Pillar 2: Crypto visibility and QASI completeness
Pillar 2 measures how much of an organization's critical estate has validated cryptographic inventory records. Coverage is calculated separately for critical systems and for critical data flows, as validated records divided by the full identified population. Levels rise at 50%, 80%, 95% and 100% coverage in each category. P2 contributes 4 points per level, up to 20.
New to this? Read Cryptographic inventory: definition, scope and required fields first. After this, continue with Pillar 3: Data longevity and exposure management.
In one sentence: P2 counts validated records against the whole critical population, not what a scanner reached.
How this pillar differs from a cryptographic inventory
A cryptographic inventory is the record itself. Pillar 2 is the assessment of that record: whether it covers the complete identified critical population, whether each counted record is validated by a named owner and technical reviewer, whether dependency links are maintained, and whether evidence is current (Clause 5.1).
The same inventory can support different P2 levels depending on validated coverage and evidence quality. Scan output alone does not set the level; QCI-5.1-03 states that scan reach never replaces the coverage metrics. Guidance on building the inventory belongs to the inventory topics.
How coverage is measured
Coverage in each category is 100 times the number of current validated critical records divided by the complete identified critical population in that category. Numerator, denominator, unvalidated count, exclusions and reconciliation gaps are published. Scan reach never replaces these metrics (QCI-5.1-03).
A record with an unknown algorithm, profile or parameters, critical trust dependency or key-protection mechanism does not count as validated (QCI-5.1-02). Critical evidence older than 90 calendar days does not support a criterion unless a documented review confirms the configuration is unchanged (QCI-5.1-04).
Evidence required at each level
Levels are cumulative. An organization receives the highest level for which every criterion at that level and all lower positive levels is supported. Unsupported, contradictory or stale evidence fails the affected criterion, and fractional levels are not allowed (QCI-6.1-01).
| Level | Required evidence |
|---|---|
| 0 | One or more level 1 criteria are unsupported. |
| 1 | Initial critical-system and flow populations, owners and discovery sources identified; unknowns explicitly recorded. |
| 2 | QASI record structure and validation process operating; at least 50% validated coverage in each applicable category; reconciliation and discovery limitations documented. |
| 3 | At least 80% validated coverage in each category; linked use, trust and supplier records maintained; material changes enter revalidation. |
| 4 | At least 95% validated coverage in each category; discovery provenance satisfies Clause 5.4; no unresolved material population discrepancy; unknowns and stale records have owned remediation. |
| 5 | 100% validated coverage in each category; independent sampling confirms accuracy, links and current evidence; no unresolved high-impact visibility finding. |
How NIST or other primary authorities address it
This concept originates with QCI in QCI-QS1. NIST and other standards bodies do not define or endorse it.
How QCI-QS1 addresses it
P2 is levelled against Clause 6.7 using the coverage measures in Clause 5.1. The 95% threshold at level 4 is the same threshold the G60 gate uses.
| Requirement | Clause | Relationship | Pillar | Gate |
|---|---|---|---|---|
| QCI-6.7-01 | 6.7 | explicit requirement | P2 | — |
| QCI-5.1-02 | 5.1 | explicit requirement | P2 | — |
| QCI-5.1-03 | 5.1 | explicit requirement | P2 | G60 |
| QCI-5.1-04 | 5.1 | explicit requirement | P2 | — |
| QCI-6.3-01 | 6.3 | explanatory context | — | G60 |
Common mistakes
- Reporting scanner reach as coverage (QCI-5.1-03).
- Combining systems and flows into one percentage instead of two.
- Counting records with an unknown algorithm or key-protection mechanism as validated (QCI-5.1-02).
Questions
How many points can Pillar 2 contribute?
Up to 20. Each level adds 4 points in the formula R = 4×L1 + 4×L2 + 4×L3 + 5×L4 + 3×L5 (QCI-6.1-02).
Can a pillar be marked not applicable?
Only where its entire subject population is demonstrably absent and that absence is independently checked. Weight is not redistributed, and no 0–100 total or band is published while a pillar is not applicable (QCI-6.1-03).
Are systems and data flows combined into one percentage?
No. System coverage and critical-flow coverage are calculated separately, and each level threshold applies to each applicable category (QCI-5.1-03, QCI-6.7-01).
Sources
- QCI-QS1 Quantum Readiness and Post-Quantum Cryptography Governance Standard, Quantum Core Institute, Version 2.3, September 23, 2026, Clause 6.7. Supports: P2 level criteria.
- QCI-QS1 Quantum Readiness and Post-Quantum Cryptography Governance Standard, Quantum Core Institute, Version 2.3, September 23, 2026, Clause 5.1. Supports: Coverage calculation and validation.
- QCI-QS1 Quantum Readiness and Post-Quantum Cryptography Governance Standard, Quantum Core Institute, Version 2.3, September 23, 2026, Clause 6.3. Supports: G60 threshold.
Related learning
Guides for this pillar
Back to QCI-QS1 scoring: pillars and gates · All Knowledge Center topics
Page history
- Published
- Not yet recorded
- Standard edition
- QCI-QS1 v2.3 (September 23, 2026)
Cite this page
Quantum Core Institute. (n.d.). Pillar 2: Crypto visibility and QASI completeness. https://quantumcoreinstitute.com/learn/qci-qs1/crypto-visibility-pillar
Link: https://quantumcoreinstitute.com/learn/qci-qs1/crypto-visibility-pillar