QCI-QS1 scoring: pillars and gates

    QCI-QS1 Clause 6 scores readiness across five pillars, then caps the result if any of three gates fails. Read the score overview first, then the pillars in order, then the gates that limit the final result.

    Suggested order

    1. What is QCI-QS1? : Read the standard's scope and structure
    2. Q-Risk Score and how scoring gates work : Learn how the score is calculated
    3. Pillar 1: Governance and accountability : Work through the five pillars
    4. What G60 means and how to satisfy it : Check the three gates that cap the score

    Published pages in this section

    Showing 10 of 10 published pages.

    • Definition

      What is QCI-QS1?

      The standard of record: scope, conformance, scoring, supplier oversight and governing-body reporting.

    • Definition

      Q-Risk Score and how scoring gates work

      What the 0–100 Q-Risk Score measures, how it is calculated and what it does not mean.

    • Implementation

      Pillar 1: Governance and accountability

      P1 measures whether quantum risk has named owners, approved policy, a working quarterly cycle and governing-body oversight. It carries 20 of the 100 points (4 points per level).

    • Implementation

      Pillar 2: Crypto visibility and QASI completeness

      P2 measures how much of the critical population has validated cryptographic inventory records. Coverage is calculated separately for critical systems and critical flows. P2 carries 20 points.

    • Implementation

      Pillar 3: Data longevity and exposure management

      P3 measures whether each critical system and flow has a justified confidentiality and verification horizon, an exposure analysis and an owned treatment. P3 carries 20 points.

    • Implementation

      Pillar 4: PQC migration readiness and crypto agility

      P4 measures accepted production migration and tested crypto agility, not plans or vendor availability. It is the most heavily weighted pillar at 5 points per level, up to 25.

    • Implementation

      Pillar 5: Third-party readiness

      P5 measures how many critical suppliers have current, adequate roadmap responses and authorized attestations, and how supplier claims are checked. It carries 3 points per level, up to 15.

    • Implementation

      What G60 means and how to satisfy it

      G60 caps the final Q-Risk Score at 60 unless validated inventory coverage is at least 95% for both critical systems and critical flows, with no unresolved material population discrepancy.

    • Implementation

      What G70 means and how to satisfy it

      G70 caps the final Q-Risk Score at 70 unless every critical supplier has a current, adequate product- and deployment-specific roadmap response and authorized attestation. An approved operating exception is not a substitute.

    • Implementation

      What G80 means and how to satisfy it

      G80 caps the final Q-Risk Score at 80 unless at least one critical trust pathway has passed a representative end-to-end crypto-agility test under Clause 4.7 in the previous 12 months.

    See also