Governance

    QCI-QS1 governance FAQ

    Common questions about applying QCI-QS1: who it applies to, how the Q-Risk Score and its gates work, what the standard does and does not determine for compliance, and who can perform an independent assessment.

    Go to the QCI-QS1 standard page

    The standard

    QCI-QS1 is QCI's published quantum readiness and post-quantum cryptography governance standard. The current edition is v2.3, effective September 23, 2026. It defines governance roles, a cryptographic inventory (QASI), the Q-Risk Score, supplier requirements, and board reporting. It is free to download, cite, and adopt. Read the QCI-QS1 standard page.

    Any organization that stores long-lived confidential data or runs systems that depend on cryptography. Scope is not limited to large enterprises. Sector supplements (S1 through S7) tailor the requirements for financial institutions, healthcare providers, state and local government, and other sectors. The supplements are listed on the standards index.

    No. QCI-QS1 is a voluntary governance standard. Whether to comply is a decision for your organization, your board, or your regulator. The requirements are written so the artifacts they produce — an inventory, supplier attestations, board reporting — are the same artifacts regulators and auditors already ask for. See how QCI-QS1 aligns with standards and regulation.

    The standard itself, the practitioner handbook, and seven sector supplements. The standards index on the QCI-QS1 page lists each document with its version, status, and download.

    The current edition is v2.3. Older editions remain available and are labeled “Superseded.” Conformance claims name the edition they were made against, so keep the edition you scored with archived. Score new assessments against the current edition.

    Scoring and gates

    The Q-Risk Score is a 0 to 100 measure of quantum readiness defined in QCI-QS1. It combines five pillars weighted 20, 20, 20, 25 and 15 percent. Three gates then cap the result: 60 without inventory coverage of at least 95%, 70 without supplier evidence, and 80 without a crypto-agility test in the last 12 months. The score is not a certificate (QCI-1.2-04). Full explanation of the Q-Risk Score.

    Only where its entire subject population is demonstrably absent and that absence is independently checked. Weight is not redistributed, and no 0–100 total or band is published while a pillar is not applicable (QCI-6.1-03).

    G60 requires at least 95 percent validated coverage of both critical systems and critical flows, with no unresolved material population discrepancy. G70 requires current roadmap responses and authorized, officer-level attestations for every critical supplier, with no exception substitute. G80 requires a representative critical trust-path agility test within 12 months. Each gate caps the Q-Risk Score until its evidence is in place: G60, G70, G80.

    Scores of 81 to 100 fall in the Defensible band. The standard's logic matters more than the number: a lower score with a documented, evidenced plan is a governance success; an undocumented gap that surfaces in an incident is the failure. The scoring guide lists every band and how the gates cap the result.

    A self-assessed score reflects your own answers. A validated score is confirmed by evidence reviewed under the standard's conformance definitions. Conformance claims state which kind they are, so an auditor or a counterparty can tell the difference. The QCI-QS1 Conformance Review is the validated path.

    Compliance and assurance

    No. The score is not a compliance determination (QCI-1.2-04). It measures readiness, and the gates cap it. A high score supports governance and conformance claims; it does not certify your organization against any law or framework.

    The regulatory alignment guide maps the Q-Risk pillars to each framework. The practical point: artifacts produced under QCI-QS1 — the QASI inventory, supplier attestations, agility test results, and board inserts — are the same evidence those frameworks ask for, so one body of work serves both.

    QCI performs Independent Assessments, and so do assessors licensed under the QCI Assessor Program. Licensing requires passing the program exam, completing a supervised assessment, and meeting the program's licensing requirements. The assessor register lists currently licensed assessors. About the Independent Assessment.

    No. QCI does not issue an independent determination on its own readiness or implementation work. This holds even after the 12-month cooling-off period that follows QCI engagement work. If your engagement involved QCI's readiness or implementation work, plan for the determination to come from an assessor who was not part of that work.

    The artifacts the standard already requires: the QASI inventory with validated coverage, supplier attestations, agility test results, and board inserts. The audit evidence guide sets out what auditors should expect to see.

    Governance and cadence

    A one-page quarterly board insert tied to the Q-Risk Score (QCI-QS1 Section 8). It carries the current score and delta since last quarter, QASI coverage percentage, the top three exposures, vendor readiness status and exceptions, completed and planned actions, and any requests for board decisions or risk acceptance. It is designed to attach to your existing quarterly risk pack, not replace it. How to write the board report.

    Two cadences are built into the standard: the quarterly board insert, and the 12-month window on the G80 agility test. Beyond those, re-run the assessment when your posture changes materially — the score describes the state you evidenced on the day you measured it.

    Start with our free Q-Risk Score assessment to understand your current posture. From there, QCI consultants can recommend the appropriate program tier based on your organization's size, industry, and risk profile. Schedule a consultation to begin.