What G80 means and how to satisfy it
G80 is the crypto-agility gate in QCI-QS1 v2.3. Unless at least one critical trust pathway has passed a representative end-to-end crypto-agility test under Clause 4.7 within the previous 12 months, and after any invalidating material change, the final Q-Risk Score is capped at 80. The pathway tested and the limits of the test must be disclosed.
New to this? Read Pillar 4: PQC migration readiness and crypto agility first.
In one sentence: Without a recent, disclosed agility test on a critical pathway, the score cannot exceed 80.
Why it matters
The Defensible readiness band (81–100) requires every gate to pass. G80 makes sure that band is only reached after the organization has shown it can actually change cryptography on a critical path.
Illustrative example: an organization whose last agility test was 14 months ago, with all other gates passed and a raw score of 86, receives a final score of 80.
What the test must cover
The test follows the Clause 4.7 plan categories: end-to-end interoperability, actual algorithm negotiation, authentication and trust validation, invalid key, ciphertext and signature inputs, downgrade and fallback, message and certificate size and fragmentation where relevant, resource exhaustion, capacity and latency, backup and restore, failover and authorized rollback. Omitted categories need a documented technical non-applicability rationale, and the test environment must be representative of the critical pathway (QCI-4.7-01).
Timing and material change
The pass must fall within the previous 12 months and after any invalidating material change (QCI-6.3-01). A test that was valid can stop counting when the pathway changes in a way that invalidates it, even inside the 12 months.
How G80 differs from a generic migration test
A migration test checks that one planned change works before acceptance. G80 asks a different question: has the organization shown, on at least one critical trust pathway, that it can change its approved cryptographic profile end to end, reject invalid or downgraded operation and recover. The pathway and the limits of the test are disclosed.
The standard's informative guidance notes that the minimum G80 proof is deliberately narrower than the representative estate testing required for P4 levels 4 and 5, so one successful demonstration should not be presented as enterprise readiness (Clause 9.2).
What happens when G80 fails
In the standard's worked example, pillar levels 5, 5, 5, 2, 5 give a raw score of 85. With G80 failed and the other gates passed, the final score is 80, in the Advancing band. A score of 80 is not Defensible readiness, which starts at 81 (QCI-6.5-01).
What organizations should do
- Choose a critical trust pathway and plan a test covering the Clause 4.7 categories, documenting any omitted category (QCI-4.7-01).
- Govern any rollback that restores vulnerable protection as an exception (QCI-4.7-02).
- Record the pathway and the test's limits for disclosure (QCI-6.3-01).
- Repeat the test within 12 months and after any invalidating material change.
Evidence an auditor should expect
Rows marked "QCI requirement" come from the standard. Rows marked "Editorial suggestion" are QCI's practical advice and are not requirements.
| Artifact | Scope | Owner | Currency | Verification | Basis |
|---|---|---|---|---|---|
| Test plan and results | One named critical trust pathway | Engineering and accountable service owner | Within previous 12 months | Review results against Clause 4.7 categories | QCI requirement (QCI-4.7-01) |
| Disclosure of pathway and test limits | Score report | Quantum Risk Owner | Current assessment | Confirm disclosure matches test record | QCI requirement (QCI-6.3-01) |
How NIST or other primary authorities address it
This concept originates with QCI in QCI-QS1. NIST and other standards bodies do not define or endorse it.
How QCI-QS1 addresses it
G80 is defined in the Clause 6.3 gate table. Test content comes from Clause 4.7. The minimum G80 proof is deliberately narrower than the representative testing for P4 levels 4 and 5 (Clause 9.2, informative).
| Requirement | Clause | Relationship | Pillar | Gate |
|---|---|---|---|---|
| QCI-6.3-01 | 6.3 | explicit requirement | — | G80 |
| QCI-4.7-01 | 4.7 | explicit requirement | P4 | G80 |
| QCI-4.7-02 | 4.7 | supporting evidence | P4 | G80 |
| QCI-6.5-01 | 6.5 | explanatory context | — | G80 |
Common mistakes
- Presenting one successful pathway test as enterprise readiness.
- Reading a final score of exactly 80 as a pass (QCI-6.5-01).
Questions
Does a test from 14 months ago satisfy G80?
No. The test must be within the previous 12 months and after any invalidating material change (QCI-6.3-01).
Is one pathway enough?
For G80, yes: at least one critical trust pathway. P4 levels 4 and 5 need representative testing across distinct patterns (QCI-6.9-01).
Can a score of 80 be called Defensible readiness?
No. The Defensible readiness band starts at 81 and requires all score gates to pass (QCI-6.5-01).
Sources
- QCI-QS1 Quantum Readiness and Post-Quantum Cryptography Governance Standard, Quantum Core Institute, Version 2.3, September 23, 2026, Clause 6.3. Supports: G80 pass condition and cap.
- QCI-QS1 Quantum Readiness and Post-Quantum Cryptography Governance Standard, Quantum Core Institute, Version 2.3, September 23, 2026, Clause 4.7. Supports: Test categories and acceptance.
- QCI-QS1 Quantum Readiness and Post-Quantum Cryptography Governance Standard, Quantum Core Institute, Version 2.3, September 23, 2026, Clause 9.2 (informative). Supports: Narrow G80 proof versus estate testing.
Related learning
Where the gate's evidence comes from
Back to QCI-QS1 scoring: pillars and gates · All Knowledge Center topics
Page history
- Published
- Not yet recorded
- Standard edition
- QCI-QS1 v2.3 (September 23, 2026)
Cite this page
Quantum Core Institute. (n.d.). What G80 means and how to satisfy it. https://quantumcoreinstitute.com/learn/qci-qs1/g80-agility-gate
Link: https://quantumcoreinstitute.com/learn/qci-qs1/g80-agility-gate