Quantum Risk Knowledge Center
Short, sourced explanations of quantum risk and how organizations prepare for it. Pages about QCI-QS1 cite the requirements they rely on; the standard itself stays the edition of record. No sign-in is needed.
New to quantum risk? Start here
Reading paths
Read these in order. Further steps are added as their pages are published.
Beginner path
From what readiness means to the first roadmap.
Board path
What directors oversee, ask and receive.
Technical path
From vulnerable cryptography to tested change.
Procurement path
From supplier readiness to contract terms.
By role
Board members
Risk and compliance
Technical leads
Topics
Fundamentals
The core ideas behind quantum risk: what is exposed, why timing matters and which cryptography is affected.
1 published page
QCI-QS1 scoring: pillars and gates
How the five Q-Risk pillars are levelled and how the G60, G70 and G80 gates cap the final score under QCI-QS1 v2.3.
10 published pages
Cryptographic inventory
How organizations find, record and keep current the cryptography their critical systems and data flows rely on.
1 published page
Migration and crypto agility
How organizations plan, test and accept the move to post-quantum cryptography, and prove they can change cryptography again.
7 published pages
Suppliers and procurement
How to assess supplier post-quantum readiness, what to ask vendors and what a supplier attestation should contain.
5 published pages
Governance and assurance
What boards should ask, what a board report contains and what evidence auditors should expect.
5 published pages
Standards and regulation
Post-quantum cryptography standards, NIST transition guidance and how QCI-QS1 relates to legal obligations.
3 published pages
All published pages
Showing 32 of 32 published pages.
- DefinitionFundamentals
What is Harvest Now, Decrypt Later?
Why encrypted data captured today can be exposed later, and which data that matters for.
- DefinitionQCI-QS1 scoring: pillars and gates
What is QCI-QS1?
The standard of record: scope, conformance, scoring, supplier oversight and governing-body reporting.
- DefinitionQCI-QS1 scoring: pillars and gates
Q-Risk Score and how scoring gates work
What the 0–100 Q-Risk Score measures, how it is calculated and what it does not mean.
- ImplementationQCI-QS1 scoring: pillars and gates
Pillar 1: Governance and accountability
P1 measures whether quantum risk has named owners, approved policy, a working quarterly cycle and governing-body oversight. It carries 20 of the 100 points (4 points per level).
- ImplementationQCI-QS1 scoring: pillars and gates
Pillar 2: Crypto visibility and QASI completeness
P2 measures how much of the critical population has validated cryptographic inventory records. Coverage is calculated separately for critical systems and critical flows. P2 carries 20 points.
- ImplementationQCI-QS1 scoring: pillars and gates
Pillar 3: Data longevity and exposure management
P3 measures whether each critical system and flow has a justified confidentiality and verification horizon, an exposure analysis and an owned treatment. P3 carries 20 points.
- ImplementationQCI-QS1 scoring: pillars and gates
Pillar 4: PQC migration readiness and crypto agility
P4 measures accepted production migration and tested crypto agility, not plans or vendor availability. It is the most heavily weighted pillar at 5 points per level, up to 25.
- ImplementationQCI-QS1 scoring: pillars and gates
Pillar 5: Third-party readiness
P5 measures how many critical suppliers have current, adequate roadmap responses and authorized attestations, and how supplier claims are checked. It carries 3 points per level, up to 15.
- ImplementationQCI-QS1 scoring: pillars and gates
What G60 means and how to satisfy it
G60 caps the final Q-Risk Score at 60 unless validated inventory coverage is at least 95% for both critical systems and critical flows, with no unresolved material population discrepancy.
- ImplementationQCI-QS1 scoring: pillars and gates
What G70 means and how to satisfy it
G70 caps the final Q-Risk Score at 70 unless every critical supplier has a current, adequate product- and deployment-specific roadmap response and authorized attestation. An approved operating exception is not a substitute.
- ImplementationQCI-QS1 scoring: pillars and gates
What G80 means and how to satisfy it
G80 caps the final Q-Risk Score at 80 unless at least one critical trust pathway has passed a representative end-to-end crypto-agility test under Clause 4.7 in the previous 12 months.
- DefinitionCryptographic inventory
Cryptographic inventory: definition, scope and required fields
What a cryptographic inventory records and how its coverage is measured.
- DefinitionMigration and crypto agility
Crypto agility: definition and practical demonstration
What crypto agility means in practice and how it is demonstrated.
- ImplementationMigration and crypto agility
PQC migration roadmap, milestones and decision records
- DecisionMigration and crypto agility
When to begin PQC migration and when to defer deployment
- DecisionMigration and crypto agility
What determines PQC migration duration and effort
- DecisionMigration and crypto agility
What migrates first and why
- DefinitionMigration and crypto agility
Hybrid approaches and their limitations
- ImplementationMigration and crypto agility
Testing, acceptance and rollback
- DefinitionSuppliers and procurement
What is supplier PQC readiness?
- ImplementationSuppliers and procurement
What should you ask vendors about PQC?
- DefinitionSuppliers and procurement
What is a PQC supplier attestation?
- DecisionSuppliers and procurement
How do you evaluate a vendor's quantum-readiness claim?
- DecisionSuppliers and procurement
What should PQC contract language address?
- DecisionGovernance and assurance
What should boards know and ask about quantum risk?
- ImplementationGovernance and assurance
What should a quantum-risk board report contain?
- ImplementationGovernance and assurance
What evidence should an auditor expect for quantum readiness?
- DefinitionGovernance and assurance
What is a defensible quantum-risk posture?
- DecisionGovernance and assurance
What is a quantum-risk assessment?
- DefinitionStandards and regulation
What post-quantum cryptography is
What post-quantum cryptography is and why organizations are moving to it.
- DefinitionStandards and regulation
NIST PQC standards and transition guidance
How NIST's post-quantum standards and transition guidance affect migration timing.
- DecisionStandards and regulation
How does QCI-QS1 align with standards and regulation?