Quantum Risk Knowledge Center

    Short, sourced explanations of quantum risk and how organizations prepare for it. Pages about QCI-QS1 cite the requirements they rely on; the standard itself stays the edition of record. No sign-in is needed.

    New to quantum risk? Start here

    1. What is Harvest Now, Decrypt Later?
    2. What post-quantum cryptography is
    3. What is QCI-QS1?
    4. Q-Risk Score and how scoring gates work
    5. Cryptographic inventory: definition, scope and required fields
    6. Crypto agility: definition and practical demonstration

    Reading paths

    Read these in order. Further steps are added as their pages are published.

    By role

    Topics

    Fundamentals

    The core ideas behind quantum risk: what is exposed, why timing matters and which cryptography is affected.

    1 published page

    QCI-QS1 scoring: pillars and gates

    How the five Q-Risk pillars are levelled and how the G60, G70 and G80 gates cap the final score under QCI-QS1 v2.3.

    10 published pages

    Cryptographic inventory

    How organizations find, record and keep current the cryptography their critical systems and data flows rely on.

    1 published page

    Migration and crypto agility

    How organizations plan, test and accept the move to post-quantum cryptography, and prove they can change cryptography again.

    7 published pages

    Suppliers and procurement

    How to assess supplier post-quantum readiness, what to ask vendors and what a supplier attestation should contain.

    5 published pages

    Governance and assurance

    What boards should ask, what a board report contains and what evidence auditors should expect.

    5 published pages

    Standards and regulation

    Post-quantum cryptography standards, NIST transition guidance and how QCI-QS1 relates to legal obligations.

    3 published pages

    All published pages

    Showing 32 of 32 published pages.

    Start the Q-Risk screeningRead QCI-QS1