Implementation

    What should you ask vendors about PQC?

    Ask each vendor about the specific product and release you use: its cryptographic footprint, supported standards and dated milestones, upgrade path, testing and validation, your responsibilities and costs, and how it will disclose changes and incidents. Ask for evidence, not just answers. For QCI-QS1 conformance, every critical supplier request must cover areas A–F of Clause 7.2, which Annex C turns into specific questions.

    New to this? Read What is supplier PQC readiness? first. After this, continue with What is a PQC supplier attestation?.

    In one sentence: Ask product-specific questions, request evidence for each answer, and keep QCI-required areas separate from your own procurement questions.

    Why it matters

    Generic questionnaires produce generic answers. A request that asks for scope, dates and evidence lets you tell present capability from future intent.

    Under QCI-QS1 the request must seek evidence attachments or controlled access, and unavailable evidence is recorded as a limitation (QCI-7.2-01).

    Required QCI request areas (Clause 7.2, Annex C)

    Clause 7.2 requires these areas for every critical supplier. Annex C is an informative template that operationalizes them; summaries below paraphrase it. Annex C also asks responders to distinguish present capability, customer deployment, future commitment and unknown information in every relevant answer.

    QCI-QS1 required request areas and example evidence
    AreaWhat to ask (Annex C summary)Evidence to request
    A Product scope and footprintLegal entity, product, releases, deployment models, subservices and exclusions; cryptographic functions, algorithms, protocols, libraries and key or trust dependencies; available versus default versus enabled versus observed useScoped CBOM or equivalent, with producer, method and limitations
    B Roadmap and milestonesTarget standards and profiles, release, pilot and production dates, owners; binding commitments versus estimates; limitations, end-of-support, and what happens if dates slipDated roadmap with owners; notification process
    C Agility and upgrade pathAlgorithm selection, credential and trust-anchor rollover, key migration, rollback, legacy-path retirement; hybrid or PQC-only constructions; authentication separate from key establishment; experimental mechanismsConfiguration documentation; interoperability evidence
    D Testing and assurancePerformance, interoperability, invalid-input, downgrade and recovery results; algorithm tests, module validation and independent reviews identified separatelyTest reports with versions and configurations; certificate numbers and caveats
    E Customer obligations and supportActions the customer must take; responsibility matrix; costs, support life, lead times, interruption, evidence-access rights, change notice, migration help, portability and exitResponsibility matrix; commercial and support terms
    F Disclosure and incident readinessVulnerability disclosure, notification timing, emergency updates, key compromise handling; how material changes refresh inventories and attestations; correcting earlier inaccurate claimsDisclosure policy; change-notification procedure
    G AI platform posture (where applicable)Questions G1–G5 for suppliers operating AI platforms, model registries or AI artifact key management (QCI-6.4-01)Signature, channel and key-protection evidence for AI artifacts

    Proposed procurement questions (not QCI requirements)

    These are editorial suggestions you may add for your own procurement. They are not required for QCI-QS1 conformance.

    • Which named contact owns your PQC roadmap for this product?
    • Will you participate in a joint interoperability test with our environment?
    • Which customer reference configurations have you tested?
    • How long will you support the classical path after the PQC option ships?

    Handling the responses

    • Set a response deadline no later than 60 calendar days after issue, unless an earlier obligation applies (QCI-7.2-04).
    • Record engineering and vendor-risk acceptance, or the reasons a response is inadequate (QCI-7.2-03).
    • Send nonresponse or inadequate responses at the deadline into exception and escalation (QCI-7.2-04).
    • Evaluate supplier CBOM evidence under Clause 5.4 and validation claims under Clause 4.8 (QCI-7.2-04).

    What organizations should do

    1. Issue the A–F request (plus G where applicable) to every critical supplier.
    2. Name the product, release and deployment in each request.
    3. Ask for evidence attachments or controlled access, not narrative answers only.
    4. Set and track a deadline of no more than 60 days.
    5. Keep your own extra questions labeled separately from QCI-required areas.

    Evidence an auditor should expect

    Rows marked "QCI requirement" come from the standard. Rows marked "Editorial suggestion" are QCI's practical advice and are not requirements.

    Expected evidence
    ArtifactScopeOwnerCurrencyVerificationBasis
    Issued supplier requestEach critical supplierSupplier relationship ownerPer request cycleCheck areas A–F (and G where applicable) are coveredQCI requirement (QCI-7.2-01)
    Response deadline and escalation recordEach requestVendor-risk leadAt deadlineCheck deadline ≤ 60 days and escalation of gapsQCI requirement (QCI-7.2-04)
    Adequacy decisionEach responseEngineering and vendor-risk reviewersAt reviewCheck acceptance or reasons for inadequacy are recordedQCI requirement (QCI-7.2-03)

    How NIST or other primary authorities address it

    This concept originates with QCI in QCI-QS1. NIST and other standards bodies do not define or endorse it.

    How QCI-QS1 addresses it

    The six request areas and the 60-day deadline are QCI-QS1 requirements. Annex C wording is informative: it shows one way to ask, and does not add obligations.

    QCI-QS1 v2.3 mappings
    RequirementClauseRelationshipPillarGate
    QCI-7.2-017.2explicit requirementP5G70
    QCI-7.2-047.2explicit requirementP5G70
    QCI-6.4-016.4explicit requirementP5—
    QCI-7.2-037.2supporting evidenceP5G70

    Common mistakes

    • Asking "Are you quantum-safe?" instead of naming the product and release.
    • Accepting answers without evidence or controlled access.
    • Mixing your own procurement questions into the QCI-required set without labels.
    • Leaving deadlines open-ended.

    Questions for the board

    • Has every critical supplier received the full request, and how many responses are overdue?
    • Which responses were judged inadequate, and what happened next?

    Questions

    Do I have to use Annex C word for word?

    No. Annex C is informative. The requirement is that every critical supplier request covers areas A–F of Clause 7.2, plus G1–G5 for applicable AI suppliers (QCI-7.2-01).

    How long should vendors have to respond?

    QCI-QS1 sets the deadline at no later than 60 calendar days after issue, unless an earlier obligation applies (QCI-7.2-04).

    What if the vendor says the information is confidential?

    The request may seek controlled evidence access instead of attachments. Evidence that remains unavailable is recorded and assessed as a limitation (QCI-7.2-01).

    Sources

    1. QCI-QS1 Quantum Readiness and Post-Quantum Cryptography Governance Standard, Quantum Core Institute, Version 2.3, September 23, 2026, Clause 7. Supports: Supplier identification, request content, adequacy, attestation and oversight.
    2. QCI-QS1 Quantum Readiness and Post-Quantum Cryptography Governance Standard, Quantum Core Institute, Version 2.3, September 23, 2026, Annex C. Supports: Vendor roadmap request pack (informative template implementing Clause 7).
    3. QCI-QS1 Quantum Readiness and Post-Quantum Cryptography Governance Standard, Quantum Core Institute, Version 2.3, September 23, 2026, Clause 6.4. Supports: AI supplier questions G1–G5.

    Back to Suppliers and procurement · All Knowledge Center topics

    Page history

    Published
    Not yet recorded
    Standard edition
    QCI-QS1 v2.3 (September 23, 2026)

    Cite this page

    Quantum Core Institute. (n.d.). What should you ask vendors about PQC?. https://quantumcoreinstitute.com/learn/suppliers/pqc-vendor-questions

    Link: https://quantumcoreinstitute.com/learn/suppliers/pqc-vendor-questions