What should PQC contract language address?
PQC contract discussions usually address which products and releases are in scope, which roadmap commitments are binding, how and when evidence is delivered, notice of cryptographic changes and incidents, cooperation on testing, support life, and responsibilities during transition and exit. This page offers discussion prompts, not boilerplate. Whether any term is enforceable, and what obligations apply, depends on the actual contract and jurisdiction.
New to this? Read What is supplier PQC readiness? first.
In one sentence: Use the contract to make supplier commitments, evidence and notice explicit; take legal advice on the wording.
Why it matters
Without agreed terms, a supplier may have no obligation to share evidence, give notice of changes or keep to its roadmap.
QCI-QS1 requires new or renewed material procurements to evaluate PQC profiles, migration support, upgrade cost and lead time, evidence access, support life, notification, and exit options, and material contractual gaps to be resolved or accepted before commitment (QCI-7.1-02).
Discussion prompts
These prompts are for procurement, legal and engineering to discuss with a supplier. They are not legally sufficient contract language.
| Topic | Prompts to discuss |
|---|---|
| Product scope | Which products, releases, deployment models and subservices are covered? What is excluded? |
| Roadmap commitments | Which milestones are binding and which are estimates? What happens if a date slips? |
| Evidence delivery | What evidence will be delivered, how often, and with what access rights? Will attestations be refreshed annually and on material change? |
| Change notice | How much notice of cryptographic changes, vulnerabilities and emergency updates will be given, and through which channel? |
| Testing cooperation | Will the supplier support joint interoperability and acceptance testing in a customer environment? |
| Support | How long will current and classical paths be supported? What are upgrade costs and lead times? |
| Transition and exit | Who does what during migration? How are data and keys made portable? What substitution or exit path exists? |
Where QCI-QS1 applies
- Material contractual gaps are resolved or accepted by the appropriate risk or procurement authority before commitment (QCI-7.1-02).
- At Pillar 5 level 4, material milestones and notification obligations are contractually established or have approved procurement exceptions (QCI-6.10-01).
- A supplier roadmap shall not be represented as deployed protection, whatever the contract says (QCI-7.1-02).
Limits of this page
QCI does not provide legal advice. This page does not state any statutory duty. Enforceability, remedies and legal obligations depend on the actual contract, governing law and jurisdiction. Sector rules may add requirements; record any that apply in your applicability register (QCI-2.2-01).
What organizations should do
- Add PQC topics to the review checklist for new and renewed material procurements.
- Agree which roadmap milestones are binding before signing.
- Agree evidence delivery and change-notice terms.
- Record any accepted contractual gap with the approving authority.
- Take legal advice on wording.
Evidence an auditor should expect
Rows marked "QCI requirement" come from the standard. Rows marked "Editorial suggestion" are QCI's practical advice and are not requirements.
| Artifact | Scope | Owner | Currency | Verification | Basis |
|---|---|---|---|---|---|
| Procurement PQC evaluation | Each new or renewed material procurement | Procurement lead with engineering | Before commitment | Check the QCI-7.1-02 factors were evaluated | QCI requirement (QCI-7.1-02) |
| Accepted contractual gap record | Each unresolved material gap | Risk or procurement authority | Before commitment | Check approver and rationale | QCI requirement (QCI-7.1-02) |
| Contract term summary | Critical supplier contracts | Supplier relationship owner | On renewal | Check milestones and notification terms are captured | Editorial suggestion |
How NIST or other primary authorities address it
This concept originates with QCI in QCI-QS1. NIST and other standards bodies do not define or endorse it.
How QCI-QS1 addresses it
QCI-QS1 requires procurements to evaluate these topics and resolve or accept material gaps. It does not prescribe contract wording.
| Requirement | Clause | Relationship | Pillar | Gate |
|---|---|---|---|---|
| QCI-7.1-02 | 7.1 | explicit requirement | P5 | — |
| QCI-6.10-01 | 6.10 | supporting evidence | P5 | — |
| QCI-7.3-01 | 7.3 | supporting evidence | P5 | — |
| QCI-2.2-01 | 2.2 | explanatory context | P1 | — |
Common mistakes
- Copying clause templates without legal review.
- Treating a contractual roadmap date as present protection.
- Signing renewals without evaluating PQC support and exit options.
- Leaving evidence-access rights undefined.
Questions for the board
- Which critical supplier contracts include PQC milestones and notification terms?
- Which material contractual gaps were accepted, and by whom?
Questions
Is there standard PQC contract language I can copy?
QCI does not publish legally sufficient boilerplate. Use the prompts on this page with your legal counsel; enforceability depends on the contract and jurisdiction.
Must every existing contract be renegotiated?
QCI-QS1 applies the procurement evaluation to new or renewed material procurements (QCI-7.1-02). Existing suppliers are still overseen under Clause 7.
Does a contract term satisfy G70?
No. G70 requires a current, adequate roadmap response and authorized attestation for every critical supplier (QCI-6.3-01). Contract terms can help you obtain them.
Sources
- QCI-QS1 Quantum Readiness and Post-Quantum Cryptography Governance Standard, Quantum Core Institute, Version 2.3, September 23, 2026, Clause 7. Supports: Supplier identification, request content, adequacy, attestation and oversight.
- QCI-QS1 Quantum Readiness and Post-Quantum Cryptography Governance Standard, Quantum Core Institute, Version 2.3, September 23, 2026, Clause 6.10. Supports: P5 supplier rubric.
- QCI-QS1 Quantum Readiness and Post-Quantum Cryptography Governance Standard, Quantum Core Institute, Version 2.3, September 23, 2026, Clause 2.2. Supports: Applicability register.
Related learning
Back to Suppliers and procurement · All Knowledge Center topics
Page history
- Published
- Not yet recorded
- Standard edition
- QCI-QS1 v2.3 (September 23, 2026)
Cite this page
Quantum Core Institute. (n.d.). What should PQC contract language address?. https://quantumcoreinstitute.com/learn/suppliers/pqc-contract-considerations
Link: https://quantumcoreinstitute.com/learn/suppliers/pqc-contract-considerations