Post-Quantum Ready. Field Book.
Executive Field Book / 2026 Edition
From Mandate to Operating Control
From theory to measurable control.
Post-quantum cryptography is no longer a research question. Federal mandates, standards bodies, and procurement frameworks have converged on a single conclusion: organizations that depend on public-key cryptography must begin migration now, or accept unquantified risk to every system that stores, transmits, or signs sensitive data.
The path from mandate to operating control follows three steps: Inventory every cryptographic dependency across the enterprise, Validate each dependency against current and emerging threat models, and Migrate to quantum-resistant alternatives on a risk-prioritized schedule.
This is a continuous control loop, not a one-time project. Cryptographic posture must be measured, reported, and improved continuously as algorithms are deprecated, new threat intelligence emerges, and compliance frameworks tighten.
Federal Timeline
Risk Quadrant: Exposure x Shelf Life
The quantum risk to any given system is a function of two variables: how exposed its cryptographic surface is today, and how long the data it protects must remain confidential. Systems with high exposure and long shelf life — classified records, financial instruments, healthcare data — face the most urgent migration pressure.
Low Exposure
Short Shelf Life
Monitor
High Exposure
Short Shelf Life
Plan
Low Exposure
Long Shelf Life
Prioritize
High Exposure
Long Shelf Life
Migrate Now
Mosca's Theorem: X + Y > Z
Michele Mosca's inequality frames the urgency precisely. If X (the time a secret must remain secure) plus Y (the time required to migrate the system) exceeds Z (the time until a cryptanalytically relevant quantum computer exists), then the data is already at risk. Harvest-now-decrypt-later attacks make this inequality actionable today, not at some future date when quantum hardware matures.
The Qtonic Quantum Suite
Find exposure. Prove materiality. Fix migration sequence.
The Qtonic Quantum Suite is a four-stage operating model for post-quantum readiness. Each product addresses a distinct phase of the migration lifecycle, from initial discovery through independent validation. The suite is designed to work together or independently, integrating with existing GRC, SOC, and procurement workflows.
QScout
Find
External quantum risk snapshot. Public-domain scan delivers a buyer-readable executive snapshot with severity profile, HNDL indicator, and methodology-backed evidence.
QStrike
Prove
Controlled quantum validation engine. Multi-provider exploit harnesses, red/blue/arbiter scoring, and a signed proof artifact with $2M challenge diligence.
QSolve
Fix
Migration governance engine. Five workstreams, trigger-based escalation, and a governance board that tracks every dependency from measured exposure to validated migration.
QLab
Prove
Independent PQC solution evaluation. 200+ implementations scored across 10 dimensions with provenance tags, continuous testing, and no paid inclusion.
QScout
QScout turns a public domain into an executive snapshot.
Request a QScout assessment with your work email and proposed scope. An analyst reviews the request, confirms approved scope, and agrees the assessment outputs and delivery timing. Submitting the form does not start a scan or guarantee a report.
After scope is confirmed, a QScout assessment can review approved cryptographic surfaces such as TLS configuration, certificate chains, key exchange parameters and cipher suite negotiation. Assessment depth and evidence delivery depend on the agreed engagement.
Delivery Lanes
QScout public intake
Assessment request reviewed by an analyst before scope, outputs and timing are agreed.
public/credentialed/privileged scope
Governed follow-on paths with approved scope, credentials, privileged access, CBOM, and evidence depth as authorized.
Pulse (report family)
The QScout report family across Surface, Silver, and Gold. Reassessment or continuity work is separately scoped; the fourth QScout offering and not a public continuous-monitoring product.
QScout Public Intake Authorization Model
Request a QScout assessment with your work email and proposed scope. An analyst reviews the request, confirms approved scope, and agrees the assessment outputs and delivery timing. Submitting the form does not start a scan or guarantee a report. Assessment work follows requester verification and approval of the target scope. Approved public-surface assessments do not require internal credentials. Credentialed or privileged assessment depth requires separately approved access.
Six QScout Outputs
Executive Grade
A single letter grade (A through F) summarizing externally visible cryptographic posture.
HNDL Indicator
Harvest-now-decrypt-later exposure indicator based on observed key exchange and cipher suite configuration.
Severity Profile
Distribution of findings across Critical, High, Medium, Low, and Informational severity bands.
Methodology Notes
Per-finding methodology citations linking each observation to its scoring rationale and check family.
CBOM Handoff
Cryptographic Bill of Materials structured for downstream QStrike validation or third-party integration.
Decision Snapshot
Clear recommendation on whether deeper investigation is warranted, with supporting evidence summary.
Visual Model: Public Snapshot to CBOM Handoff
Public Snapshot
TLS configuration, certificate chain, key exchange, and cipher suite analysis from public-facing endpoints.
Protocol Analysis
Deep inspection of negotiated protocol parameters, extension support, and session configuration.
Cryptographic Mapping
Algorithm inventory mapped to NIST PQC standards with gap analysis and migration priority.
CBOM Handoff
Structured output artifact for governance review, QStrike validation, or third-party tooling integration.
Artifacts That Survive Handoff
Every QScout output is designed to survive handoff to downstream systems and stakeholders. The executive grade and severity profile are formatted for board-level reporting. The CBOM is structured for ingestion by QStrike, GRC platforms, and third-party vulnerability management tools. Methodology notes provide the audit trail required for compliance documentation. The decision snapshot gives the CISO a defensible recommendation, not a data dump.
Open remaining field book chapters
QStrike
QStrike validates the path, not just the weakness.
QStrike is a controlled forward-threat validation engine. It applies real commercial quantum-cloud lattice reduction to a Hidden Number Problem constructed from a real ephemeral side-channel leak. QQ26 presents the perspective of a 2030/2031 quantum-capable adversary today; it does not directly break encryption or predict when encryption will break. QStrike produces evidence packages that document the method, controls, and proof limits.
Validation Pipeline
Provider Profiles
real commercial quantum-cloud services across four modalities.
Exploit Harnesses
Target-specific exploit constructions mapped to the cryptographic surface identified by QScout.
Red/Blue Team
Adversarial red team attempts exploitation. Blue team validates defensive posture. A separate governed reviewer scores.
Arbiter Scoring
Confidence-weighted severity scoring with full evidence chain and reproducibility documentation.
6 Platform Profiles Across 4 Quantum Modalities
IBM Quantum
Superconducting
IonQ
Trapped Ion
Quantinuum
Trapped Ion
Rigetti
Superconducting
D-Wave
Quantum Annealing
QuEra
Neutral Atom
Proof Model
Evidence
Raw observations from exploit-harness execution against commercial quantum-cloud execution or governed engagement-specific validation lanes.
Controlled Validation
Reproducible test execution with documented parameters, environmental conditions, and control baselines.
Signed Proof
Cryptographically signed artifact (ECDSA-P256-SHA256 today; ML-DSA-65 migration in flight) documenting the complete evidence chain and scoring rationale.
Customer Verification
Independent verification path allowing the customer to validate proof integrity without trusting the issuer.
Challenge and Review
QStrike operates a three-role adversarial review: Red Team constructs and executes exploit harnesses. Blue Team validates defensive controls and identifies false positives. A governed reviewer scores each finding with confidence-weighted severity and resolves disagreements between red and blue.
Every QStrike finding carries a confidence-weighted severity score. The confidence weight reflects the reproducibility of the exploit, the quality of the bounded commercial quantum-cloud evidence, and the documented reviewer rationale.
Challenge Diligence
Challenge terms apply only to qualifying QStrike engagements and remain in controlled procurement. If a governed later review proves that an in-scope High or Critical finding was missed, the contract controls the remedy. QScout is not covered by those terms.
QSolve
QSolve turns measured exposure into migration discipline.
QSolve is the migration governance engine of the Qtonic Quantum Suite. It takes the measured exposure from QScout and the validated findings from QStrike and translates them into a structured migration program with clear ownership, dependencies, decision gates, and status tracking.
The governance board tracks every migration action across five dimensions: Owner (who is accountable), Risk (what is the exposure if migration is delayed), Dependency (what must happen first), Decision (what approval is required), and Status (current state of the migration action).
Governance Board
| Owner | Risk | Dependency | Decision | Status |
|---|---|---|---|---|
| CISO | Critical | HSM upgrade | Board approval | In Progress |
| VP Engineering | High | Library update | Tech lead sign-off | Planned |
| Compliance Lead | Medium | Audit completion | GRC review | Queued |
Five Migration Triggers
Critical Finding
QStrike validates a critical-severity quantum vulnerability with high confidence.
Compliance Deadline
A regulatory or mandate deadline requires migration action within a defined window.
Vendor Deprecation
A key vendor announces deprecation of a cryptographic primitive in active use.
Board Directive
The governance board or CISO issues a directive to begin migration for a specific system.
Drift Detection
Approved reassessment scope detects regression in cryptographic posture; not a public continuous-monitoring product promise.
Five Migration Workstreams
Security
Vulnerability remediation, cryptographic library upgrades, and key rotation across affected systems.
Infrastructure
Network configuration, certificate management, and HSM migration for quantum-resistant key material.
Engineering
Application-layer changes, protocol upgrades, and integration testing for PQC algorithm support.
Compliance
Documentation, audit trail generation, and regulatory reporting for NIST, CNSA 2.0, and sector-specific frameworks.
Procurement
Vendor assessment, contract review, and supply-chain validation for PQC-ready components and services.
Qtonic Quantum Lab
A scoring rubric built for the buyer's question.
Qtonic Quantum Lab is an independent PQC solution evaluation platform. It scores post-quantum cryptography implementations across a published 10-dimension rubric with no paid inclusion, no vendor influence on rankings, and continuous re-testing against evolving threat models and standards.
200+
Implementations Scored
12
Categories
10
Scoring Dimensions
24/7
Continuous Testing
10 Scoring Dimensions
Algorithm Strength
Implementation Maturity
Performance Profile
Standards Compliance
Interoperability
Side-Channel Resistance
Key Management
Migration Readiness
Vendor Stability
Documentation Quality
Provenance Tags
Verified
Score derived from direct testing against vendor-supplied implementation with documented methodology.
Contested
Score challenged by vendor or third party. Under review with documented dispute timeline.
Inferred
Score derived from public documentation, published benchmarks, or third-party analysis. Not directly tested.
Degraded
Previously verified score degraded due to new vulnerability disclosure, vendor instability, or failed re-test.
Illustrative Scorecard
PQC-KEM-073
Illustrative ML-KEM implementation scorecard
Team and Trust Model
Mission-tested leadership. Evidence-linked scoring.
Mission Pedigree
Leadership team drawn from defense, intelligence, and critical infrastructure backgrounds with direct experience in cryptographic operations, threat analysis, and secure system design.
Scoring Independence
Qtonic Quantum Lab scoring methodology is published, vendor-independent, and subject to challenge review. No paid inclusion. No vendor influence on rankings. Expert network provides independent validation.
Adjacency
Qtonic Quantum operates as a cryptographic readiness control plane — not a replacement for existing GRC, SOC, network, or procurement tooling. Outputs are designed for integration, not displacement.
Expert Network
The Qtonic Quantum expert network provides independent domain expertise across six areas critical to PQC evaluation and migration. Expert network members are independent of the scoring team and provide review, challenge, and validation services.
Lattice-Based Cryptography
Code-Based Cryptography
Hash-Based Signatures
Quantum Computing Hardware
Federal Compliance (FedRAMP, CMMC)
Critical Infrastructure Security
Adjacency Map
Qtonic Quantum operates as a cryptographic readiness control plane. It does not replace existing GRC, SOC, network, or procurement tooling. Instead, it feeds structured, scored, and signed outputs into those systems.
Feeds into
GRC Platforms
Feeds into
SOC/SIEM
Feeds into
Network Infrastructure
Feeds into
Procurement/Supply Chain
Sector Playbooks
Government
Mandates + Defensible Federal Lifecycle
Federal agencies operate under the most explicit mandate framework for post-quantum migration. OMB M-23-02 requires cryptographic inventory. CNSA 2.0 sets algorithm-specific deadlines. NIST FIPS 203/204/205 define the approved replacements. The compliance path is clear; the execution challenge is scale, legacy dependency, and cross-agency coordination.
QScout provides the inventory baseline. QStrike validates the exposure claims. QSolve structures the migration program against the federal timeline. Qtonic Quantum Lab evaluates the PQC solutions the agency is considering for deployment.
Financial Services
Settlement, KYC, and Code Signing
Financial institutions face quantum risk across three critical surfaces: real-time settlement systems that depend on cryptographic integrity, KYC and identity verification systems that rely on digital signatures, and code-signing infrastructure that validates software supply chain integrity.
The shelf life of financial data — transaction records, customer identity, audit trails — extends well beyond any reasonable estimate of quantum computing timelines. Harvest-now-decrypt-later is not theoretical for this sector; it is the operating assumption for any well-resourced adversary.
Healthcare & Operational Technology
Patient Records, Connected Devices, SCADA, Energy
Healthcare organizations manage some of the longest-lived sensitive data in any sector. Patient records must remain confidential for decades. Connected medical devices often run cryptographic implementations that cannot be easily upgraded. Operational technology environments — SCADA systems, energy infrastructure, industrial control — face the additional challenge of air-gapped or semi-connected systems where cryptographic migration requires physical intervention.
The combination of long data shelf life, constrained upgrade paths, and safety-critical operating environments makes healthcare and OT among the highest-priority sectors for PQC migration planning.
When to Use Each Product
You need a fast, external baseline. You want to understand your publicly visible cryptographic posture before committing to a deeper engagement.
You have identified specific cryptographic targets and need validated proof of exploitability under quantum computing conditions.
You have validated findings and need to structure a migration program with clear ownership, dependencies, and governance.
Buyer Readiness: 10 Questions
Do we know which cryptographic algorithms are in use across our infrastructure?
Have we assessed our exposure to harvest-now-decrypt-later attacks?
Do we have a cryptographic bill of materials for critical systems?
Have we validated our vendors’ PQC migration readiness?
Is our key management infrastructure compatible with PQC algorithms?
Do we have a migration timeline aligned with CNSA 2.0 deadlines?
Have we tested PQC algorithm performance in our environment?
Do we have board-level reporting on cryptographic risk?
Have we assessed our compliance obligations for PQC migration?
Do we have a procurement framework for PQC-ready products?
30-60-90 Day Plan
30 Days
- Request QScout assessment on primary domains
- Review executive grade and HNDL indicator
- Identify highest-priority systems by shelf life
- Brief CISO on initial findings
60 Days
- Commission QStrike validation on critical findings
- Generate CBOM for top-10 systems
- Begin vendor assessment with Qtonic Quantum Lab scores
- Draft migration governance structure
90 Days
- Launch QSolve migration program for Phase 1 systems
- Plan separately scoped reassessment cadence (not a public continuous-monitoring product)
- Board-level readiness report
- Procurement framework for PQC-ready components
Sources
- [1]
National Institute of Standards and Technology (NIST). "FIPS 203: Module-Lattice-Based Key-Encapsulation Mechanism Standard." August 2024.
https://csrc.nist.gov/pubs/fips/203/final - [2]
National Institute of Standards and Technology (NIST). "FIPS 204: Module-Lattice-Based Digital Signature Standard." August 2024.
https://csrc.nist.gov/pubs/fips/204/final - [3]
National Institute of Standards and Technology (NIST). "FIPS 205: Stateless Hash-Based Digital Signature Standard." August 2024.
https://csrc.nist.gov/pubs/fips/205/final - [4]
National Security Agency (NSA). "Commercial National Security Algorithm Suite 2.0." September 2022.
https://media.defense.gov/2022/Sep/07/2003071836/-1/-1/0/CSI_CNSA_2.0_FAQ_.PDF - [5]
Office of Management and Budget (OMB). "M-23-02: Migrating to Post-Quantum Cryptography." November 2022.
https://www.whitehouse.gov/wp-content/uploads/2022/11/M-23-02-M-Memo-on-Migrating-to-Post-Quantum-Cryptography.pdf - [6]
Mosca, Michele. "Cybersecurity in an Era with Quantum Computers: Will We Be Ready?" IEEE Security & Privacy, vol. 16, no. 5, 2018.
https://doi.org/10.1109/MSP.2018.3761723 - [7]
Chen, Lily et al. "Report on Post-Quantum Cryptography." NIST IR 8105. April 2016.
https://csrc.nist.gov/pubs/ir/8105/final - [8]
Cybersecurity and Infrastructure Security Agency (CISA). "Post-Quantum Cryptography Initiative." 2023.
https://www.cisa.gov/quantum - [9]
National Security Memorandum NSM-10. "Promoting United States Leadership in Quantum Computing While Mitigating Risks to Vulnerable Cryptographic Systems." May 2022.
https://bidenwhitehouse.archives.gov/briefing-room/statements-releases/2022/05/04/national-security-memorandum-on-promoting-united-states-leadership-in-quantum-computing-while-mitigating-risks-to-vulnerable-cryptographic-systems/ - [10]
European Union Agency for Cybersecurity (ENISA). "Post-Quantum Cryptography: Current State and Quantum Mitigation." May 2021.
https://www.enisa.europa.eu/publications/post-quantum-cryptography-current-state-and-quantum-mitigation - [11]
Bernstein, Daniel J. and Tanja Lange. "Post-quantum cryptography." Nature, vol. 549, 2017.
https://doi.org/10.1038/nature23461 - [12]
Quantum Economic Development Consortium (QED-C). "A Guide to a Quantum-Safe Organization." 2023.
https://quantumconsortium.org/ - [13]
Department of Homeland Security (DHS). "Post-Quantum Cryptography: Frequently Asked Questions." 2022.
https://www.dhs.gov/quantum - [14]
International Organization for Standardization (ISO). "ISO/IEC 18033: Encryption Algorithms." Ongoing revision for PQC inclusion.
https://www.iso.org/standard/54531.html
Appendices
Appendix A: Claims Register
| Claim | Status | Evidence |
|---|---|---|
| QScout public intake requires no credentials or agent installation | Verified | Architecture documentation + independent test |
| QStrike public evidence uses governed real commercial quantum-cloud services | Verified | Public integrity documentation; no customer execution or provider endorsement is implied by the browser demonstration |
| Qtonic Quantum Lab scores 200+ implementations | Verified | Published floor; live registry ≥ 200, see /lab |
| Qtonic Quantum Lab has no paid inclusion or vendor influence | Verified | Published methodology + challenge review process |
| QStrike proof artifacts are cryptographically signed (ECDSA-P256-SHA256 today; ML-DSA-65 migration in flight) | Verified | Signature verification path documented |
| $2M challenge diligence applies only to qualifying QStrike engagements | Verified | Published challenge terms and engagement qualification language |
| CNSA 2.0 Phase 1 deadline is January 2027 | Verified | NSA CNSA 2.0 FAQ, September 2022 |
| FIPS 203, 204, 205 published August 2024 | Verified | NIST publications archive |
Appendix B: Sample Proof Artifact
{
"version": "1.0",
"type": "qstrike-proof",
"id": "QS-2026-0142",
"timestamp": "2026-04-15T14:32:00Z",
"target": {
"domain": "example.com",
"protocol": "TLS 1.2",
"key_exchange": "ECDHE-RSA-AES256-GCM-SHA384",
"key_size": 2048
},
"finding": {
"severity": "HIGH",
"confidence": 0.94,
"category": "Key Exchange Vulnerability",
"description": "RSA-2048 key exchange vulnerable to quantum factoring under projected hardware capabilities within 10-year shelf life.",
"cvss_quantum": 8.1
},
"validation": {
"provider_profile": "IBM Quantum Eagle (127-qubit)",
"harness_id": "HRN-RSA-2048-FACTOR-v3",
"red_team_result": "EXPLOITABLE",
"blue_team_result": "NO_MITIGATION",
"arbiter_decision": "CONFIRMED"
},
"signature": {
"algorithm": "ECDSA-P256-SHA256",
"signer": "Qtonic Quantum Proof Authority",
"signature": "base64:...[truncated]..."
}
}Appendix C: Approved Public Check Families
TLS Version
Protocol version negotiation and minimum version enforcement.
Certificate Chain
Chain completeness, validity, and trust anchor verification.
Key Exchange
Key exchange algorithm strength and PQC readiness.
Cipher Suite
Symmetric cipher selection, mode of operation, and key length.
Signature Algorithm
Certificate and handshake signature algorithm strength.
HSTS Configuration
HTTP Strict Transport Security header presence and configuration.
Certificate Transparency
CT log inclusion and SCT presence verification.
OCSP Stapling
Online Certificate Status Protocol stapling support.
Protocol Extensions
TLS extension support and configuration analysis.
Session Configuration
Session ticket, resumption, and 0-RTT configuration.
HNDL Exposure
Harvest-now-decrypt-later risk based on key exchange and data classification.
Algorithm Deprecation
Use of deprecated or soon-to-be-deprecated cryptographic algorithms.
Key Length
Asymmetric and symmetric key length adequacy against quantum threat models.
PQC Readiness
Support for or compatibility with NIST PQC standard algorithms.
Configuration Hygiene
Overall TLS configuration best-practice adherence.
Appendix D: Procurement Readiness Grid
Compliance
- NIST FIPS 203/204/205 alignment
- CNSA 2.0 compliance statement
- Not FedRAMP Authorized or FedRAMP Ready; FedRAMP-scoped assessment support available
- Inherited cloud-provider SOC 2 Type II reports (procurement review, on request)
Government Registration
- SAM.gov registration (where applicable, on request)
- CAGE code (where applicable, on request)
- NAICS code coverage for cybersecurity services
Data Handling
- Data residency documentation
- Encryption-at-rest and in-transit specifications
- Data retention and deletion policies
Key Custody
- HSM specifications and FIPS 140-3 level
- Key generation and rotation procedures
- Customer-managed key support
Contracts
- Standard terms and conditions
- Government contract vehicle eligibility
- SLA specifications and uptime commitments
Vulnerability Disclosure
- Published vulnerability disclosure policy
- Bug bounty program availability
- Incident response SLA
Find exposure. Prove materiality. Fix migration sequence. Validate.
Qtonic Quantum · Miami, Florida