Cookie Preferences

    We use cookies to ensure our website functions properly and to improve your experience. Essential cookies are always active. You can choose to enable other categories below. Learn more

    QCI-QS1 Clause 6 · Published Methodology

    Q-Risk Score Methodology

    The Q-Risk Score is a 0–100 quantum risk metric scored across five weighted pillars, constrained by hard ceilings that prevent inflated posture claims. The methodology is published, auditable, and aligned to QCI-QS1.

    The Formula

    Q-Risk Score = min(
      HardCeiling(controls),
      0.25 × CryptographicExposure
    + 0.20 × GovernanceReadiness
    + 0.20 × TechnicalPreparedness
    + 0.20 × StrategicAlignment
    + 0.15 × OperationalResilience
    )
    
    Each pillar is scored 0–100 from evidenced controls.
    HardCeiling enforces caps when foundational controls are absent.

    The hard-ceiling operator is what separates Q-Risk from posture-only scoring models. A weighted sum alone allows organizations to compensate for missing foundations with cosmetic controls. The Q-Risk methodology refuses that trade.

    The Five Pillars

    Cryptographic Exposure

    25% weight

    Current cryptographic infrastructure vulnerability — share of RSA, ECC, and DH dependencies across identity, payments, and data systems.

    QASI completenessVendor PQC roadmapLong-life data exposure (HNDL)

    Governance Readiness

    20% weight

    Board oversight, accountable executive, documented quantum risk appetite, and integration into enterprise risk management.

    QRAF roles assignedBoard attestation cadencePolicy coverage

    Technical Preparedness

    20% weight

    Infrastructure and talent readiness to execute migration — crypto agility, CA/PKI modernization, and engineering capacity.

    Crypto agility maturityCertificate lifecycle automationPQC pilot status

    Strategic Alignment

    20% weight

    Integration of quantum risk into enterprise risk, vendor management, M&A diligence, and capital planning.

    Vendor oversight (Clause 7)Procurement clausesMulti-year funding plan

    Operational Resilience

    15% weight

    Incident response, crypto-failure playbooks, and continuity testing for cryptographic outages or forced algorithm migration.

    Crisis simulation resultsRollback proceduresDetection capability

    Hard Ceilings

    Hard ceilings are non-negotiable caps that prevent inflated scores when foundational controls are absent. They are how Q-Risk stays defensible to auditors, boards, and regulators.

    Ceiling: 49
    No QASI inventory in last 12 months

    Without a cryptographic inventory, no other control can be reliably evidenced.

    Ceiling: 59
    No board-level quantum risk owner

    Governance accountability is a precondition for sustained program execution.

    Ceiling: 69
    Critical vendors with no PQC roadmap

    Third-party dependencies materially constrain enterprise migration timelines.

    Ceiling: 74
    No crypto-agility for certificate or algorithm rotation

    Inability to swap algorithms creates an unrecoverable operational risk.

    Methodology Properties

    Published — open, free, and versioned under QCI-QS1 Clause 6
    Auditable — every score traces to evidenced controls
    Reproducible — same inputs produce the same score
    Defensible — designed for board, regulator, and external assessor review
    Hard-ceiling enforced — no posture-only score inflation
    Aligned to QCI-QS1 — clause-by-clause traceability

    Score Your Organization

    The Q-Risk Score assessment takes about 15 minutes and produces a board-ready report with pillar breakdowns, applicable hard ceilings, and a prioritized remediation path.