What G70 means and how to satisfy it
G70 is the supplier gate in QCI-QS1 v2.3. Unless every critical supplier has a current, adequate product- and deployment-specific roadmap response and an authorized attestation assessed under Clause 7, the final Q-Risk Score is capped at 70. An approved operating exception is not a substitute, and risk acceptance may permit continued service but does not satisfy the gate.
New to this? Read Pillar 5: Third-party readiness first. After this, continue with What G80 means and how to satisfy it.
In one sentence: One critical supplier without adequate, current evidence holds the score at 70.
Why it matters
Critical cryptography often sits in purchased products and services. The gate prevents an organization from counting readiness it cannot evidence from its suppliers.
Illustrative example: twelve of thirteen critical suppliers have adequate attestations; the thirteenth has an approved exception. G70 fails and the final score is capped at 70.
Which suppliers are in scope
Critical suppliers are those materially affecting identity and trust, signing, secure communications, key management, regulated or long-lived confidentiality, transaction integrity or relevant AI infrastructure, including cloud, SaaS, managed services, embedded products and material subservice dependencies (QCI-7.1-01). Criticality follows Clause 1.1, and a critical dependency is not excluded solely because evidence or supplier access is unavailable (QCI-1.1-02).
When a response is adequate and current
- It addresses every applicable request area and identifies product and deployment scope (QCI-7.2-03).
- It separates available, configured and deployed posture, and supplies assessable evidence for material present-tense claims (QCI-7.2-03).
- It gives owned, dated commitments and limitations (QCI-7.2-03).
- The attestation is signed by an authorized signatory (QCI-7.2-02) and refreshed at least annually and on material cryptographic change (QCI-7.2-03).
- Superseded or materially invalidated evidence does not pass G70 (QCI-7.2-03).
Missing or insufficient responses
Nonresponse or an inadequate response at the deadline enters the exception and escalation process (QCI-7.2-04). That process records missed commitments, compensating controls, exit or replacement plans and customer actions, and reports top critical supplier exceptions to the governing body (QCI-7.3-01).
Operating exceptions and the gate are separate. An exception can let the organization keep using a supplier while risk is managed; it does not satisfy G70. Risk acceptance may permit continued service but does not satisfy the gate (QCI-7.2-04), and an approved operating exception is not a substitute (QCI-6.3-01).
What happens when G70 fails
In the standard's worked example, pillar levels 5, 5, 5, 5, 3 give a raw score of 94. G70 fails despite approved exceptions, so the final score is 70, in the Advancing band. A final score of 70 does not imply that G70 passed (QCI-6.5-01).
What organizations should do
- Send every critical supplier a request covering areas A–F of Annex C, plus G1–G5 for applicable AI suppliers (QCI-7.2-01).
- Set a response deadline no later than 60 calendar days after issue; nonresponse enters the exception and escalation process (QCI-7.2-04).
- Obtain an attestation signed by an officer or equivalently authorized signatory (QCI-7.2-02).
- Record engineering and vendor-risk acceptance of each response, and refresh attestations at least annually and on material cryptographic change (QCI-7.2-03).
Evidence an auditor should expect
Rows marked "QCI requirement" come from the standard. Rows marked "Editorial suggestion" are QCI's practical advice and are not requirements.
| Artifact | Scope | Owner | Currency | Verification | Basis |
|---|---|---|---|---|---|
| Supplier request and response | Each critical supplier, product and deployment | Relationship owner | Response within 60 days of issue | Check every request area is addressed | QCI requirement (QCI-7.2-01) |
| Authorized attestation | Named legal entity, products and releases | Supplier signatory | Refreshed at least annually and on material change | Confirm signatory authority and as-of date | QCI requirement (QCI-7.2-02) |
| Adequacy decision | Each response | Engineering and vendor-risk | Checked quarterly | Review recorded acceptance or reasons for inadequacy | QCI requirement (QCI-7.2-03) |
How NIST or other primary authorities address it
This concept originates with QCI in QCI-QS1. NIST and other standards bodies do not define or endorse it.
How QCI-QS1 addresses it
G70 is defined in the Clause 6.3 gate table and assessed using Clause 7.
| Requirement | Clause | Relationship | Pillar | Gate |
|---|---|---|---|---|
| QCI-6.3-01 | 6.3 | explicit requirement | — | G70 |
| QCI-7.2-01 | 7.2 | explicit requirement | P5 | G70 |
| QCI-7.2-02 | 7.2 | explicit requirement | P5 | G70 |
| QCI-7.2-03 | 7.2 | explicit requirement | P5 | G70 |
| QCI-7.2-04 | 7.2 | explicit requirement | P5 | G70 |
| QCI-7.1-01 | 7.1 | explicit requirement | P5 | G70 |
| QCI-7.3-01 | 7.3 | supporting evidence | P5 | G70 |
| QCI-6.5-01 | 6.5 | explanatory context | — | G70 |
Common mistakes
- Using an approved operating exception in place of evidence (QCI-6.3-01).
- Relying on superseded or materially invalidated attestations (QCI-7.2-03).
Questions for the board
- Which critical suppliers lack a current, adequate attestation, and what is the decision on each?
Questions
Can an approved exception for one supplier keep G70 passing?
No. An approved operating exception is not a substitute for a current, adequate response and attestation (QCI-6.3-01).
How long do suppliers have to respond?
The request sets a deadline no later than 60 calendar days after issue, unless an earlier obligation applies (QCI-7.2-04).
How often must attestations be refreshed?
At least annually and on material cryptographic change, with relevance checked quarterly (QCI-7.2-03).
Sources
- QCI-QS1 Quantum Readiness and Post-Quantum Cryptography Governance Standard, Quantum Core Institute, Version 2.3, September 23, 2026, Clause 6.3. Supports: G70 pass condition and cap.
- QCI-QS1 Quantum Readiness and Post-Quantum Cryptography Governance Standard, Quantum Core Institute, Version 2.3, September 23, 2026, Clause 7.2. Supports: Request, attestation and adequacy.
Related learning
Before this
Where the gate's evidence comes from
Back to QCI-QS1 scoring: pillars and gates · All Knowledge Center topics
Page history
- Published
- Not yet recorded
- Standard edition
- QCI-QS1 v2.3 (September 23, 2026)
Cite this page
Quantum Core Institute. (n.d.). What G70 means and how to satisfy it. https://quantumcoreinstitute.com/learn/qci-qs1/g70-supplier-gate
Link: https://quantumcoreinstitute.com/learn/qci-qs1/g70-supplier-gate