What should you ask vendors about PQC?
Ask each vendor about the specific product and release you use: its cryptographic footprint, supported standards and dated milestones, upgrade path, testing and validation, your responsibilities and costs, and how it will disclose changes and incidents. Ask for evidence, not just answers. For QCI-QS1 conformance, every critical supplier request must cover areas A–F of Clause 7.2, which Annex C turns into specific questions.
New to this? Read What is supplier PQC readiness? first. After this, continue with What is a PQC supplier attestation?.
In one sentence: Ask product-specific questions, request evidence for each answer, and keep QCI-required areas separate from your own procurement questions.
Why it matters
Generic questionnaires produce generic answers. A request that asks for scope, dates and evidence lets you tell present capability from future intent.
Under QCI-QS1 the request must seek evidence attachments or controlled access, and unavailable evidence is recorded as a limitation (QCI-7.2-01).
Required QCI request areas (Clause 7.2, Annex C)
Clause 7.2 requires these areas for every critical supplier. Annex C is an informative template that operationalizes them; summaries below paraphrase it. Annex C also asks responders to distinguish present capability, customer deployment, future commitment and unknown information in every relevant answer.
| Area | What to ask (Annex C summary) | Evidence to request |
|---|---|---|
| A Product scope and footprint | Legal entity, product, releases, deployment models, subservices and exclusions; cryptographic functions, algorithms, protocols, libraries and key or trust dependencies; available versus default versus enabled versus observed use | Scoped CBOM or equivalent, with producer, method and limitations |
| B Roadmap and milestones | Target standards and profiles, release, pilot and production dates, owners; binding commitments versus estimates; limitations, end-of-support, and what happens if dates slip | Dated roadmap with owners; notification process |
| C Agility and upgrade path | Algorithm selection, credential and trust-anchor rollover, key migration, rollback, legacy-path retirement; hybrid or PQC-only constructions; authentication separate from key establishment; experimental mechanisms | Configuration documentation; interoperability evidence |
| D Testing and assurance | Performance, interoperability, invalid-input, downgrade and recovery results; algorithm tests, module validation and independent reviews identified separately | Test reports with versions and configurations; certificate numbers and caveats |
| E Customer obligations and support | Actions the customer must take; responsibility matrix; costs, support life, lead times, interruption, evidence-access rights, change notice, migration help, portability and exit | Responsibility matrix; commercial and support terms |
| F Disclosure and incident readiness | Vulnerability disclosure, notification timing, emergency updates, key compromise handling; how material changes refresh inventories and attestations; correcting earlier inaccurate claims | Disclosure policy; change-notification procedure |
| G AI platform posture (where applicable) | Questions G1–G5 for suppliers operating AI platforms, model registries or AI artifact key management (QCI-6.4-01) | Signature, channel and key-protection evidence for AI artifacts |
Proposed procurement questions (not QCI requirements)
These are editorial suggestions you may add for your own procurement. They are not required for QCI-QS1 conformance.
- Which named contact owns your PQC roadmap for this product?
- Will you participate in a joint interoperability test with our environment?
- Which customer reference configurations have you tested?
- How long will you support the classical path after the PQC option ships?
Handling the responses
- Set a response deadline no later than 60 calendar days after issue, unless an earlier obligation applies (QCI-7.2-04).
- Record engineering and vendor-risk acceptance, or the reasons a response is inadequate (QCI-7.2-03).
- Send nonresponse or inadequate responses at the deadline into exception and escalation (QCI-7.2-04).
- Evaluate supplier CBOM evidence under Clause 5.4 and validation claims under Clause 4.8 (QCI-7.2-04).
What organizations should do
- Issue the A–F request (plus G where applicable) to every critical supplier.
- Name the product, release and deployment in each request.
- Ask for evidence attachments or controlled access, not narrative answers only.
- Set and track a deadline of no more than 60 days.
- Keep your own extra questions labeled separately from QCI-required areas.
Evidence an auditor should expect
Rows marked "QCI requirement" come from the standard. Rows marked "Editorial suggestion" are QCI's practical advice and are not requirements.
| Artifact | Scope | Owner | Currency | Verification | Basis |
|---|---|---|---|---|---|
| Issued supplier request | Each critical supplier | Supplier relationship owner | Per request cycle | Check areas A–F (and G where applicable) are covered | QCI requirement (QCI-7.2-01) |
| Response deadline and escalation record | Each request | Vendor-risk lead | At deadline | Check deadline ≤ 60 days and escalation of gaps | QCI requirement (QCI-7.2-04) |
| Adequacy decision | Each response | Engineering and vendor-risk reviewers | At review | Check acceptance or reasons for inadequacy are recorded | QCI requirement (QCI-7.2-03) |
How NIST or other primary authorities address it
This concept originates with QCI in QCI-QS1. NIST and other standards bodies do not define or endorse it.
How QCI-QS1 addresses it
The six request areas and the 60-day deadline are QCI-QS1 requirements. Annex C wording is informative: it shows one way to ask, and does not add obligations.
| Requirement | Clause | Relationship | Pillar | Gate |
|---|---|---|---|---|
| QCI-7.2-01 | 7.2 | explicit requirement | P5 | G70 |
| QCI-7.2-04 | 7.2 | explicit requirement | P5 | G70 |
| QCI-6.4-01 | 6.4 | explicit requirement | P5 | — |
| QCI-7.2-03 | 7.2 | supporting evidence | P5 | G70 |
Common mistakes
- Asking "Are you quantum-safe?" instead of naming the product and release.
- Accepting answers without evidence or controlled access.
- Mixing your own procurement questions into the QCI-required set without labels.
- Leaving deadlines open-ended.
Questions for the board
- Has every critical supplier received the full request, and how many responses are overdue?
- Which responses were judged inadequate, and what happened next?
Questions
Do I have to use Annex C word for word?
No. Annex C is informative. The requirement is that every critical supplier request covers areas A–F of Clause 7.2, plus G1–G5 for applicable AI suppliers (QCI-7.2-01).
How long should vendors have to respond?
QCI-QS1 sets the deadline at no later than 60 calendar days after issue, unless an earlier obligation applies (QCI-7.2-04).
What if the vendor says the information is confidential?
The request may seek controlled evidence access instead of attachments. Evidence that remains unavailable is recorded and assessed as a limitation (QCI-7.2-01).
Sources
- QCI-QS1 Quantum Readiness and Post-Quantum Cryptography Governance Standard, Quantum Core Institute, Version 2.3, September 23, 2026, Clause 7. Supports: Supplier identification, request content, adequacy, attestation and oversight.
- QCI-QS1 Quantum Readiness and Post-Quantum Cryptography Governance Standard, Quantum Core Institute, Version 2.3, September 23, 2026, Annex C. Supports: Vendor roadmap request pack (informative template implementing Clause 7).
- QCI-QS1 Quantum Readiness and Post-Quantum Cryptography Governance Standard, Quantum Core Institute, Version 2.3, September 23, 2026, Clause 6.4. Supports: AI supplier questions G1–G5.
Related learning
Before this
Back to Suppliers and procurement · All Knowledge Center topics
Page history
- Published
- Not yet recorded
- Standard edition
- QCI-QS1 v2.3 (September 23, 2026)
Cite this page
Quantum Core Institute. (n.d.). What should you ask vendors about PQC?. https://quantumcoreinstitute.com/learn/suppliers/pqc-vendor-questions
Link: https://quantumcoreinstitute.com/learn/suppliers/pqc-vendor-questions