What evidence should an auditor expect for quantum readiness?
An auditor should expect dated, attributable records for each area: governance (roles, policy, board decisions), inventory (validated records with coverage counts), exposure (confidentiality and verification horizons), migration (roadmap, test and acceptance results) and suppliers (requests, responses, attestations, exceptions). Under QCI-QS1 every claim must link to evidence applicable to the scope and configuration assessed. Some records are required; others are useful examples.
New to this? Read What should a quantum-risk board report contain? first. After this, continue with What is a defensible quantum-risk posture?.
In one sentence: Every claim needs dated, attributable evidence for the scope it covers.
Why it matters
QCI-QS1 requires every conformance result, maturity criterion, coverage claim and migration-completion claim to link to attributable, dated evidence applicable to the assessed scope and configuration (QCI-4.8-01).
Evidence matrix
"Required" rows are QCI-QS1 records. "Example" rows are editorial suggestions that often help but are not mandatory.
| Area | Artifact | Purpose | Owner | Scope and date | Basis | Limitation |
|---|---|---|---|---|---|---|
| Governance (P1) | Conformance record | Applicability, evidence and result per requirement | Quantum Risk Owner | Each requirement; assessment date | Required, QCI-1.2-01 | Does not by itself show deployed protection |
| Governance (P1) | Board decision log | Shows oversight decisions | Company secretary | Each quarter | Required, QCI-8.2-01 | Acknowledgement is not acceptance |
| Inventory (P2) | QASI records and coverage report | Shows what cryptography exists and how much is validated | System owners | Critical systems and flows; ≤90-day evidence | Required, QCI-5.2-01, QCI-5.1-04 | Discovery tools have blind spots |
| Exposure (P3) | Horizon and exposure analysis | Shows how long protection must last | Data owners | Each critical record | Required, QCI-4.2-02 | Horizons are judgments and need owner confirmation |
| Migration (P4) | Roadmap, test and acceptance results | Shows completion and agility | Engineering | Each change; tests within 12 months for G80 | Required, QCI-4.7-01 | A pilot is not completion |
| Suppliers (P5) | Requests, responses, attestations, exceptions | Shows supplier readiness | Vendor risk | Each critical supplier; annual refresh | Required, QCI-7.2-01, QCI-7.2-03 | Attestation is the supplier's own claim |
| Any | Walkthrough notes or screenshots | Corroborate records | Assessor | Sample | Example | Not sufficient alone |
What makes evidence usable
- It names its producer, reviewer, integrity controls, retention period and access limits (QCI-4.8-01).
- Supplier assertion, algorithm testing, module validation and full-system acceptance are kept distinct (QCI-4.8-03).
- Assessors use risk-based sampling that includes all unresolved high-impact exceptions (QCI-4.8-02).
- Stale evidence does not support a gate or maturity criterion (QCI-5.1-04).
What organizations should do
- Build an assessment-pack index linking every claim to evidence.
- Record producer, reviewer and date on each record.
- Mark which records are required and which are supporting examples.
- Retain each pack through at least the next annual assurance cycle.
Evidence an auditor should expect
Rows marked "QCI requirement" come from the standard. Rows marked "Editorial suggestion" are QCI's practical advice and are not requirements.
| Artifact | Scope | Owner | Currency | Verification | Basis |
|---|---|---|---|---|---|
| Assessment-pack index | Assessment boundary | Quantum Risk Owner | Each assessment | Sample claims and trace to evidence | QCI requirement (QCI-4.8-01) |
| Sampling record | Each assessment | Assessor | Each assessment | Check population, selection rationale and closure verification | QCI requirement (QCI-4.8-02) |
How NIST or other primary authorities address it
This concept originates with QCI in QCI-QS1. NIST and other standards bodies do not define or endorse it.
How QCI-QS1 addresses it
Clause 4.8 sets the evidence and assurance rules; the pillar rubrics in Clauses 6.6–6.10 define what each level needs.
| Requirement | Clause | Relationship | Pillar | Gate |
|---|---|---|---|---|
| QCI-4.8-01 | 4.8 | explicit requirement | — | — |
| QCI-4.8-02 | 4.8 | explicit requirement | — | — |
| QCI-4.8-03 | 4.8 | explicit requirement | — | — |
| QCI-1.2-01 | 1.2 | explicit requirement | — | — |
| QCI-5.1-04 | 5.1 | supporting evidence | P2 | — |
Common mistakes
- Accepting slide decks in place of records.
- Using evidence from a different environment or release.
- Treating a module validation certificate as proof of the whole system.
Questions for the board
- Could an outside reviewer trace our reported score to evidence without asking us to explain it?
Questions
Is every artifact in the matrix mandatory?
No. Rows marked Required are QCI-QS1 records; rows marked Example are helpful but optional.
How old can evidence be?
Critical evidence should be no older than 90 days unless a documented review confirms unchanged configuration (QCI-5.1-04).
Does a vendor certificate count?
It counts as the type of evidence it is. A validated algorithm or module is not assurance of the complete deployed system (QCI-4.8-03).
Sources
- QCI-QS1 Quantum Readiness and Post-Quantum Cryptography Governance Standard, Quantum Core Institute, Version 2.3, September 23, 2026, Clause 4.8. Supports: Evidence and assurance.
- QCI-QS1 Quantum Readiness and Post-Quantum Cryptography Governance Standard, Quantum Core Institute, Version 2.3, September 23, 2026, Clause 1.2. Supports: Conformance claims, assessment type and the score's meaning.
- QCI-QS1 Quantum Readiness and Post-Quantum Cryptography Governance Standard, Quantum Core Institute, Version 2.3, September 23, 2026, Clauses 5–7. Supports: Inventory, scoring and supplier evidence.
Related learning
Back to Governance and assurance · All Knowledge Center topics
Page history
- Published
- Not yet recorded
- Standard edition
- QCI-QS1 v2.3 (September 23, 2026)
Cite this page
Quantum Core Institute. (n.d.). What evidence should an auditor expect for quantum readiness?. https://quantumcoreinstitute.com/learn/governance/quantum-readiness-audit-evidence
Link: https://quantumcoreinstitute.com/learn/governance/quantum-readiness-audit-evidence