QCI-QS1 scoring: pillars and gates
QCI-QS1 Clause 6 scores readiness across five pillars, then caps the result if any of three gates fails. Read the score overview first, then the pillars in order, then the gates that limit the final result.
Suggested order
- What is QCI-QS1? : Read the standard's scope and structure
- Q-Risk Score and how scoring gates work : Learn how the score is calculated
- Pillar 1: Governance and accountability : Work through the five pillars
- What G60 means and how to satisfy it : Check the three gates that cap the score
Published pages in this section
Showing 10 of 10 published pages.
- Definition
What is QCI-QS1?
The standard of record: scope, conformance, scoring, supplier oversight and governing-body reporting.
- Definition
Q-Risk Score and how scoring gates work
What the 0–100 Q-Risk Score measures, how it is calculated and what it does not mean.
- Implementation
Pillar 1: Governance and accountability
P1 measures whether quantum risk has named owners, approved policy, a working quarterly cycle and governing-body oversight. It carries 20 of the 100 points (4 points per level).
- Implementation
Pillar 2: Crypto visibility and QASI completeness
P2 measures how much of the critical population has validated cryptographic inventory records. Coverage is calculated separately for critical systems and critical flows. P2 carries 20 points.
- Implementation
Pillar 3: Data longevity and exposure management
P3 measures whether each critical system and flow has a justified confidentiality and verification horizon, an exposure analysis and an owned treatment. P3 carries 20 points.
- Implementation
Pillar 4: PQC migration readiness and crypto agility
P4 measures accepted production migration and tested crypto agility, not plans or vendor availability. It is the most heavily weighted pillar at 5 points per level, up to 25.
- Implementation
Pillar 5: Third-party readiness
P5 measures how many critical suppliers have current, adequate roadmap responses and authorized attestations, and how supplier claims are checked. It carries 3 points per level, up to 15.
- Implementation
What G60 means and how to satisfy it
G60 caps the final Q-Risk Score at 60 unless validated inventory coverage is at least 95% for both critical systems and critical flows, with no unresolved material population discrepancy.
- Implementation
What G70 means and how to satisfy it
G70 caps the final Q-Risk Score at 70 unless every critical supplier has a current, adequate product- and deployment-specific roadmap response and authorized attestation. An approved operating exception is not a substitute.
- Implementation
What G80 means and how to satisfy it
G80 caps the final Q-Risk Score at 80 unless at least one critical trust pathway has passed a representative end-to-end crypto-agility test under Clause 4.7 in the previous 12 months.