Pillar 4: PQC migration readiness and crypto agility
Pillar 4 measures accepted production migration to approved cryptographic profiles and tested crypto agility. Plans, pilots and vendor availability do not count as completion. Levels move from an assigned roadmap to 90% and then 100% completion in each critical transition category, backed by representative testing. It is the most heavily weighted pillar: 5 points per level, up to 25.
New to this? Read Crypto agility: definition and practical demonstration first. After this, continue with What G80 means and how to satisfy it.
In one sentence: P4 counts what has been changed and accepted in production, not what is planned.
How this pillar differs from crypto agility
Crypto agility is the capability to change cryptographic algorithms, parameters and trust components without redesigning systems. Pillar 4 is the scored assessment of migration readiness and agility together, and it separates three kinds of evidence that are often blurred.
A plan shows intent. Execution evidence shows protection accepted in production or verified decommissioning (QCI-6.2-02). Test acceptance shows a tested change met its plan under Clause 4.7. A plan, a pilot, supplier availability or an accepted risk does not count as completion. P4 levels 4 and 5 require representative testing across distinct patterns, which is wider than the single-pathway proof that G80 requires.
What counts as migration completion
Completion means accepted production protection, or verified decommissioning with vulnerable dependency retirement. Supplier availability, a plan, an accepted risk or a pilot does not count. Deferring an item does not remove it from the denominator (QCI-6.2-02).
Acceptance requires engineering and service-owner approval of test results, monitoring, recovery and residual exceptions, plus evidence that legacy paths are removed or excepted (QCI-4.7-02).
Evidence required at each level
Levels are cumulative. An organization receives the highest level for which every criterion at that level and all lower positive levels is supported. Unsupported, contradictory or stale evidence fails the affected criterion, and fractional levels are not allowed (QCI-6.1-01).
| Level | Required evidence |
|---|---|
| 0 | One or more level 1 criteria are unsupported. |
| 1 | Vulnerable dependencies and initial approved target candidates identified; engineering owners assigned. |
| 2 | Approved profiles and a prioritized, resourced dependency roadmap with acceptance, recovery and retirement criteria; long-lead replacement decisions recorded. |
| 3 | A representative pilot has passed applicable Clause 4.7 tests; at least one critical production transition accepted, or current evidence shows no critical transition is needed. |
| 4 | At least 90% completion in each critical transition category; every remaining item has an owned deadline and treatment; representative operational tests cover deployed patterns and recovery/fallback. |
| 5 | 100% completion in each category; no unauthorized legacy critical path; current representative tests and independent review confirm configuration, trust/key lifecycle, recovery and retirement evidence. |
Representative testing
At levels 4 and 5, representative testing covers each materially distinct critical protocol, trust, key-management and deployment pattern. A documented equivalence analysis may justify shared tests (QCI-6.9-01). This is broader than the single-pathway test that satisfies G80.
How NIST or other primary authorities address it
This concept originates with QCI in QCI-QS1. NIST and other standards bodies do not define or endorse it.
How QCI-QS1 addresses it
P4 is levelled against Clause 6.9. Completion is defined in Clause 6.2 and acceptance in Clause 4.7.
| Requirement | Clause | Relationship | Pillar | Gate |
|---|---|---|---|---|
| QCI-6.9-01 | 6.9 | explicit requirement | P4 | — |
| QCI-6.2-02 | 6.2 | explicit requirement | P4 | — |
| QCI-4.7-01 | 4.7 | supporting evidence | P4 | — |
| QCI-4.7-02 | 4.7 | supporting evidence | P4 | — |
Common mistakes
- Counting a pilot or vendor release as completion (QCI-4.7-02).
- Dropping deferred items from the denominator (QCI-6.2-02).
Questions
How many points can Pillar 4 contribute?
Up to 25. Each level adds 5 points in the formula R = 4×L1 + 4×L2 + 4×L3 + 5×L4 + 3×L5 (QCI-6.1-02).
Can a pillar be marked not applicable?
Only where its entire subject population is demonstrably absent and that absence is independently checked. Weight is not redistributed, and no 0–100 total or band is published while a pillar is not applicable (QCI-6.1-03).
Does a successful pilot count toward P4 completion?
No. A pilot can support level 3, but completion percentages count only accepted production protection or verified decommissioning (QCI-6.2-02, QCI-4.7-02).
Sources
- QCI-QS1 Quantum Readiness and Post-Quantum Cryptography Governance Standard, Quantum Core Institute, Version 2.3, September 23, 2026, Clause 6.9. Supports: P4 level criteria.
- QCI-QS1 Quantum Readiness and Post-Quantum Cryptography Governance Standard, Quantum Core Institute, Version 2.3, September 23, 2026, Clause 6.2. Supports: Completion definition.
- QCI-QS1 Quantum Readiness and Post-Quantum Cryptography Governance Standard, Quantum Core Institute, Version 2.3, September 23, 2026, Clause 4.7. Supports: Testing and acceptance.
Related learning
Elsewhere
Guides for this pillar
Back to QCI-QS1 scoring: pillars and gates · All Knowledge Center topics
Page history
- Published
- Not yet recorded
- Standard edition
- QCI-QS1 v2.3 (September 23, 2026)
Cite this page
Quantum Core Institute. (n.d.). Pillar 4: PQC migration readiness and crypto agility. https://quantumcoreinstitute.com/learn/qci-qs1/migration-readiness-pillar
Link: https://quantumcoreinstitute.com/learn/qci-qs1/migration-readiness-pillar