Cookie Preferences

    We use cookies to ensure our website functions properly and to improve your experience. Essential cookies are always active. You can choose to enable other categories below. Learn more

    Published Standard — v2.2

    QCI-QS1

    Quantum Readiness and Post-Quantum Cryptography Governance Standard

    The authoritative framework for quantum-related cryptographic risk governance, inventory, scoring, and board reporting. Free to download, cite, and adopt.

    Document QCI-QS1Version 2.2Status ActiveEffective June 8, 2026
    Download Standard

    Executive Summary

    Quantum computers will break the cryptographic infrastructure securing digital identity, financial transactions, and confidential communications. The threat is not theoretical. The timeline is real. Organizations that begin migration planning now will spend months doing it. Organizations that wait will spend years — under pressure, at cost, and under scrutiny.

    QCI-QS1 defines what organizations must govern, measure, and report to address this risk. It establishes six integrated components: a governance and accountability framework (QRAF), a crypto dependency inventory standard (QASI), a comparable readiness scoring method (Q-Risk Score), a vendor roadmap request pack for third-party crypto risk, a board briefing insert for quarterly oversight, and conformance clauses for audit and compliance use.

    This standard is designed to be citeable by auditors, referenced in risk registers, and presented to boards. It is free, complete, and carries no strings. The organizations that adopt it early will be the ones regulators and peers point to when the timeline compresses.

    QCI-QS1 defines the requirements. The QCI Practitioner Handbook v2.2, the public practitioner companion, provides the 90-day establishment sequence, scoring worksheets, and anonymized inventory examples to get your program started. Organizations requiring assessment support should contact QCI to discuss an engagement.

    Standards Index

    Current publication status of all QCI governance standards and supplements.

    DocumentVersionStatusLast UpdatedActions

    QCI-QS1

    Quantum Readiness and Post-Quantum Cryptography Governance Standard

    v2.2ActiveJune 8, 2026

    QCI Practitioner Handbook

    Practitioner Handbook (QCI-QRMS-1A)

    v2.2ActiveJune 11, 2026

    QCI-QS1-S1

    Financial Institutions Supplement

    v1.1ActiveJune 10, 2026

    QCI-QS1-S2

    Healthcare Supplement

    v1.1ActiveJune 10, 2026

    QCI-QS1-S3

    State & Local Government Supplement

    v1.1ActiveJune 10, 2026

    QCI-QS1-S4

    Critical Infrastructure Supplement

    v1.1ActiveJune 10, 2026

    QCI-QS1-S5

    Insurance Carrier Supplement

    v1.1ActiveJune 10, 2026

    QCI-QS1-S6

    EU Financial Entities — DORA Alignment

    v1.1ActiveJune 10, 2026

    QCI-QS1-S7

    EU Critical Infrastructure — NIS2 Alignment

    v1.1ActiveJune 10, 2026

    Change Log

    Version history for all published standards and supplements.

    June 10, 2026

    All seven sector supplements (S1–S7) refreshed to v1.1 with updated regulatory mappings and vendor guidance.

    June 8, 2026

    QCI-QS1 v2.2 published. Updated governance components, QASI guidance, and Q-Risk scoring refinements.

    February 2, 2026

    QCI-QS1 v2.1 published as Active standard. Comprehensive governance framework covering QRAF, QASI, Q-Risk Score, Vendor Oversight, and Board Reporting.

    June 11, 2026

    QCI Practitioner Handbook v2.2 published — refreshed 90-day establishment sequence, expanded scoring worksheets, and updated inventory examples.

    Ready to Implement the Standard?

    Get expert guidance on adopting QCI-QS1 — from governance setup to board reporting and sector-specific compliance mapping.