Implementation

    What evidence should an auditor expect for quantum readiness?

    An auditor should expect dated, attributable records for each area: governance (roles, policy, board decisions), inventory (validated records with coverage counts), exposure (confidentiality and verification horizons), migration (roadmap, test and acceptance results) and suppliers (requests, responses, attestations, exceptions). Under QCI-QS1 every claim must link to evidence applicable to the scope and configuration assessed. Some records are required; others are useful examples.

    New to this? Read What should a quantum-risk board report contain? first. After this, continue with What is a defensible quantum-risk posture?.

    In one sentence: Every claim needs dated, attributable evidence for the scope it covers.

    Why it matters

    QCI-QS1 requires every conformance result, maturity criterion, coverage claim and migration-completion claim to link to attributable, dated evidence applicable to the assessed scope and configuration (QCI-4.8-01).

    Evidence matrix

    "Required" rows are QCI-QS1 records. "Example" rows are editorial suggestions that often help but are not mandatory.

    Evidence by pillar
    AreaArtifactPurposeOwnerScope and dateBasisLimitation
    Governance (P1)Conformance recordApplicability, evidence and result per requirementQuantum Risk OwnerEach requirement; assessment dateRequired, QCI-1.2-01Does not by itself show deployed protection
    Governance (P1)Board decision logShows oversight decisionsCompany secretaryEach quarterRequired, QCI-8.2-01Acknowledgement is not acceptance
    Inventory (P2)QASI records and coverage reportShows what cryptography exists and how much is validatedSystem ownersCritical systems and flows; ≤90-day evidenceRequired, QCI-5.2-01, QCI-5.1-04Discovery tools have blind spots
    Exposure (P3)Horizon and exposure analysisShows how long protection must lastData ownersEach critical recordRequired, QCI-4.2-02Horizons are judgments and need owner confirmation
    Migration (P4)Roadmap, test and acceptance resultsShows completion and agilityEngineeringEach change; tests within 12 months for G80Required, QCI-4.7-01A pilot is not completion
    Suppliers (P5)Requests, responses, attestations, exceptionsShows supplier readinessVendor riskEach critical supplier; annual refreshRequired, QCI-7.2-01, QCI-7.2-03Attestation is the supplier's own claim
    AnyWalkthrough notes or screenshotsCorroborate recordsAssessorSampleExampleNot sufficient alone

    What makes evidence usable

    • It names its producer, reviewer, integrity controls, retention period and access limits (QCI-4.8-01).
    • Supplier assertion, algorithm testing, module validation and full-system acceptance are kept distinct (QCI-4.8-03).
    • Assessors use risk-based sampling that includes all unresolved high-impact exceptions (QCI-4.8-02).
    • Stale evidence does not support a gate or maturity criterion (QCI-5.1-04).

    What organizations should do

    1. Build an assessment-pack index linking every claim to evidence.
    2. Record producer, reviewer and date on each record.
    3. Mark which records are required and which are supporting examples.
    4. Retain each pack through at least the next annual assurance cycle.

    Evidence an auditor should expect

    Rows marked "QCI requirement" come from the standard. Rows marked "Editorial suggestion" are QCI's practical advice and are not requirements.

    Expected evidence
    ArtifactScopeOwnerCurrencyVerificationBasis
    Assessment-pack indexAssessment boundaryQuantum Risk OwnerEach assessmentSample claims and trace to evidenceQCI requirement (QCI-4.8-01)
    Sampling recordEach assessmentAssessorEach assessmentCheck population, selection rationale and closure verificationQCI requirement (QCI-4.8-02)

    How NIST or other primary authorities address it

    This concept originates with QCI in QCI-QS1. NIST and other standards bodies do not define or endorse it.

    How QCI-QS1 addresses it

    Clause 4.8 sets the evidence and assurance rules; the pillar rubrics in Clauses 6.6–6.10 define what each level needs.

    QCI-QS1 v2.3 mappings
    RequirementClauseRelationshipPillarGate
    QCI-4.8-014.8explicit requirement——
    QCI-4.8-024.8explicit requirement——
    QCI-4.8-034.8explicit requirement——
    QCI-1.2-011.2explicit requirement——
    QCI-5.1-045.1supporting evidenceP2—

    Common mistakes

    • Accepting slide decks in place of records.
    • Using evidence from a different environment or release.
    • Treating a module validation certificate as proof of the whole system.

    Questions for the board

    • Could an outside reviewer trace our reported score to evidence without asking us to explain it?

    Questions

    Is every artifact in the matrix mandatory?

    No. Rows marked Required are QCI-QS1 records; rows marked Example are helpful but optional.

    How old can evidence be?

    Critical evidence should be no older than 90 days unless a documented review confirms unchanged configuration (QCI-5.1-04).

    Does a vendor certificate count?

    It counts as the type of evidence it is. A validated algorithm or module is not assurance of the complete deployed system (QCI-4.8-03).

    Sources

    1. QCI-QS1 Quantum Readiness and Post-Quantum Cryptography Governance Standard, Quantum Core Institute, Version 2.3, September 23, 2026, Clause 4.8. Supports: Evidence and assurance.
    2. QCI-QS1 Quantum Readiness and Post-Quantum Cryptography Governance Standard, Quantum Core Institute, Version 2.3, September 23, 2026, Clause 1.2. Supports: Conformance claims, assessment type and the score's meaning.
    3. QCI-QS1 Quantum Readiness and Post-Quantum Cryptography Governance Standard, Quantum Core Institute, Version 2.3, September 23, 2026, Clauses 5–7. Supports: Inventory, scoring and supplier evidence.

    Back to Governance and assurance · All Knowledge Center topics

    Page history

    Published
    Not yet recorded
    Standard edition
    QCI-QS1 v2.3 (September 23, 2026)

    Cite this page

    Quantum Core Institute. (n.d.). What evidence should an auditor expect for quantum readiness?. https://quantumcoreinstitute.com/learn/governance/quantum-readiness-audit-evidence

    Link: https://quantumcoreinstitute.com/learn/governance/quantum-readiness-audit-evidence