Cookie Preferences

    We use cookies to ensure our website functions properly and to improve your experience. Essential cookies are always active. You can choose to enable other categories below. Review our cookie policy

    Think Earlier.

    A number you can defend twelve months from now, not a claim you have to walk back.

    QCI-QS1 Clause 6 · Published Methodology

    Q-Risk Score Methodology

    The Q-Risk Score is a 0–100 quantum risk metric scored across five weighted pillars, constrained by hard ceilings that prevent inflated posture claims. The methodology is published, auditable, and aligned to QCI-QS1.

    Think earlier. Act when the evidence says to act.

    The Formula

    Raw score = 4 × P1 + 4 × P2 + 4 × P3 + 5 × P4 + 3 × P5
    Final score = min(raw score, every triggered gate cap)
    
    Each pillar level is an evidenced integer from 0 to 5.
    G60, G70 and G80 cap the result at 60, 70 and 80 when failed.

    The Core formula uses the five evidenced pillar levels. The final result cannot exceed any failed gate's cap. A not-applicable pillar does not receive redistributed weight or a 0–100 total.

    The Five Pillars

    Governance and accountability

    20% weight

    Ownership, risk decisions, obligations, oversight and reporting.

    Named ownerObligations registerBoard reporting

    Crypto visibility and QASI completeness

    20% weight

    Validated inventory of critical systems, critical data flows and cryptographic dependencies.

    Critical-system coverageCritical-flow coverageDiscovery provenance

    Data longevity and exposure management

    20% weight

    Confidentiality and verification horizons, long-lived data and exposure through critical flows.

    Data horizonsHNDL exposureCritical flows

    PQC migration readiness and crypto agility

    25% weight

    Migration decisions, accepted protection and tested algorithm replacement.

    Migration recordCrypto-agility testAcceptance evidence

    Third-party readiness

    15% weight

    Current product-specific supplier roadmaps, authorized attestations and oversight.

    Critical suppliersRoadmap responsesAuthorized attestations

    Hard Ceilings

    The v2.3 gates cap a formal score when their pass conditions are not evidenced. The free 26-question screening does not verify or apply these gates.

    Ceiling: 60
    G60 · Inventory

    Both critical-system and critical-flow validated coverage must reach at least 95 percent, without an unresolved material population discrepancy.

    Ceiling: 70
    G70 · Suppliers

    Every critical supplier needs a current, adequate product/deployment-specific roadmap response and authorized attestation. An operating exception is not a substitute.

    Ceiling: 80
    G80 · Agility

    At least one critical trust pathway must pass an end-to-end crypto-agility test within the previous 12 months and after an invalidating material change.

    Methodology Properties

    Published: open, free, and versioned under QCI-QS1 Clause 6
    Auditable, every score traces to evidenced controls
    Reproducible, same inputs produce the same score
    Defensible: designed for board, regulator, and external assessor review
    Hard-ceiling enforced, no posture-only score inflation
    Aligned to QCI-QS1, clause-by-clause traceability

    Score Your Organization

    The free 26-question tool provides a self-reported screening estimate and priority areas. An evidenced QCI-QS1 v2.3 score requires pillar decisions and gate review.