Definition

    What is a PQC supplier attestation?

    A PQC supplier attestation is a signed statement by an authorized officer of the supplier that describes, as of a stated date, the cryptography and transition capabilities of named products and releases. It separates verified present facts from future commitments, lists limitations and customer responsibilities, and references supporting evidence. It is the supplier's own claim, not independent assurance, and it must be refreshed when the cryptography changes.

    New to this? Read What is supplier PQC readiness? first. After this, continue with How do you evaluate a vendor's quantum-readiness claim?.

    In one sentence: An attestation is the supplier's signed, scoped and dated account of present cryptography and future commitments.

    Why it matters

    An attestation puts a named, authorized person behind specific statements. That makes claims reviewable and correctable.

    Under QCI-QS1, an authorized attestation is one condition of the G70 supplier gate, alongside an adequate roadmap response (QCI-6.3-01).

    What the attestation identifies (QCI-7.2-02)

    • The supplier legal entity.
    • Customer-facing products, services and releases covered.
    • The as-of date.
    • Verified facts kept separate from future commitments.
    • Algorithm and library inventory, supported profiles and migration milestones.
    • Customer transition steps and disclosure obligations.
    • Limitations, exclusions and evidence references.
    • Signatory name, role, authority, signature and date. An officer or equivalently authorized person signs.

    Attestation, roadmap, marketing statement and independent assurance

    Four kinds of supplier statement
    StatementWho makes itWhat it showsWhat it does not show
    Marketing statementSupplier marketingGeneral directionScope, dates, evidence or accountability
    RoadmapSupplier product teamPlanned dates and ownersPresent or deployed protection (QCI-7.1-02)
    AttestationAuthorized supplier signatoryScoped, dated present facts and commitmentsIndependent verification
    Independent assuranceA party independent of the supplierReview of claims against technical or customer evidenceAnything outside the reviewed sample or scope

    Dates and change notification

    Attestations are refreshed at least annually and on material cryptographic change; customer relevance and material changes are checked quarterly (QCI-7.2-03). Annex C area F asks how material changes trigger refreshed attestations and how inaccurate earlier claims are corrected.

    Relevance to G70

    G70 passes only when every critical supplier has a current, adequate product- and deployment-specific roadmap response and authorized attestation assessed under Clause 7 (QCI-6.3-01). A letter that is unscoped, undated, signed without authority, or unsupported by an adequate response does not meet that condition. Superseded or materially invalidated evidence does not pass G70 (QCI-7.2-03).

    What organizations should do

    1. Request the attestation with the response, using the Annex C form or an equivalent.
    2. Check the signatory's role and basis of authority.
    3. Check the products, releases and deployment models named match yours.
    4. Record the next refresh date and the change events that would invalidate it.

    Evidence an auditor should expect

    Rows marked "QCI requirement" come from the standard. Rows marked "Editorial suggestion" are QCI's practical advice and are not requirements.

    Expected evidence
    ArtifactScopeOwnerCurrencyVerificationBasis
    Signed supplier attestationNamed products and releasesSupplier signatory; held by relationship ownerRefreshed at least annually and on material changeCheck every QCI-7.2-02 element is presentQCI requirement (QCI-7.2-02)
    Receiving review recordEach attestationEngineering and vendor-risk reviewersAt receipt and quarterly relevance checkRecord adequacy decision, relevance and next reviewQCI requirement (QCI-7.2-03)

    How NIST or other primary authorities address it

    This concept originates with QCI in QCI-QS1. NIST and other standards bodies do not define or endorse it.

    How QCI-QS1 addresses it

    QCI-QS1 sets the attestation's content and signatory, its refresh cadence, and its role in G70. The Annex C attestation form is an informative example.

    QCI-QS1 v2.3 mappings
    RequirementClauseRelationshipPillarGate
    QCI-7.2-027.2explicit requirementP5G70
    QCI-7.2-037.2explicit requirementP5G70
    QCI-6.3-016.3explicit requirement—G70
    QCI-4.8-034.8supporting evidence——

    Common mistakes

    • Accepting a sales letter as an attestation.
    • Accepting a statement that blends present facts with plans.
    • Not checking the signatory's authority.
    • Keeping an attestation after the product's cryptography has changed.

    Questions for the board

    • How many critical suppliers have a current authorized attestation, and when does each expire?
    • Which attestations are supported by independent review?

    Questions

    Is an attestation the same as a certification?

    No. It is the supplier's own signed statement. Independent assurance means a party independent of the supplier has checked claims against evidence.

    Does any signed letter satisfy G70?

    No. G70 requires a current, adequate product- and deployment-specific roadmap response and an authorized attestation for every critical supplier, assessed under Clause 7 (QCI-6.3-01).

    Can risk acceptance stand in for a missing attestation?

    Risk acceptance may permit continued service but does not satisfy G70, and an approved operating exception is not a substitute (QCI-7.2-04, QCI-6.3-01).

    Sources

    1. QCI-QS1 Quantum Readiness and Post-Quantum Cryptography Governance Standard, Quantum Core Institute, Version 2.3, September 23, 2026, Clause 7. Supports: Supplier identification, request content, adequacy, attestation and oversight.
    2. QCI-QS1 Quantum Readiness and Post-Quantum Cryptography Governance Standard, Quantum Core Institute, Version 2.3, September 23, 2026, Annex C. Supports: Vendor roadmap request pack (informative template implementing Clause 7).
    3. QCI-QS1 Quantum Readiness and Post-Quantum Cryptography Governance Standard, Quantum Core Institute, Version 2.3, September 23, 2026, Clause 6.3. Supports: G70 supplier gate pass condition.
    4. QCI-QS1 Quantum Readiness and Post-Quantum Cryptography Governance Standard, Quantum Core Institute, Version 2.3, September 23, 2026, Clause 4.8. Supports: Distinguishing supplier assertion from testing and validation.

    Back to Suppliers and procurement · All Knowledge Center topics

    Page history

    Published
    Not yet recorded
    Standard edition
    QCI-QS1 v2.3 (September 23, 2026)

    Cite this page

    Quantum Core Institute. (n.d.). What is a PQC supplier attestation?. https://quantumcoreinstitute.com/learn/suppliers/pqc-supplier-attestation

    Link: https://quantumcoreinstitute.com/learn/suppliers/pqc-supplier-attestation