QCI-QS1
Quantum Readiness and Post-Quantum Cryptography Governance Standard
The authoritative framework for quantum-related cryptographic risk governance, inventory, scoring, and board reporting. Free to download, cite, and adopt.
Executive Summary
Quantum computers will break the cryptographic infrastructure securing digital identity, financial transactions, and confidential communications. The threat is not theoretical. The timeline is real. Organizations that begin migration planning now will spend months doing it. Organizations that wait will spend years — under pressure, at cost, and under scrutiny.
QCI-QS1 defines what organizations must govern, measure, and report to address this risk. It establishes six integrated components: a governance and accountability framework (QRAF), a crypto dependency inventory standard (QASI), a comparable readiness scoring method (Q-Risk Score), a vendor roadmap request pack for third-party crypto risk, a board briefing insert for quarterly oversight, and conformance clauses for audit and compliance use.
This standard is designed to be citeable by auditors, referenced in risk registers, and presented to boards. It is free, complete, and carries no strings. The organizations that adopt it early will be the ones regulators and peers point to when the timeline compresses.
Standards Index
Current publication status of all QCI governance standards and supplements.
| Document | Version | Status | Last Updated | Actions |
|---|---|---|---|---|
QCI-QS1 Quantum Readiness and Post-Quantum Cryptography Governance Standard | v2.2 | Active | June 8, 2026 | |
QCI Practitioner Handbook Practitioner Handbook (QCI-QRMS-1A) | v2.2 | Active | June 11, 2026 | |
QCI-QS1-S1 Financial Institutions Supplement | v1.1 | Active | June 10, 2026 | |
QCI-QS1-S2 Healthcare Supplement | v1.1 | Active | June 10, 2026 | |
QCI-QS1-S3 State & Local Government Supplement | v1.1 | Active | June 10, 2026 | |
QCI-QS1-S4 Critical Infrastructure Supplement | v1.1 | Active | June 10, 2026 | |
QCI-QS1-S5 Insurance Carrier Supplement | v1.1 | Active | June 10, 2026 | |
QCI-QS1-S6 EU Financial Entities — DORA Alignment | v1.1 | Active | June 10, 2026 | |
QCI-QS1-S7 EU Critical Infrastructure — NIS2 Alignment | v1.1 | Active | June 10, 2026 |
Change Log
Version history for all published standards and supplements.
All seven sector supplements (S1–S7) refreshed to v1.1 with updated regulatory mappings and vendor guidance.
QCI-QS1 v2.2 published. Updated governance components, QASI guidance, and Q-Risk scoring refinements.
QCI-QS1 v2.1 published as Active standard. Comprehensive governance framework covering QRAF, QASI, Q-Risk Score, Vendor Oversight, and Board Reporting.
QCI Practitioner Handbook v2.2 published — refreshed 90-day establishment sequence, expanded scoring worksheets, and updated inventory examples.
Ready to Implement the Standard?
Get expert guidance on adopting QCI-QS1 — from governance setup to board reporting and sector-specific compliance mapping.