Pillar 5: Third-party readiness
Pillar 5 measures how many critical suppliers have current, adequate post-quantum roadmap responses and authorized attestations, and how far their claims are checked against technical and customer evidence. Levels rise at 50%, 80% and then every critical supplier. A supplier roadmap is never treated as deployed protection. P5 contributes 3 points per level, up to 15.
New to this? Read Q-Risk Score and how scoring gates work first. After this, continue with What G70 means and how to satisfy it.
In one sentence: P5 asks whether critical suppliers have given adequate, signed and current evidence of readiness.
How this pillar differs from supplier readiness in general
Supplier readiness describes whether a vendor's products can support post-quantum protection. Pillar 5 assesses the organization's own oversight: whether every critical supplier is identified under Clause 7.1, whether requests were issued and answered, whether each response was accepted as adequate or rejected with reasons, and whether attestations are current (QCI-7.2-03).
A supplier roadmap is not deployed protection (QCI-7.1-02). P5 credits the organization's evidenced oversight of supplier posture, and G70 separately caps the score when any critical supplier lacks a current, adequate response and authorized attestation.
Which suppliers are in scope
Critical suppliers are those materially affecting identity and trust, signing, secure communications, key management, regulated or long-lived confidentiality, transaction integrity or relevant AI infrastructure, including cloud, SaaS, managed services and embedded products (QCI-7.1-01). Percentages use all identified critical suppliers in scope (QCI-6.10-01).
Evidence required at each level
Levels are cumulative. An organization receives the highest level for which every criterion at that level and all lower positive levels is supported. Unsupported, contradictory or stale evidence fails the affected criterion, and fractional levels are not allowed (QCI-6.1-01).
| Level | Required evidence |
|---|---|
| 0 | One or more level 1 criteria are unsupported. |
| 1 | Critical suppliers identified; accountable relationship owners assigned; initial requests issued. |
| 2 | Complete standard request issued to every critical supplier; deadlines, adequacy criteria and exception register operating; at least 50% have current adequate responses and attestations. |
| 3 | At least 80% have current adequate responses and attestations; shared responsibilities documented; missing or inadequate evidence escalated and treated. |
| 4 | Every critical supplier has a current adequate response and attestation; material milestones and notification obligations contractually established or covered by approved procurement exceptions; customer deployment evidence distinguished from supplier capability. |
| 5 | Independent review confirms a risk-based sample of supplier claims against technical/customer evidence; every due material milestone met or an approved alternative deployed; no overdue high-impact supplier finding. |
What makes a response adequate
A response is adequate only when it addresses every applicable request area, identifies product and deployment scope, separates available, configured and deployed posture, supplies assessable evidence for material present-tense claims, and gives owned, dated commitments and limitations (QCI-7.2-03).
How NIST or other primary authorities address it
This concept originates with QCI in QCI-QS1. NIST and other standards bodies do not define or endorse it.
How QCI-QS1 addresses it
P5 is levelled against Clause 6.10, with adequacy and attestation defined in Clause 7.
| Requirement | Clause | Relationship | Pillar | Gate |
|---|---|---|---|---|
| QCI-6.10-01 | 6.10 | explicit requirement | P5 | — |
| QCI-7.1-01 | 7.1 | explicit requirement | P5 | — |
| QCI-7.1-02 | 7.1 | explicit requirement | P5 | — |
| QCI-7.2-03 | 7.2 | explicit requirement | P5 | G70 |
Common mistakes
- Representing a supplier roadmap as deployed protection (QCI-7.1-02).
- Treating supplier capability as proof of the organization's own deployment.
Questions
How many points can Pillar 5 contribute?
Up to 15. Each level adds 3 points in the formula R = 4×L1 + 4×L2 + 4×L3 + 5×L4 + 3×L5 (QCI-6.1-02).
Can a pillar be marked not applicable?
Only where its entire subject population is demonstrably absent and that absence is independently checked. Weight is not redistributed, and no 0–100 total or band is published while a pillar is not applicable (QCI-6.1-03).
Does a supplier roadmap count as deployed protection?
No. A supplier roadmap shall not be represented as deployed protection (QCI-7.1-02).
Sources
- QCI-QS1 Quantum Readiness and Post-Quantum Cryptography Governance Standard, Quantum Core Institute, Version 2.3, September 23, 2026, Clause 6.10. Supports: P5 level criteria.
- QCI-QS1 Quantum Readiness and Post-Quantum Cryptography Governance Standard, Quantum Core Institute, Version 2.3, September 23, 2026, Clause 7.1–7.2. Supports: Supplier scope and adequacy.
Related learning
Before this
Elsewhere
Guides for this pillar
Back to QCI-QS1 scoring: pillars and gates · All Knowledge Center topics
Page history
- Published
- Not yet recorded
- Standard edition
- QCI-QS1 v2.3 (September 23, 2026)
Cite this page
Quantum Core Institute. (n.d.). Pillar 5: Third-party readiness. https://quantumcoreinstitute.com/learn/qci-qs1/third-party-readiness-pillar
Link: https://quantumcoreinstitute.com/learn/qci-qs1/third-party-readiness-pillar