Pillar 3: Data longevity and exposure management
Pillar 3 measures whether each critical system and data flow has a justified confidentiality and verification horizon, an exposure analysis and owner confirmation, and whether exposures above risk appetite have owned, evidenced treatment. Coverage thresholds rise from 50% to 100% in each category. P3 contributes 4 points per level, up to 20 of the 100 points.
New to this? Read What is Harvest Now, Decrypt Later? first. After this, continue with Pillar 4: PQC migration readiness and crypto agility.
In one sentence: P3 asks how long protection must hold and whether exposures beyond appetite are being treated.
How this pillar differs from harvest now, decrypt later
Harvest now, decrypt later describes one threat: encrypted data captured today and read later. Pillar 3 is broader and is scored. It assesses whether the organization has identified how long data must stay confidential and how long signatures and other trust decisions must remain verifiable, and whether those horizons are linked to the systems and flows that protect them.
Confidentiality horizons concern how long information must stay secret. Verification horizons concern how long a signature, certificate or record must remain trustworthy. P3 assesses both, against the Clause 6.8 rubric, using evidence rather than a description of the threat.
How horizon-and-exposure coverage is counted
Coverage uses all critical systems and flows in scope as denominators, and counts only records with separate justified horizons, relevant exposure analysis and owner confirmation (QCI-6.8-01).
Evidence required at each level
Levels are cumulative. An organization receives the highest level for which every criterion at that level and all lower positive levels is supported. Unsupported, contradictory or stale evidence fails the affected criterion, and fractional levels are not allowed (QCI-6.1-01).
| Level | Required evidence |
|---|---|
| 0 | One or more level 1 criteria are unsupported. |
| 1 | Critical data/service categories and initial confidentiality, verification and HNDL concerns identified. |
| 2 | Approved risk method and treatment rules; coverage at least 50% in each category; exposures separated from plans and accepted risk. |
| 3 | Coverage at least 80% in each category; every above-appetite exposure has an approved owned treatment or escalated decision; treatment progress evidenced. |
| 4 | Coverage 100%; two quarterly reviews show current records; overdue treatments and historical-copy limitations explicitly reported; closures have verified mitigation evidence. |
| 5 | Independent review validates prioritization, horizons and a risk-based sample of closures; no unapproved above-appetite exposure and no overdue high-impact finding. |
How NIST or other primary authorities address it
This concept originates with QCI in QCI-QS1. NIST and other standards bodies do not define or endorse it.
How QCI-QS1 addresses it
P3 is levelled against Clause 6.8. Harvest-now, decrypt-later concerns appear from level 1. Governing-body reporting must keep exposure reduction separate from maturity improvement (Clause 8.1).
| Requirement | Clause | Relationship | Pillar | Gate |
|---|---|---|---|---|
| QCI-6.8-01 | 6.8 | explicit requirement | P3 | — |
| QCI-8.1-02 | 8.1 | supporting evidence | P3, P1 | — |
| QCI-6.1-01 | 6.1 | explicit requirement | — | — |
Common mistakes
- Treating an approved plan as reduced exposure. Reporting may not clear exposure because a plan or attestation exists (QCI-8.1-02).
- Recording one horizon for both confidentiality and verification instead of separate justified horizons.
Questions
How many points can Pillar 3 contribute?
Up to 20. Each level adds 4 points in the formula R = 4×L1 + 4×L2 + 4×L3 + 5×L4 + 3×L5 (QCI-6.1-02).
Can a pillar be marked not applicable?
Only where its entire subject population is demonstrably absent and that absence is independently checked. Weight is not redistributed, and no 0–100 total or band is published while a pillar is not applicable (QCI-6.1-03).
Does an approved migration plan reduce P3 exposure?
No. Exposures are kept separate from plans and accepted risk from level 2, and reporting may not clear exposure because a plan exists (QCI-6.8-01, QCI-8.1-02).
Sources
- QCI-QS1 Quantum Readiness and Post-Quantum Cryptography Governance Standard, Quantum Core Institute, Version 2.3, September 23, 2026, Clause 6.8. Supports: P3 level criteria.
- QCI-QS1 Quantum Readiness and Post-Quantum Cryptography Governance Standard, Quantum Core Institute, Version 2.3, September 23, 2026, Clause 8.1. Supports: Reporting exposure versus maturity.
Related learning
Before this
Guides for this pillar
Back to QCI-QS1 scoring: pillars and gates · All Knowledge Center topics
Page history
- Published
- Not yet recorded
- Standard edition
- QCI-QS1 v2.3 (September 23, 2026)
Cite this page
Quantum Core Institute. (n.d.). Pillar 3: Data longevity and exposure management. https://quantumcoreinstitute.com/learn/qci-qs1/data-longevity-pillar
Link: https://quantumcoreinstitute.com/learn/qci-qs1/data-longevity-pillar