instruments

    QCI-T1

    Discovery Evidence Acceptance Checklist

    v1.0ActiveSeptember 23, 2026

    QCI-T2

    Crypto Agility Test and Acceptance Protocol

    v1.0ActiveSeptember 23, 2026

    QCI-T3

    Exception Register Template

    v1.0ActiveSeptember 23, 2026

    QCI-T4

    Decision Record Template

    v1.0ActiveSeptember 23, 2026
    Companion Handouts

    Handouts list options by cryptographic domain without ranking them. Inclusion is not endorsement and conformance depends on no tool or provider.

    QCI-QS1-C1

    Cryptographic Discovery Tools

    v1.0ActiveSeptember 23, 2026

    QCI-QS1-C2

    PQC Remediation and Migration Providers

    v1.0ActiveSeptember 23, 2026

    QCI-QS1-C3

    Sector-Specific Protocols

    v1.0ActiveSeptember 23, 2026

    QCI-QS1-C4

    AI Systems and Agent Channels

    v1.0ActiveSeptember 23, 2026

    QCI-QS1-C5

    Identity and the Double Migration

    v1.0ActiveSeptember 23, 2026

    Change Log

    Version history for all published standards and supplements.

    September 23, 2026

    QCI-QS1 v2.3 published. Fixed Core scoring profile; gate G60 requires 95 percent validated coverage of critical systems and critical flows; gate G70 no longer satisfied by a registered exception; Defensible readiness band moved to 81 to 100; stable QCI requirement identifiers for every requirement; approved cryptographic profiles, key and trust lifecycle, and migration test and acceptance requirements added; obligations register required; human and workload identity inventoried separately; Annex G thirteen-domain cryptographic taxonomy added. Edition transition rules in Clause 1.3. v2.2 retained as Superseded.

    September 23, 2026

    QCI Practitioner Handbook V2.3 published. All references corrected to QCI requirement identifiers; chapters on scoring and the crypto agility test rewritten for the v2.3 gates; worked QASI examples restated with confidentiality and verification horizons; new chapters 13 (Selecting tools and providers) and 14 (Governing the migration across domains).

    September 23, 2026

    Sector supplements S1 to S7 refreshed to v1.2 and S8 to v1.1, aligned to QCI-QS1 v2.3: requirement identifiers, obligations register entries, flow coverage, the 81-point band, gate G70 consequences by sector, and vendor status tables reviewed against supplier publications as of September 23, 2026. S4 recasts IT and OT as two assessment boundaries. S5 treats reinsurers on critical flows as critical suppliers.

    September 23, 2026

    QCI-PN-01 QKD Position Note v1.1 published, aligned to v2.3: crypto-agility reference corrected to gate G80 and QCI-4.7; position relative to approved cryptographic profiles added. Position unchanged.

    September 23, 2026

    New public documents published: QCI-M1 Migration Governance Method; QCI-P1 Independent Assessment overview; QCI-R1 Capability Register specification; instruments QCI-T1 to T4; companion handouts QCI-QS1-C1 to C5.

    September 10, 2026

    QCI-QS1-S8 EU Digital Identity Wallet Supplement v1.0 published, mapping QCI-QS1 to eIDAS 2.0, the EUDI Wallet architecture, and the EU Coordinated PQC Roadmap.

    June 10, 2026

    QCI-PN-01 Position Note published: Quantum Key Distribution is not a substitute for post-quantum cryptography and not a quantum-readiness action under QCI-QS1. Free to download and cite.

    June 10, 2026

    Regulatory Radar QKD Addendum v1.0 published: Tier 5 (NSA, NCSC, EU agency guidance) and Tier 6 (EU quantum-communication initiatives) entries added, both classifying QKD as excluded from QCI-QS1 readiness actions.

    June 2026

    QCI Practitioner Handbook v2.2 published: aligned to QCI-QS1 v2.2 with identity inventory worksheets alongside the 90-day establishment sequence.

    June 10, 2026

    All seven sector supplements (S1–S7) refreshed to v1.1 with updated regulatory mappings and vendor guidance.

    June 8, 2026

    QCI-QS1 v2.2 published. Updated governance components, QASI guidance, and Q-Risk scoring refinements.

    February 2, 2026

    QCI-QS1 v2.1 published as Active standard. Comprehensive governance framework covering QRAF, QASI, Q-Risk Score, Vendor Oversight, and Board Reporting.

    Ready to Implement the Standard?

    Get expert guidance on adopting QCI-QS1, from governance setup to board reporting and sector-specific compliance mapping.