Implementation

    Pillar 4: PQC migration readiness and crypto agility

    Pillar 4 measures accepted production migration to approved cryptographic profiles and tested crypto agility. Plans, pilots and vendor availability do not count as completion. Levels move from an assigned roadmap to 90% and then 100% completion in each critical transition category, backed by representative testing. It is the most heavily weighted pillar: 5 points per level, up to 25.

    New to this? Read Crypto agility: definition and practical demonstration first. After this, continue with What G80 means and how to satisfy it.

    In one sentence: P4 counts what has been changed and accepted in production, not what is planned.

    How this pillar differs from crypto agility

    Crypto agility is the capability to change cryptographic algorithms, parameters and trust components without redesigning systems. Pillar 4 is the scored assessment of migration readiness and agility together, and it separates three kinds of evidence that are often blurred.

    A plan shows intent. Execution evidence shows protection accepted in production or verified decommissioning (QCI-6.2-02). Test acceptance shows a tested change met its plan under Clause 4.7. A plan, a pilot, supplier availability or an accepted risk does not count as completion. P4 levels 4 and 5 require representative testing across distinct patterns, which is wider than the single-pathway proof that G80 requires.

    What counts as migration completion

    Completion means accepted production protection, or verified decommissioning with vulnerable dependency retirement. Supplier availability, a plan, an accepted risk or a pilot does not count. Deferring an item does not remove it from the denominator (QCI-6.2-02).

    Acceptance requires engineering and service-owner approval of test results, monitoring, recovery and residual exceptions, plus evidence that legacy paths are removed or excepted (QCI-4.7-02).

    Evidence required at each level

    Levels are cumulative. An organization receives the highest level for which every criterion at that level and all lower positive levels is supported. Unsupported, contradictory or stale evidence fails the affected criterion, and fractional levels are not allowed (QCI-6.1-01).

    P4 migration and agility rubric, QCI-QS1 v2.3 Clause 6.9
    LevelRequired evidence
    0One or more level 1 criteria are unsupported.
    1Vulnerable dependencies and initial approved target candidates identified; engineering owners assigned.
    2Approved profiles and a prioritized, resourced dependency roadmap with acceptance, recovery and retirement criteria; long-lead replacement decisions recorded.
    3A representative pilot has passed applicable Clause 4.7 tests; at least one critical production transition accepted, or current evidence shows no critical transition is needed.
    4At least 90% completion in each critical transition category; every remaining item has an owned deadline and treatment; representative operational tests cover deployed patterns and recovery/fallback.
    5100% completion in each category; no unauthorized legacy critical path; current representative tests and independent review confirm configuration, trust/key lifecycle, recovery and retirement evidence.

    Representative testing

    At levels 4 and 5, representative testing covers each materially distinct critical protocol, trust, key-management and deployment pattern. A documented equivalence analysis may justify shared tests (QCI-6.9-01). This is broader than the single-pathway test that satisfies G80.

    How NIST or other primary authorities address it

    This concept originates with QCI in QCI-QS1. NIST and other standards bodies do not define or endorse it.

    How QCI-QS1 addresses it

    P4 is levelled against Clause 6.9. Completion is defined in Clause 6.2 and acceptance in Clause 4.7.

    QCI-QS1 v2.3 mappings
    RequirementClauseRelationshipPillarGate
    QCI-6.9-016.9explicit requirementP4—
    QCI-6.2-026.2explicit requirementP4—
    QCI-4.7-014.7supporting evidenceP4—
    QCI-4.7-024.7supporting evidenceP4—

    Common mistakes

    • Counting a pilot or vendor release as completion (QCI-4.7-02).
    • Dropping deferred items from the denominator (QCI-6.2-02).

    Questions

    How many points can Pillar 4 contribute?

    Up to 25. Each level adds 5 points in the formula R = 4×L1 + 4×L2 + 4×L3 + 5×L4 + 3×L5 (QCI-6.1-02).

    Can a pillar be marked not applicable?

    Only where its entire subject population is demonstrably absent and that absence is independently checked. Weight is not redistributed, and no 0–100 total or band is published while a pillar is not applicable (QCI-6.1-03).

    Does a successful pilot count toward P4 completion?

    No. A pilot can support level 3, but completion percentages count only accepted production protection or verified decommissioning (QCI-6.2-02, QCI-4.7-02).

    Sources

    1. QCI-QS1 Quantum Readiness and Post-Quantum Cryptography Governance Standard, Quantum Core Institute, Version 2.3, September 23, 2026, Clause 6.9. Supports: P4 level criteria.
    2. QCI-QS1 Quantum Readiness and Post-Quantum Cryptography Governance Standard, Quantum Core Institute, Version 2.3, September 23, 2026, Clause 6.2. Supports: Completion definition.
    3. QCI-QS1 Quantum Readiness and Post-Quantum Cryptography Governance Standard, Quantum Core Institute, Version 2.3, September 23, 2026, Clause 4.7. Supports: Testing and acceptance.

    Back to QCI-QS1 scoring: pillars and gates · All Knowledge Center topics

    Page history

    Published
    Not yet recorded
    Standard edition
    QCI-QS1 v2.3 (September 23, 2026)

    Cite this page

    Quantum Core Institute. (n.d.). Pillar 4: PQC migration readiness and crypto agility. https://quantumcoreinstitute.com/learn/qci-qs1/migration-readiness-pillar

    Link: https://quantumcoreinstitute.com/learn/qci-qs1/migration-readiness-pillar