Implementation

    What G70 means and how to satisfy it

    G70 is the supplier gate in QCI-QS1 v2.3. Unless every critical supplier has a current, adequate product- and deployment-specific roadmap response and an authorized attestation assessed under Clause 7, the final Q-Risk Score is capped at 70. An approved operating exception is not a substitute, and risk acceptance may permit continued service but does not satisfy the gate.

    New to this? Read Pillar 5: Third-party readiness first. After this, continue with What G80 means and how to satisfy it.

    In one sentence: One critical supplier without adequate, current evidence holds the score at 70.

    Why it matters

    Critical cryptography often sits in purchased products and services. The gate prevents an organization from counting readiness it cannot evidence from its suppliers.

    Illustrative example: twelve of thirteen critical suppliers have adequate attestations; the thirteenth has an approved exception. G70 fails and the final score is capped at 70.

    Which suppliers are in scope

    Critical suppliers are those materially affecting identity and trust, signing, secure communications, key management, regulated or long-lived confidentiality, transaction integrity or relevant AI infrastructure, including cloud, SaaS, managed services, embedded products and material subservice dependencies (QCI-7.1-01). Criticality follows Clause 1.1, and a critical dependency is not excluded solely because evidence or supplier access is unavailable (QCI-1.1-02).

    When a response is adequate and current

    • It addresses every applicable request area and identifies product and deployment scope (QCI-7.2-03).
    • It separates available, configured and deployed posture, and supplies assessable evidence for material present-tense claims (QCI-7.2-03).
    • It gives owned, dated commitments and limitations (QCI-7.2-03).
    • The attestation is signed by an authorized signatory (QCI-7.2-02) and refreshed at least annually and on material cryptographic change (QCI-7.2-03).
    • Superseded or materially invalidated evidence does not pass G70 (QCI-7.2-03).

    Missing or insufficient responses

    Nonresponse or an inadequate response at the deadline enters the exception and escalation process (QCI-7.2-04). That process records missed commitments, compensating controls, exit or replacement plans and customer actions, and reports top critical supplier exceptions to the governing body (QCI-7.3-01).

    Operating exceptions and the gate are separate. An exception can let the organization keep using a supplier while risk is managed; it does not satisfy G70. Risk acceptance may permit continued service but does not satisfy the gate (QCI-7.2-04), and an approved operating exception is not a substitute (QCI-6.3-01).

    What happens when G70 fails

    In the standard's worked example, pillar levels 5, 5, 5, 5, 3 give a raw score of 94. G70 fails despite approved exceptions, so the final score is 70, in the Advancing band. A final score of 70 does not imply that G70 passed (QCI-6.5-01).

    What organizations should do

    1. Send every critical supplier a request covering areas A–F of Annex C, plus G1–G5 for applicable AI suppliers (QCI-7.2-01).
    2. Set a response deadline no later than 60 calendar days after issue; nonresponse enters the exception and escalation process (QCI-7.2-04).
    3. Obtain an attestation signed by an officer or equivalently authorized signatory (QCI-7.2-02).
    4. Record engineering and vendor-risk acceptance of each response, and refresh attestations at least annually and on material cryptographic change (QCI-7.2-03).

    Evidence an auditor should expect

    Rows marked "QCI requirement" come from the standard. Rows marked "Editorial suggestion" are QCI's practical advice and are not requirements.

    Expected evidence
    ArtifactScopeOwnerCurrencyVerificationBasis
    Supplier request and responseEach critical supplier, product and deploymentRelationship ownerResponse within 60 days of issueCheck every request area is addressedQCI requirement (QCI-7.2-01)
    Authorized attestationNamed legal entity, products and releasesSupplier signatoryRefreshed at least annually and on material changeConfirm signatory authority and as-of dateQCI requirement (QCI-7.2-02)
    Adequacy decisionEach responseEngineering and vendor-riskChecked quarterlyReview recorded acceptance or reasons for inadequacyQCI requirement (QCI-7.2-03)

    How NIST or other primary authorities address it

    This concept originates with QCI in QCI-QS1. NIST and other standards bodies do not define or endorse it.

    How QCI-QS1 addresses it

    G70 is defined in the Clause 6.3 gate table and assessed using Clause 7.

    QCI-QS1 v2.3 mappings
    RequirementClauseRelationshipPillarGate
    QCI-6.3-016.3explicit requirement—G70
    QCI-7.2-017.2explicit requirementP5G70
    QCI-7.2-027.2explicit requirementP5G70
    QCI-7.2-037.2explicit requirementP5G70
    QCI-7.2-047.2explicit requirementP5G70
    QCI-7.1-017.1explicit requirementP5G70
    QCI-7.3-017.3supporting evidenceP5G70
    QCI-6.5-016.5explanatory context—G70

    Common mistakes

    • Using an approved operating exception in place of evidence (QCI-6.3-01).
    • Relying on superseded or materially invalidated attestations (QCI-7.2-03).

    Questions for the board

    • Which critical suppliers lack a current, adequate attestation, and what is the decision on each?

    Questions

    Can an approved exception for one supplier keep G70 passing?

    No. An approved operating exception is not a substitute for a current, adequate response and attestation (QCI-6.3-01).

    How long do suppliers have to respond?

    The request sets a deadline no later than 60 calendar days after issue, unless an earlier obligation applies (QCI-7.2-04).

    How often must attestations be refreshed?

    At least annually and on material cryptographic change, with relevance checked quarterly (QCI-7.2-03).

    Sources

    1. QCI-QS1 Quantum Readiness and Post-Quantum Cryptography Governance Standard, Quantum Core Institute, Version 2.3, September 23, 2026, Clause 6.3. Supports: G70 pass condition and cap.
    2. QCI-QS1 Quantum Readiness and Post-Quantum Cryptography Governance Standard, Quantum Core Institute, Version 2.3, September 23, 2026, Clause 7.2. Supports: Request, attestation and adequacy.

    Back to QCI-QS1 scoring: pillars and gates · All Knowledge Center topics

    Page history

    Published
    Not yet recorded
    Standard edition
    QCI-QS1 v2.3 (September 23, 2026)

    Cite this page

    Quantum Core Institute. (n.d.). What G70 means and how to satisfy it. https://quantumcoreinstitute.com/learn/qci-qs1/g70-supplier-gate

    Link: https://quantumcoreinstitute.com/learn/qci-qs1/g70-supplier-gate