Think Earlier.
The quantum problem starts before the quantum computer arrives.
QCI-QS1
Quantum Readiness and Post-Quantum Cryptography Governance Standard
The authoritative framework for quantum-related cryptographic risk governance, inventory, scoring, and board reporting. Free to download, cite, and adopt.
23 documents, 2.4 MB. No form required.
Executive Summary
Quantum computers will break the cryptographic infrastructure securing digital identity, financial transactions, and confidential communications. The threat is not theoretical. The timeline is real. Organizations that begin migration planning now will spend months doing it. Organizations that wait will spend years: under pressure, at cost, and under scrutiny.
QCI-QS1 defines what organizations must govern, measure, and report to address this risk. It establishes five integrated components: a governance and accountability framework (QRAF), a crypto dependency inventory standard (QASI), a comparable readiness scoring method (Q-Risk Score), a vendor roadmap request pack for third-party crypto risk, and a governing-body briefing insert for quarterly oversight. Clause 1 governs conformance claims and distinguishes self-assessment from independent assessment.
Version 2.3 fixes a single scoring profile, requires 95 percent validated coverage of both critical systems and critical data flows, removes the exception route through the supplier gate, moves the Defensible readiness band to 81 to 100, and gives every requirement a stable QCI identifier. Scores from earlier editions are not directly comparable without restatement.
This standard is designed to be citeable by auditors, referenced in risk registers, and presented to boards. It is free, complete, and carries no strings. The organizations that adopt it early will be the ones regulators and peers point to when the timeline compresses.
How QCI helps
Independent assessment
An assessed Q-Risk Score under Clause 1, based on the evidence your program holds.
Supplier attestation round
We collect and test critical supplier evidence against G70. Defined scope, 60-day clock.
90-day establishment program
Governance, inventory and board reporting set up to the standard, in sequence.
Start here
One document for your role. The rest can wait.
Board member
Annex D, Governing body insert template
then QCI-P1, Independent Assessment
OpenCISO or Quantum Risk Owner
Practitioner Handbook, chapter 2
The 90-day establishment sequence
OpenProcurement
Annex C, Vendor roadmap request pack
then QCI-QS1-C2, Remediation and Migration Providers
OpenAuditor or assessor
QCI-P1, Independent Assessment
then QCI-T1, Discovery Evidence Acceptance Checklist
OpenStandards Index
Current publication status of all QCI governance standards and supplements.
| Document | Version | Status | Last Updated | Actions |
|---|---|---|---|---|
| Core Standard & Companions | ||||
QCI-QS1 Quantum Readiness and Post-Quantum Cryptography Governance Standard | v2.3 | Active | September 23, 2026 | |
QCI-QS1 v2.2 Superseded, retained for edition transition under QCI-1.3-01 | v2.2 | Superseded | June 8, 2026 | |
QCI Practitioner Handbook Practitioner Handbook: Calibration, Agility Test and Establishment Sequence | V2.3 | Active | September 23, 2026 | |
| Sector Supplements (US) | ||||
QCI-QS1-S1 Financial Institutions Supplement | v1.2 | Active | September 23, 2026 | |
QCI-QS1-S2 Healthcare Supplement | v1.2 | Active | September 23, 2026 | |
QCI-QS1-S3 State & Local Government Supplement | v1.2 | Active | September 23, 2026 | |
QCI-QS1-S4 Critical Infrastructure Supplement | v1.2 | Active | September 23, 2026 | |
QCI-QS1-S5 Insurance Carrier Supplement | v1.2 | Active | September 23, 2026 | |
| Regional Supplements (EU) | ||||
QCI-QS1-S6 EU Financial Entities: DORA Alignment | v1.2 | Active | September 23, 2026 | |
QCI-QS1-S7 EU Critical Infrastructure: NIS2 Alignment | v1.2 | Active | September 23, 2026 | |
QCI-QS1-S8 EU Digital Identity Wallet: eIDAS 2.0 Alignment | v1.1 | Active | September 23, 2026 | |
| Position Notes | ||||
QCI-PN-01 Position Note: Quantum Key Distribution (QKD) | v1.1 | Active | September 23, 2026 | |
| Methods & Assessment | ||||
QCI-M1 Migration Governance Method: Governing post-quantum migration across every cryptographic domain | v1.0 | Active | September 23, 2026 | |
QCI-P1 Independent Assessment under QCI-QS1: What an independently assessed result means | v1.0 | Active | September 23, 2026 | |
QCI-R1 Post-Quantum Capability Register: Specification, inclusion criteria and listing format | v1.0 | Active | September 23, 2026 | |
| Instruments | ||||
QCI-T1 Discovery Evidence Acceptance Checklist | v1.0 | Active | September 23, 2026 | |
QCI-T2 Crypto Agility Test and Acceptance Protocol | v1.0 | Active | September 23, 2026 | |
QCI-T3 Exception Register Template | v1.0 | Active | September 23, 2026 | |
QCI-T4 Decision Record Template | v1.0 | Active | September 23, 2026 | |
| Companion Handouts Handouts list options by cryptographic domain without ranking them. Inclusion is not endorsement and conformance depends on no tool or provider. | ||||
QCI-QS1-C1 Cryptographic Discovery Tools | v1.0 | Active | September 23, 2026 | |
QCI-QS1-C2 PQC Remediation and Migration Providers | v1.0 | Active | September 23, 2026 | |
QCI-QS1-C3 Sector-Specific Protocols | v1.0 | Active | September 23, 2026 | |
QCI-QS1-C4 AI Systems and Agent Channels | v1.0 | Active | September 23, 2026 | |
QCI-QS1-C5 Identity and the Double Migration | v1.0 | Active | September 23, 2026 | |
Change Log
Version history for all published standards and supplements.
QCI-QS1 v2.3 published. Fixed Core scoring profile; gate G60 requires 95 percent validated coverage of critical systems and critical flows; gate G70 no longer satisfied by a registered exception; Defensible readiness band moved to 81 to 100; stable QCI requirement identifiers for every requirement; approved cryptographic profiles, key and trust lifecycle, and migration test and acceptance requirements added; obligations register required; human and workload identity inventoried separately; Annex G thirteen-domain cryptographic taxonomy added. Edition transition rules in Clause 1.3. v2.2 retained as Superseded.
QCI Practitioner Handbook V2.3 published. All references corrected to QCI requirement identifiers; chapters on scoring and the crypto agility test rewritten for the v2.3 gates; worked QASI examples restated with confidentiality and verification horizons; new chapters 13 (Selecting tools and providers) and 14 (Governing the migration across domains).
Sector supplements S1 to S7 refreshed to v1.2 and S8 to v1.1, aligned to QCI-QS1 v2.3: requirement identifiers, obligations register entries, flow coverage, the 81-point band, gate G70 consequences by sector, and vendor status tables reviewed against supplier publications as of September 23, 2026. S4 recasts IT and OT as two assessment boundaries. S5 treats reinsurers on critical flows as critical suppliers.
QCI-PN-01 QKD Position Note v1.1 published, aligned to v2.3: crypto-agility reference corrected to gate G80 and QCI-4.7; position relative to approved cryptographic profiles added. Position unchanged.
New public documents published: QCI-M1 Migration Governance Method; QCI-P1 Independent Assessment overview; QCI-R1 Capability Register specification; instruments QCI-T1 to T4; companion handouts QCI-QS1-C1 to C5.
QCI-QS1-S8 EU Digital Identity Wallet Supplement v1.0 published, mapping QCI-QS1 to eIDAS 2.0, the EUDI Wallet architecture, and the EU Coordinated PQC Roadmap.
QCI-PN-01 Position Note published: Quantum Key Distribution is not a substitute for post-quantum cryptography and not a quantum-readiness action under QCI-QS1. Free to download and cite.
Regulatory Radar QKD Addendum v1.0 published: Tier 5 (NSA, NCSC, EU agency guidance) and Tier 6 (EU quantum-communication initiatives) entries added, both classifying QKD as excluded from QCI-QS1 readiness actions.
QCI Practitioner Handbook v2.2 published: aligned to QCI-QS1 v2.2 with identity inventory worksheets alongside the 90-day establishment sequence.
All seven sector supplements (S1–S7) refreshed to v1.1 with updated regulatory mappings and vendor guidance.
QCI-QS1 v2.2 published. Updated governance components, QASI guidance, and Q-Risk scoring refinements.
QCI-QS1 v2.1 published as Active standard. Comprehensive governance framework covering QRAF, QASI, Q-Risk Score, Vendor Oversight, and Board Reporting.
Ready to Implement the Standard?
Get expert guidance on adopting QCI-QS1, from governance setup to board reporting and sector-specific compliance mapping.