What is a PQC supplier attestation?
A PQC supplier attestation is a signed statement by an authorized officer of the supplier that describes, as of a stated date, the cryptography and transition capabilities of named products and releases. It separates verified present facts from future commitments, lists limitations and customer responsibilities, and references supporting evidence. It is the supplier's own claim, not independent assurance, and it must be refreshed when the cryptography changes.
New to this? Read What is supplier PQC readiness? first. After this, continue with How do you evaluate a vendor's quantum-readiness claim?.
In one sentence: An attestation is the supplier's signed, scoped and dated account of present cryptography and future commitments.
Why it matters
An attestation puts a named, authorized person behind specific statements. That makes claims reviewable and correctable.
Under QCI-QS1, an authorized attestation is one condition of the G70 supplier gate, alongside an adequate roadmap response (QCI-6.3-01).
What the attestation identifies (QCI-7.2-02)
- The supplier legal entity.
- Customer-facing products, services and releases covered.
- The as-of date.
- Verified facts kept separate from future commitments.
- Algorithm and library inventory, supported profiles and migration milestones.
- Customer transition steps and disclosure obligations.
- Limitations, exclusions and evidence references.
- Signatory name, role, authority, signature and date. An officer or equivalently authorized person signs.
Attestation, roadmap, marketing statement and independent assurance
| Statement | Who makes it | What it shows | What it does not show |
|---|---|---|---|
| Marketing statement | Supplier marketing | General direction | Scope, dates, evidence or accountability |
| Roadmap | Supplier product team | Planned dates and owners | Present or deployed protection (QCI-7.1-02) |
| Attestation | Authorized supplier signatory | Scoped, dated present facts and commitments | Independent verification |
| Independent assurance | A party independent of the supplier | Review of claims against technical or customer evidence | Anything outside the reviewed sample or scope |
Dates and change notification
Attestations are refreshed at least annually and on material cryptographic change; customer relevance and material changes are checked quarterly (QCI-7.2-03). Annex C area F asks how material changes trigger refreshed attestations and how inaccurate earlier claims are corrected.
Relevance to G70
G70 passes only when every critical supplier has a current, adequate product- and deployment-specific roadmap response and authorized attestation assessed under Clause 7 (QCI-6.3-01). A letter that is unscoped, undated, signed without authority, or unsupported by an adequate response does not meet that condition. Superseded or materially invalidated evidence does not pass G70 (QCI-7.2-03).
What organizations should do
- Request the attestation with the response, using the Annex C form or an equivalent.
- Check the signatory's role and basis of authority.
- Check the products, releases and deployment models named match yours.
- Record the next refresh date and the change events that would invalidate it.
Evidence an auditor should expect
Rows marked "QCI requirement" come from the standard. Rows marked "Editorial suggestion" are QCI's practical advice and are not requirements.
| Artifact | Scope | Owner | Currency | Verification | Basis |
|---|---|---|---|---|---|
| Signed supplier attestation | Named products and releases | Supplier signatory; held by relationship owner | Refreshed at least annually and on material change | Check every QCI-7.2-02 element is present | QCI requirement (QCI-7.2-02) |
| Receiving review record | Each attestation | Engineering and vendor-risk reviewers | At receipt and quarterly relevance check | Record adequacy decision, relevance and next review | QCI requirement (QCI-7.2-03) |
How NIST or other primary authorities address it
This concept originates with QCI in QCI-QS1. NIST and other standards bodies do not define or endorse it.
How QCI-QS1 addresses it
QCI-QS1 sets the attestation's content and signatory, its refresh cadence, and its role in G70. The Annex C attestation form is an informative example.
| Requirement | Clause | Relationship | Pillar | Gate |
|---|---|---|---|---|
| QCI-7.2-02 | 7.2 | explicit requirement | P5 | G70 |
| QCI-7.2-03 | 7.2 | explicit requirement | P5 | G70 |
| QCI-6.3-01 | 6.3 | explicit requirement | — | G70 |
| QCI-4.8-03 | 4.8 | supporting evidence | — | — |
Common mistakes
- Accepting a sales letter as an attestation.
- Accepting a statement that blends present facts with plans.
- Not checking the signatory's authority.
- Keeping an attestation after the product's cryptography has changed.
Questions for the board
- How many critical suppliers have a current authorized attestation, and when does each expire?
- Which attestations are supported by independent review?
Questions
Is an attestation the same as a certification?
No. It is the supplier's own signed statement. Independent assurance means a party independent of the supplier has checked claims against evidence.
Does any signed letter satisfy G70?
No. G70 requires a current, adequate product- and deployment-specific roadmap response and an authorized attestation for every critical supplier, assessed under Clause 7 (QCI-6.3-01).
Can risk acceptance stand in for a missing attestation?
Risk acceptance may permit continued service but does not satisfy G70, and an approved operating exception is not a substitute (QCI-7.2-04, QCI-6.3-01).
Sources
- QCI-QS1 Quantum Readiness and Post-Quantum Cryptography Governance Standard, Quantum Core Institute, Version 2.3, September 23, 2026, Clause 7. Supports: Supplier identification, request content, adequacy, attestation and oversight.
- QCI-QS1 Quantum Readiness and Post-Quantum Cryptography Governance Standard, Quantum Core Institute, Version 2.3, September 23, 2026, Annex C. Supports: Vendor roadmap request pack (informative template implementing Clause 7).
- QCI-QS1 Quantum Readiness and Post-Quantum Cryptography Governance Standard, Quantum Core Institute, Version 2.3, September 23, 2026, Clause 6.3. Supports: G70 supplier gate pass condition.
- QCI-QS1 Quantum Readiness and Post-Quantum Cryptography Governance Standard, Quantum Core Institute, Version 2.3, September 23, 2026, Clause 4.8. Supports: Distinguishing supplier assertion from testing and validation.
Related learning
Back to Suppliers and procurement · All Knowledge Center topics
Page history
- Published
- Not yet recorded
- Standard edition
- QCI-QS1 v2.3 (September 23, 2026)
Cite this page
Quantum Core Institute. (n.d.). What is a PQC supplier attestation?. https://quantumcoreinstitute.com/learn/suppliers/pqc-supplier-attestation
Link: https://quantumcoreinstitute.com/learn/suppliers/pqc-supplier-attestation