QCI-QS1 vs DORA Compliance
How the QCI-QS1 standard satisfies DORA's ICT risk management and digital operational resilience mandates
The EU Digital Operational Resilience Act (DORA) has been enforceable since 17 January 2025. It sets binding ICT risk management, testing, incident reporting, and third-party oversight requirements for financial entities operating in the EU — including banks, payment institutions, insurers, and investment firms. QCI-QS1 is the free, citeable standard for governing the quantum cryptographic slice of that risk. This guide maps QCI-QS1 sections to the DORA articles they directly support.
DORA at a glance
Regulation (EU) 2022/2554. Applies to ~22,000 financial entities and their critical ICT third-party providers.
Five pillars: ICT risk management, incident reporting, digital operational resilience testing, third-party risk, information sharing.
Supervised by the ESAs (EBA, ESMA, EIOPA) and national competent authorities. Non-compliance can result in supervisory measures and administrative penalties.
QCI-QS1 at a glance
Free, published standard for quantum-related cryptographic risk governance. Six integrated components across Sections 4–8.
Provides a five-pillar 0–100 Q-Risk Score with hard ceiling rules that prevent score inflation, plus a normative cryptographic inventory (QASI) and vendor attestation pack.
Designed to plug into existing ICT risk frameworks — not to replace them. Cited by risk teams and auditors mapping quantum exposure into DORA, NIS2, and NCUA programs.
DORA requirement → QCI-QS1 component
| DORA requirement | QCI-QS1 evidence |
|---|---|
| Art. 5 — ICT Risk Management Framework: governance, accountable roles, board approval, documented policies. | QRAF (Section 4): named roles, decision rights, mandatory artifacts, escalation triggers, exception handling. |
| Art. 8 — Identification: continuous inventory of ICT assets, dependencies, and cryptographic controls tied to critical/important functions. | QASI (Section 5): normative inventory fields — algorithms, data longevity, key management, vendor dependencies, PQC status, crypto agility. Prerequisite for scores above 60. |
| Art. 6 & 13 — Digital operational resilience testing and continuous improvement based on measured posture. | Q-Risk Score (Section 6): five-pillar 0–100 measurement with hard ceilings preventing score inflation; enables year-over-year trending and audit-ready evidence. |
| Art. 28–30 — Third-party ICT risk: register of information, contractual controls, subcontracting oversight, exit strategies. | Vendor Roadmap Request Pack (Section 7): standardized supplier questionnaire, officer-signed attestations, exception handling normative to QCI-QS1. |
| Art. 5(2) & 17 — Management-body accountability: board-level reporting on ICT risk and incidents. | Board Briefing Insert (Section 8): required one-page quarterly artifact — current score, delta, top exposures, vendor readiness, decisions requested. |
| Art. 9 & 16 — Protection and prevention: cryptographic controls appropriate to the risk of the ICT service. | Crypto agility ceiling (Q-Risk pillar 5): demonstrated ability to rotate algorithms without service disruption required for scores above 80. |
What DORA does that QCI-QS1 does not
DORA is a legally binding EU regulation covering the full ICT risk surface — incident classification and mandatory reporting timelines, threat-led penetration testing (TLPT), and a Union-level oversight regime for Critical Third-Party Providers.
QCI-QS1 does not attempt to replicate those horizontal ICT-risk mechanics. It sits inside them, providing the quantum-specific evidence that DORA's Article 5 and Article 8 obligations increasingly require regulators to see.
What QCI-QS1 does that DORA does not
DORA does not prescribe how to measure quantum cryptographic exposure, how to inventory algorithms and key lifetimes, or when to defer a PQC migration.
QCI-QS1 supplies the missing artifacts: a normative cryptographic inventory (QASI), a comparable 0–100 Q-Risk Score with hard ceilings, a vendor request pack for third-party attestations, and a one-page board briefing insert designed to attach to the existing quarterly risk pack.
Using QCI-QS1 inside a DORA program
- Map roles. Assign the QCI-QS1 QRAF roles inside your existing DORA governance structure — no parallel committee required.
- Extend the ICT inventory. Add QASI fields to the DORA Article 8 asset inventory so cryptographic dependencies are captured alongside other ICT assets.
- Score and trend. Run the Q-Risk Score quarterly and attach the delta to the board pack alongside your DORA testing outcomes.
- Cascade to vendors. Issue the Vendor Roadmap Request Pack to ICT third-party providers already in scope of the DORA register of information.
- Report up. Use the one-page Board Briefing Insert as the quantum-risk section of the management body's DORA update.
Ready to align QCI-QS1 with your DORA program?
Measure your current Q-Risk posture, then use QCI-QS1 to produce the artifacts DORA reviewers expect to see for cryptographic risk.
Related Resources
QCI-QS1 Standard
The full published standard: QRAF, QASI, Q-Risk Score, Vendor Pack, Board Insert.
Financial Services
Sector-specific quantum readiness guidance for banks and payment institutions.
Regulatory Radar
Track DORA, NIS2, NCUA, and other quantum-relevant regulatory developments.
Quantum Compliance
How QCI-QS1 maps across SOC 2, ISO, HIPAA, DORA, and NIS2.