Skip to content
readiness control date · not a CRQC forecast

Post-Quantum Ready. Field Book.

Executive Field Book / 2026 Edition

QScoutFINDQStrikePROVEQSolveFIXQ-LabVALIDATE
Chapter 01

From Mandate to Operating Control

From theory to measurable control.

Post-quantum cryptography is no longer a research question. Federal mandates, standards bodies, and procurement frameworks have converged on a single conclusion: organizations that depend on public-key cryptography must begin migration now, or accept unquantified risk to every system that stores, transmits, or signs sensitive data.

The path from mandate to operating control follows three steps: Inventory every cryptographic dependency across the enterprise, Validate each dependency against current and emerging threat models, and Migrate to quantum-resistant alternatives on a risk-prioritized schedule.

This is a continuous control loop, not a one-time project. Cryptographic posture must be measured, reported, and improved continuously as algorithms are deprecated, new threat intelligence emerges, and compliance frameworks tighten.

Federal Timeline

2022OMB M-23-02 mandates cryptographic inventory for all federal agencies
Aug 2024NIST publishes FIPS 203, 204, 205 — first post-quantum standards finalized
Jan 2027CNSA 2.0 expected for new products and services unless a program stipulation or waiver applies
Dec 2030Equipment that does not support CNSA 2.0 should be replaced where required
Dec 2031CNSA 2.0 mandated for affected systems unless an exception applies

Risk Quadrant: Exposure x Shelf Life

The quantum risk to any given system is a function of two variables: how exposed its cryptographic surface is today, and how long the data it protects must remain confidential. Systems with high exposure and long shelf life — classified records, financial instruments, healthcare data — face the most urgent migration pressure.

Low Exposure

Short Shelf Life

Monitor

High Exposure

Short Shelf Life

Plan

Low Exposure

Long Shelf Life

Prioritize

High Exposure

Long Shelf Life

Migrate Now

Mosca's Theorem: X + Y > Z

Michele Mosca's inequality frames the urgency precisely. If X (the time a secret must remain secure) plus Y (the time required to migrate the system) exceeds Z (the time until a cryptanalytically relevant quantum computer exists), then the data is already at risk. Harvest-now-decrypt-later attacks make this inequality actionable today, not at some future date when quantum hardware matures.

Chapter 03

QScout

QScout turns a public domain into an executive snapshot.

QScout is the entry point of the Qtonic Quantum Suite. It takes a single public domain and produces a buyer-readable executive snapshot: a letter grade, severity profile, HNDL exposure indicator, and a clear decision on whether deeper investigation is warranted. No agent installation. No network access. No credentials.

The QScout approved-scope public intake is the default delivery lane. It scans externally visible cryptographic surfaces — TLS configuration, certificate chains, key exchange parameters, cipher suite negotiation — and maps each finding to a scored check family with methodology citations.

Delivery Lanes

Default

QScout public intake

Requester-verified website snapshot from authorized public surface. Buyer-readable executive snapshot.

Authorized

public/credentialed/privileged scope

Governed follow-on paths with approved scope, credentials, privileged access, CBOM, and evidence depth as authorized.

Report family

Pulse (report family)

The QScout report family across Surface, Silver, and Gold. Reassessment or continuity work is separately scoped; not a fourth tier and not a public continuous-monitoring product.

QScout Public Intake Authorization Model

The QScout approved-scope snapshot operates entirely on publicly available information. It connects only to the publicly advertised TLS endpoints of the target domain. No authentication credentials are used. No internal network access is required. No agent or software is installed on the target. The scan is equivalent to what any browser or automated client would observe when connecting to the domain. This model keeps the snapshot to publicly observable information — no credentials, no internal access, and nothing installed on the target — while delivery remains gated by requester verification and authorized public scope, with deeper assessment only under a governed engagement.

Six QScout Outputs

Executive Grade

A single letter grade (A through F) summarizing externally visible cryptographic posture.

HNDL Indicator

Harvest-now-decrypt-later exposure indicator based on observed key exchange and cipher suite configuration.

Severity Profile

Distribution of findings across Critical, High, Medium, Low, and Informational severity bands.

Methodology Notes

Per-finding methodology citations linking each observation to its scoring rationale and check family.

CBOM Handoff

Cryptographic Bill of Materials structured for downstream QStrike validation or third-party integration.

Decision Snapshot

Clear recommendation on whether deeper investigation is warranted, with supporting evidence summary.

Visual Model: Public Snapshot to CBOM Handoff

Stage 1

Public Snapshot

TLS configuration, certificate chain, key exchange, and cipher suite analysis from public-facing endpoints.

Stage 2

Protocol Analysis

Deep inspection of negotiated protocol parameters, extension support, and session configuration.

Stage 3

Cryptographic Mapping

Algorithm inventory mapped to NIST PQC standards with gap analysis and migration priority.

Stage 4

CBOM Handoff

Structured output artifact for governance review, QStrike validation, or third-party tooling integration.

Artifacts That Survive Handoff

Every QScout output is designed to survive handoff to downstream systems and stakeholders. The executive grade and severity profile are formatted for board-level reporting. The CBOM is structured for ingestion by QStrike, GRC platforms, and third-party vulnerability management tools. Methodology notes provide the audit trail required for compliance documentation. The decision snapshot gives the CISO a defensible recommendation, not a data dump.

Open remaining field book chapters
Chapter 04

QStrike

QStrike validates the path, not just the weakness.

QStrike is a controlled forward-threat validation engine. Where QScout identifies exposure, QStrike tests whether that exposure can become a defensible attack path under approved scope. The public demonstration and buyer-specific validation use provider-calibrated modeled profiles and do not contact live quantum hardware. QStrike produces evidence packages that document the method, controls, and proof limits.

Validation Pipeline

Step 1

Provider Profiles

Six provider-aligned modeled profiles across four modalities.

Step 2

Exploit Harnesses

Target-specific exploit constructions mapped to the cryptographic surface identified by QScout.

Step 3

Red/Blue Team

Adversarial red team attempts exploitation. Blue team validates defensive posture. Independent arbiter scores.

Step 4

Arbiter Scoring

Confidence-weighted severity scoring with full evidence chain and reproducibility documentation.

6 Platform Profiles Across 4 Quantum Modalities

IBM Quantum

Superconducting

IonQ

Trapped Ion

Quantinuum

Trapped Ion

Rigetti

Superconducting

D-Wave

Quantum Annealing

QuEra

Neutral Atom

Proof Model

Evidence

Raw observations from exploit-harness execution against provider-calibrated modeled profiles or governed engagement-specific validation lanes.

Controlled Validation

Reproducible test execution with documented parameters, environmental conditions, and control baselines.

Signed Proof

Cryptographically signed artifact (ECDSA-P256-SHA256 today; ML-DSA-65 migration in flight) documenting the complete evidence chain and scoring rationale.

Customer Verification

Independent verification path allowing the customer to validate proof integrity without trusting the issuer.

Challenge and Review

QStrike operates a three-role adversarial model: Red Team constructs and executes exploit harnesses. Blue Team validates defensive controls and identifies false positives. Arbiter independently scores each finding with confidence-weighted severity, resolving disagreements between red and blue.

Every QStrike finding carries a confidence-weighted severity score. The confidence weight reflects the reproducibility of the exploit, the quality of the modeled provider-calibration inputs, and the independence of the arbiter's assessment.

$2M Challenge Diligence

The $2M challenge applies only to qualifying QStrike engagements under the published challenge terms. If the qualifying engagement closes with no High or Critical findings and independent review later proves one existed in scope, Qtonic Quantum provides the stated challenge remedy under those terms. QScout is not covered by the $2M challenge.

Chapter 05

QSolve

QSolve turns measured exposure into migration discipline.

QSolve is the migration governance engine of the Qtonic Quantum Suite. It takes the measured exposure from QScout and the validated findings from QStrike and translates them into a structured migration program with clear ownership, dependencies, decision gates, and status tracking.

The governance board tracks every migration action across five dimensions: Owner (who is accountable), Risk (what is the exposure if migration is delayed), Dependency (what must happen first), Decision (what approval is required), and Status (current state of the migration action).

Governance Board

OwnerRiskDependencyDecisionStatus
CISOCriticalHSM upgradeBoard approvalIn Progress
VP EngineeringHighLibrary updateTech lead sign-offPlanned
Compliance LeadMediumAudit completionGRC reviewQueued

Five Migration Triggers

1

Critical Finding

QStrike validates a critical-severity quantum vulnerability with high confidence.

2

Compliance Deadline

A regulatory or mandate deadline requires migration action within a defined window.

3

Vendor Deprecation

A key vendor announces deprecation of a cryptographic primitive in active use.

4

Board Directive

The governance board or CISO issues a directive to begin migration for a specific system.

5

Drift Detection

Approved reassessment scope detects regression in cryptographic posture; not a public continuous-monitoring product promise.

Five Migration Workstreams

Security

Vulnerability remediation, cryptographic library upgrades, and key rotation across affected systems.

Infrastructure

Network configuration, certificate management, and HSM migration for quantum-resistant key material.

Engineering

Application-layer changes, protocol upgrades, and integration testing for PQC algorithm support.

Compliance

Documentation, audit trail generation, and regulatory reporting for NIST, CNSA 2.0, and sector-specific frameworks.

Procurement

Vendor assessment, contract review, and supply-chain validation for PQC-ready components and services.

Chapter 06

QLab

A scoring rubric built for the buyer's question.

QLab is an independent PQC solution evaluation platform. It scores post-quantum cryptography implementations across a published 10-dimension rubric with no paid inclusion, no vendor influence on rankings, and continuous re-testing against evolving threat models and standards.

200+

Implementations Scored

12

Categories

10

Scoring Dimensions

24/7

Continuous Testing

10 Scoring Dimensions

D01

Algorithm Strength

D02

Implementation Maturity

D03

Performance Profile

D04

Standards Compliance

D05

Interoperability

D06

Side-Channel Resistance

D07

Key Management

D08

Migration Readiness

D09

Vendor Stability

D10

Documentation Quality

Provenance Tags

Verified

Score derived from direct testing against vendor-supplied implementation with documented methodology.

Contested

Score challenged by vendor or third party. Under review with documented dispute timeline.

Inferred

Score derived from public documentation, published benchmarks, or third-party analysis. Not directly tested.

Degraded

Previously verified score degraded due to new vulnerability disclosure, vendor instability, or failed re-test.

Illustrative Scorecard

A-

PQC-KEM-073

Illustrative ML-KEM implementation scorecard

Algorithm Strength92/100
Implementation Maturity88/100
Performance Profile85/100
Standards Compliance94/100
Interoperability81/100
Side-Channel Resistance79/100
Key Management91/100
Migration Readiness87/100
Vendor Stability83/100
Documentation Quality90/100
Chapter 07

Team and Trust Model

Mission-tested leadership. Evidence-linked scoring.

Mission Pedigree

Leadership team drawn from defense, intelligence, and critical infrastructure backgrounds with direct experience in cryptographic operations, threat analysis, and secure system design.

Scoring Independence

Q-Lab scoring methodology is published, vendor-independent, and subject to challenge review. No paid inclusion. No vendor influence on rankings. Expert network provides independent validation.

Adjacency

Qtonic Quantum operates as a cryptographic readiness control plane — not a replacement for existing GRC, SOC, network, or procurement tooling. Outputs are designed for integration, not displacement.

Expert Network

The Qtonic Quantum expert network provides independent domain expertise across six areas critical to PQC evaluation and migration. Expert network members are independent of the scoring team and provide review, challenge, and validation services.

Lattice-Based Cryptography

Code-Based Cryptography

Hash-Based Signatures

Quantum Computing Hardware

Federal Compliance (FedRAMP, CMMC)

Critical Infrastructure Security

Adjacency Map

Qtonic Quantum operates as a cryptographic readiness control plane. It does not replace existing GRC, SOC, network, or procurement tooling. Instead, it feeds structured, scored, and signed outputs into those systems.

Feeds into

GRC Platforms

Feeds into

SOC/SIEM

Feeds into

Network Infrastructure

Feeds into

Procurement/Supply Chain

Chapter 08

Sector Playbooks

Government

Mandates + Defensible Federal Lifecycle

Federal agencies operate under the most explicit mandate framework for post-quantum migration. OMB M-23-02 requires cryptographic inventory. CNSA 2.0 sets algorithm-specific deadlines. NIST FIPS 203/204/205 define the approved replacements. The compliance path is clear; the execution challenge is scale, legacy dependency, and cross-agency coordination.

QScout provides the inventory baseline. QStrike validates the exposure claims. QSolve structures the migration program against the federal timeline. Q-Lab evaluates the PQC solutions the agency is considering for deployment.

Financial Services

Settlement, KYC, and Code Signing

Financial institutions face quantum risk across three critical surfaces: real-time settlement systems that depend on cryptographic integrity, KYC and identity verification systems that rely on digital signatures, and code-signing infrastructure that validates software supply chain integrity.

The shelf life of financial data — transaction records, customer identity, audit trails — extends well beyond any reasonable estimate of quantum computing timelines. Harvest-now-decrypt-later is not theoretical for this sector; it is the operating assumption for any well-resourced adversary.

Healthcare & Operational Technology

Patient Records, Connected Devices, SCADA, Energy

Healthcare organizations manage some of the longest-lived sensitive data in any sector. Patient records must remain confidential for decades. Connected medical devices often run cryptographic implementations that cannot be easily upgraded. Operational technology environments — SCADA systems, energy infrastructure, industrial control — face the additional challenge of air-gapped or semi-connected systems where cryptographic migration requires physical intervention.

The combination of long data shelf life, constrained upgrade paths, and safety-critical operating environments makes healthcare and OT among the highest-priority sectors for PQC migration planning.

When to Use Each Product

QScout

You need a fast, external baseline. You want to understand your publicly visible cryptographic posture before committing to a deeper engagement.

QStrike

You have identified specific cryptographic targets and need validated proof of exploitability under quantum computing conditions.

QSolve

You have validated findings and need to structure a migration program with clear ownership, dependencies, and governance.

Buyer Readiness: 10 Questions

01

Do we know which cryptographic algorithms are in use across our infrastructure?

02

Have we assessed our exposure to harvest-now-decrypt-later attacks?

03

Do we have a cryptographic bill of materials for critical systems?

04

Have we validated our vendors’ PQC migration readiness?

05

Is our key management infrastructure compatible with PQC algorithms?

06

Do we have a migration timeline aligned with CNSA 2.0 deadlines?

07

Have we tested PQC algorithm performance in our environment?

08

Do we have board-level reporting on cryptographic risk?

09

Have we assessed our compliance obligations for PQC migration?

10

Do we have a procurement framework for PQC-ready products?

30-60-90 Day Plan

30 Days

  • Request QScout assessment on primary domains
  • Review executive grade and HNDL indicator
  • Identify highest-priority systems by shelf life
  • Brief CISO on initial findings

60 Days

  • Commission QStrike validation on critical findings
  • Generate CBOM for top-10 systems
  • Begin vendor assessment with Q-Lab scores
  • Draft migration governance structure

90 Days

  • Launch QSolve migration program for Phase 1 systems
  • Plan separately scoped reassessment cadence (not a public continuous-monitoring product)
  • Board-level readiness report
  • Procurement framework for PQC-ready components
Chapter 09

Sources

  1. [1]

    National Institute of Standards and Technology (NIST). "FIPS 203: Module-Lattice-Based Key-Encapsulation Mechanism Standard." August 2024.

    https://csrc.nist.gov/pubs/fips/203/final
  2. [2]

    National Institute of Standards and Technology (NIST). "FIPS 204: Module-Lattice-Based Digital Signature Standard." August 2024.

    https://csrc.nist.gov/pubs/fips/204/final
  3. [3]

    National Institute of Standards and Technology (NIST). "FIPS 205: Stateless Hash-Based Digital Signature Standard." August 2024.

    https://csrc.nist.gov/pubs/fips/205/final
  4. [4]

    National Security Agency (NSA). "Commercial National Security Algorithm Suite 2.0." September 2022.

    https://media.defense.gov/2022/Sep/07/2003071836/-1/-1/0/CSI_CNSA_2.0_FAQ_.PDF
  5. [5]

    Office of Management and Budget (OMB). "M-23-02: Migrating to Post-Quantum Cryptography." November 2022.

    https://www.whitehouse.gov/wp-content/uploads/2022/11/M-23-02-M-Memo-on-Migrating-to-Post-Quantum-Cryptography.pdf
  6. [6]

    Mosca, Michele. "Cybersecurity in an Era with Quantum Computers: Will We Be Ready?" IEEE Security & Privacy, vol. 16, no. 5, 2018.

    https://doi.org/10.1109/MSP.2018.3761723
  7. [7]

    Chen, Lily et al. "Report on Post-Quantum Cryptography." NIST IR 8105. April 2016.

    https://csrc.nist.gov/pubs/ir/8105/final
  8. [8]

    Cybersecurity and Infrastructure Security Agency (CISA). "Post-Quantum Cryptography Initiative." 2023.

    https://www.cisa.gov/quantum
  9. [9]

    National Security Memorandum NSM-10. "Promoting United States Leadership in Quantum Computing While Mitigating Risks to Vulnerable Cryptographic Systems." May 2022.

    https://bidenwhitehouse.archives.gov/briefing-room/statements-releases/2022/05/04/national-security-memorandum-on-promoting-united-states-leadership-in-quantum-computing-while-mitigating-risks-to-vulnerable-cryptographic-systems/
  10. [10]

    European Union Agency for Cybersecurity (ENISA). "Post-Quantum Cryptography: Current State and Quantum Mitigation." May 2021.

    https://www.enisa.europa.eu/publications/post-quantum-cryptography-current-state-and-quantum-mitigation
  11. [11]

    Bernstein, Daniel J. and Tanja Lange. "Post-quantum cryptography." Nature, vol. 549, 2017.

    https://doi.org/10.1038/nature23461
  12. [12]

    Quantum Economic Development Consortium (QED-C). "A Guide to a Quantum-Safe Organization." 2023.

    https://quantumconsortium.org/
  13. [13]

    Department of Homeland Security (DHS). "Post-Quantum Cryptography: Frequently Asked Questions." 2022.

    https://www.dhs.gov/quantum
  14. [14]

    International Organization for Standardization (ISO). "ISO/IEC 18033: Encryption Algorithms." Ongoing revision for PQC inclusion.

    https://www.iso.org/standard/54531.html
Chapter 10

Appendices

Appendix A: Claims Register

ClaimStatusEvidence
QScout public intake requires no credentials or agent installationVerifiedArchitecture documentation + independent test
QStrike public evidence uses provider-calibrated modeled runtime profilesVerifiedPublic integrity documentation; no live quantum hardware contact in the browser demonstration
Q-Lab scores 200+ implementationsVerifiedPublished floor; live registry ≥ 200, see /lab
Q-Lab has no paid inclusion or vendor influenceVerifiedPublished methodology + challenge review process
QStrike proof artifacts are cryptographically signed (ECDSA-P256-SHA256 today; ML-DSA-65 migration in flight)VerifiedSignature verification path documented
$2M challenge diligence applies only to qualifying QStrike engagementsVerifiedPublished challenge terms and engagement qualification language
CNSA 2.0 Phase 1 deadline is January 2027VerifiedNSA CNSA 2.0 FAQ, September 2022
FIPS 203, 204, 205 published August 2024VerifiedNIST publications archive

Appendix B: Sample Proof Artifact

{
  "version": "1.0",
  "type": "qstrike-proof",
  "id": "QS-2026-0142",
  "timestamp": "2026-04-15T14:32:00Z",
  "target": {
    "domain": "example.com",
    "protocol": "TLS 1.2",
    "key_exchange": "ECDHE-RSA-AES256-GCM-SHA384",
    "key_size": 2048
  },
  "finding": {
    "severity": "HIGH",
    "confidence": 0.94,
    "category": "Key Exchange Vulnerability",
    "description": "RSA-2048 key exchange vulnerable to quantum factoring under projected hardware capabilities within 10-year shelf life.",
    "cvss_quantum": 8.1
  },
  "validation": {
    "provider_profile": "IBM Quantum Eagle (127-qubit)",
    "harness_id": "HRN-RSA-2048-FACTOR-v3",
    "red_team_result": "EXPLOITABLE",
    "blue_team_result": "NO_MITIGATION",
    "arbiter_decision": "CONFIRMED"
  },
  "signature": {
    "algorithm": "ECDSA-P256-SHA256",
    "signer": "Qtonic Quantum Proof Authority",
    "signature": "base64:...[truncated]..."
  }
}

Appendix C: Approved Public Check Families

F01

TLS Version

Protocol version negotiation and minimum version enforcement.

F02

Certificate Chain

Chain completeness, validity, and trust anchor verification.

F03

Key Exchange

Key exchange algorithm strength and PQC readiness.

F04

Cipher Suite

Symmetric cipher selection, mode of operation, and key length.

F05

Signature Algorithm

Certificate and handshake signature algorithm strength.

F06

HSTS Configuration

HTTP Strict Transport Security header presence and configuration.

F07

Certificate Transparency

CT log inclusion and SCT presence verification.

F08

OCSP Stapling

Online Certificate Status Protocol stapling support.

F09

Protocol Extensions

TLS extension support and configuration analysis.

F10

Session Configuration

Session ticket, resumption, and 0-RTT configuration.

F11

HNDL Exposure

Harvest-now-decrypt-later risk based on key exchange and data classification.

F12

Algorithm Deprecation

Use of deprecated or soon-to-be-deprecated cryptographic algorithms.

F13

Key Length

Asymmetric and symmetric key length adequacy against quantum threat models.

F14

PQC Readiness

Support for or compatibility with NIST PQC standard algorithms.

F15

Configuration Hygiene

Overall TLS configuration best-practice adherence.

Appendix D: Procurement Readiness Grid

Compliance

  • NIST FIPS 203/204/205 alignment
  • CNSA 2.0 compliance statement
  • Not FedRAMP Authorized or FedRAMP Ready; FedRAMP-scoped assessment support available
  • Inherited cloud-provider SOC 2 Type II reports (procurement review, on request)

Government Registration

  • SAM.gov registration (where applicable, on request)
  • CAGE code (where applicable, on request)
  • NAICS code coverage for cybersecurity services

Data Handling

  • Data residency documentation
  • Encryption-at-rest and in-transit specifications
  • Data retention and deletion policies

Key Custody

  • HSM specifications and FIPS 140-3 level
  • Key generation and rotation procedures
  • Customer-managed key support

Contracts

  • Standard terms and conditions
  • Government contract vehicle eligibility
  • SLA specifications and uptime commitments

Vulnerability Disclosure

  • Published vulnerability disclosure policy
  • Bug bounty program availability
  • Incident response SLA

Get the next Field Book revision

Quarterly updates as standards, deadlines, and sector playbooks evolve. No spam.

We use your address to send the requested information. No third-party sharing.

Find exposure. Prove materiality. Fix migration sequence. Validate.

Qtonic Quantum · Miami, Florida