Implementation

    Pillar 3: Data longevity and exposure management

    Pillar 3 measures whether each critical system and data flow has a justified confidentiality and verification horizon, an exposure analysis and owner confirmation, and whether exposures above risk appetite have owned, evidenced treatment. Coverage thresholds rise from 50% to 100% in each category. P3 contributes 4 points per level, up to 20 of the 100 points.

    New to this? Read What is Harvest Now, Decrypt Later? first. After this, continue with Pillar 4: PQC migration readiness and crypto agility.

    In one sentence: P3 asks how long protection must hold and whether exposures beyond appetite are being treated.

    How this pillar differs from harvest now, decrypt later

    Harvest now, decrypt later describes one threat: encrypted data captured today and read later. Pillar 3 is broader and is scored. It assesses whether the organization has identified how long data must stay confidential and how long signatures and other trust decisions must remain verifiable, and whether those horizons are linked to the systems and flows that protect them.

    Confidentiality horizons concern how long information must stay secret. Verification horizons concern how long a signature, certificate or record must remain trustworthy. P3 assesses both, against the Clause 6.8 rubric, using evidence rather than a description of the threat.

    How horizon-and-exposure coverage is counted

    Coverage uses all critical systems and flows in scope as denominators, and counts only records with separate justified horizons, relevant exposure analysis and owner confirmation (QCI-6.8-01).

    Evidence required at each level

    Levels are cumulative. An organization receives the highest level for which every criterion at that level and all lower positive levels is supported. Unsupported, contradictory or stale evidence fails the affected criterion, and fractional levels are not allowed (QCI-6.1-01).

    P3 exposure management rubric, QCI-QS1 v2.3 Clause 6.8
    LevelRequired evidence
    0One or more level 1 criteria are unsupported.
    1Critical data/service categories and initial confidentiality, verification and HNDL concerns identified.
    2Approved risk method and treatment rules; coverage at least 50% in each category; exposures separated from plans and accepted risk.
    3Coverage at least 80% in each category; every above-appetite exposure has an approved owned treatment or escalated decision; treatment progress evidenced.
    4Coverage 100%; two quarterly reviews show current records; overdue treatments and historical-copy limitations explicitly reported; closures have verified mitigation evidence.
    5Independent review validates prioritization, horizons and a risk-based sample of closures; no unapproved above-appetite exposure and no overdue high-impact finding.

    How NIST or other primary authorities address it

    This concept originates with QCI in QCI-QS1. NIST and other standards bodies do not define or endorse it.

    How QCI-QS1 addresses it

    P3 is levelled against Clause 6.8. Harvest-now, decrypt-later concerns appear from level 1. Governing-body reporting must keep exposure reduction separate from maturity improvement (Clause 8.1).

    QCI-QS1 v2.3 mappings
    RequirementClauseRelationshipPillarGate
    QCI-6.8-016.8explicit requirementP3—
    QCI-8.1-028.1supporting evidenceP3, P1—
    QCI-6.1-016.1explicit requirement——

    Common mistakes

    • Treating an approved plan as reduced exposure. Reporting may not clear exposure because a plan or attestation exists (QCI-8.1-02).
    • Recording one horizon for both confidentiality and verification instead of separate justified horizons.

    Questions

    How many points can Pillar 3 contribute?

    Up to 20. Each level adds 4 points in the formula R = 4×L1 + 4×L2 + 4×L3 + 5×L4 + 3×L5 (QCI-6.1-02).

    Can a pillar be marked not applicable?

    Only where its entire subject population is demonstrably absent and that absence is independently checked. Weight is not redistributed, and no 0–100 total or band is published while a pillar is not applicable (QCI-6.1-03).

    Does an approved migration plan reduce P3 exposure?

    No. Exposures are kept separate from plans and accepted risk from level 2, and reporting may not clear exposure because a plan exists (QCI-6.8-01, QCI-8.1-02).

    Sources

    1. QCI-QS1 Quantum Readiness and Post-Quantum Cryptography Governance Standard, Quantum Core Institute, Version 2.3, September 23, 2026, Clause 6.8. Supports: P3 level criteria.
    2. QCI-QS1 Quantum Readiness and Post-Quantum Cryptography Governance Standard, Quantum Core Institute, Version 2.3, September 23, 2026, Clause 8.1. Supports: Reporting exposure versus maturity.

    Back to QCI-QS1 scoring: pillars and gates · All Knowledge Center topics

    Page history

    Published
    Not yet recorded
    Standard edition
    QCI-QS1 v2.3 (September 23, 2026)

    Cite this page

    Quantum Core Institute. (n.d.). Pillar 3: Data longevity and exposure management. https://quantumcoreinstitute.com/learn/qci-qs1/data-longevity-pillar

    Link: https://quantumcoreinstitute.com/learn/qci-qs1/data-longevity-pillar