Methodology
AI-powered assessments, e-Learning paths, ecosystem collaboration, and quiz campaigns. See our Post-Quantum Maturity Model, why post-quantum matters now and post-quantum resources.
AI-powered assessments, e-Learning paths, ecosystem collaboration, and quiz campaigns. See our Post-Quantum Maturity Model, why post-quantum matters now and post-quantum resources.
AI-powered assessments, e-Learning paths, ecosystem collaboration, and quiz campaigns. See our Post-Quantum Maturity Model, why post-quantum matters now and post-quantum resources.
A simple, stable, citable framework for measuring post-quantum readiness. The model maps your organization's posture across 5 levels—from Unaware to Proactive. (Qubixor Post-Quantum Maturity Model — QPQMM)
Normative reference for "quantum-ready"
This defines how we use the term in our assessments and reports.
We align with NIST Post-Quantum Cryptography standards (FIPS 203 ML-KEM, FIPS 204 ML-DSA, FIPS 205 SLH-DSA) as the technical reference for quantum-resistant cryptography. Being quantum-ready means adopting or planning adoption of these primitives.
NIST PQC ↗More than 8 post-quantum maturity models exist today—QRAMM, Singapore QRI, DigiCert, Encryption Consulting, PKI Consortium PQCMM, PQCC, TNO, and others. Each brings value, but they are fragmented: different dimensions, vendor-specific focus, or regional scope. No single framework unified the best practices for organizations worldwide.
We built the Qubixor Post-Quantum Maturity Model to consolidate the best of these models into one framework. We benchmarked against all of them, organized findings into 5 axes that cover governance, cryptography, infrastructure, transition, and awareness—without breaking existing reports or deliverables. It is the most comprehensive organizational post-quantum maturity model, aligned with NIST, ANSSI, ENISA, NIS2, and DORA.
Models we benchmarked against:
QRAMM (CSNP) • Singapore Quantum Readiness Index • DigiCert PQC • Encryption Consulting • PKI Consortium PQCMM • PQCC Migration Roadmap • TNO PQC Handbook • Academic frameworks (Preprints QRMM)
How our model compares:
For each model: how Qubixor's framework covers its dimensions.
Regulatory standards we align with
Our 5 axes and 33 essential controls address themes these standards emphasize. These frameworks are rich; we support preparation, not a 1:1 mapping. Click each link to verify against official sources.
| Standard | Overlapping themes (our axes) | Source |
|---|---|---|
| NIST (FIPS 203/204/205, IR 8545/8547) | Cryptography (inventory C01–C02, TLS/KEM C03–C05, pilots C19, KMS C08), Infrastructure (cloud KMS/HSM I07, certs I06, I18), Transition (roadmap T01–T04, T17) | NIST CSRC ↗ |
| ANSSI | Governance (policy G01, risk G02–G17, regulatory watch G18, RACI G03), Cryptography (inventory C01–C02, KEM C05), Transition (roadmap T01, hybrid T04–T17) | cyber.gouv.fr ↗ |
| ENISA | Cryptography (hybrid, inventory, KEM), Infrastructure (TLS, cipher management), Transition (phased hybrid T04–T17), Awareness (A01–A02, A13) | ENISA ↗ |
| NIS2 | Governance (risk management G02, G17, policy G01, sectoral mapping G18), Cryptography (inventory C01–C02, KEM C05), Transition (roadmap T01) | EUR-Lex ↗ |
| DORA | Governance (ICT risk G02, G17, sectoral G18), Cryptography (inventory, KEM C05), Infrastructure (cloud KMS I07, TLS I01–I02) | EUR-Lex ↗ |
| eIDAS (Reg. 910/2014) & ETSI EN 319 series (2024-2025) | Infrastructure (certs I06, PKI), Cryptography (key protection, cert lifecycle), Governance (CPS, policy G01). EU trust services: qualified certs, timestamps, preservation (319 411, 421, 422, 521/531). Note: ETSI EN 319 standards (2024-2025) implement eIDAS regulation (2014). | EUR-Lex ↗ ETSI ↗ |
Our assessment helps prepare for compliance; it does not constitute certification. We also draw from NIST PQC migration guidance (risk framework mappings), Singapore CSA (Quantum Readiness Index, Quantum-Safe Handbook), BSI PQC migration guide, IBM Quantum Readiness, GSMA telecom PQC guidelines, IETF PQUIP, and other authoritative sources.
5 axes, 33 essential controls — Governance, Cryptography, Infrastructure, Transition, Awareness
Unified framework (Standard + Complete)
4 dims: Crypto inv., Governance, Data protection, Tech readiness
Qubixor covers all 4 via Cryptography, Governance, Infrastructure; we add explicit Transition & Awareness axes
5: Governance, Risk, Training, External engagement, Technology
All 5 domains covered via our axes. A13 (external engagement) and G18 (sectoral) address gaps we identified
Knowledge + Preparation
Covered via Cryptography, Governance, Awareness axes
5 levels: Beginner → Resilient
Levels map to our 5-maturity scale; controls overlap in crypto & infrastructure
Crypto infra, Governance, Sectoral, Interop, Strategic
Sectoral via G18; interop via Transition; strategic via Governance axes
4 stages: Prep → Assessment → Migration → Monitoring
Covered via Transition, Governance, Cryptography axes
Diagnosis, Planning, Execution
Diagnosis in Cryptography; planning in Governance/Transition; execution in Infrastructure
Product maturity (CBOM, Zero-Legacy)
Different scope: they assess vendors/products; we assess organizations. I07 (KMS/HSM vendor roadmap) covers vendor evaluation in Standard
QRI score maps directly to maturity level
“Most organizations today are between Level 0 and Level 1 in post-quantum maturity.”
| Level | Name | Characteristics | QRI Range |
|---|---|---|---|
| 0 | Unaware | No inventory, no PQ awareness at leadership level, no timeline consideration | 0–20 |
| 1 | Aware | General awareness of PQ risk, monitoring NIST / ecosystem, no structured assessment | 20–40 |
| 2 | Assessed | Crypto inventory (CBOM) initiated, risk mapping performed, executive visibility | 40–60 |
| 3 | Structured | Migration strategy drafted, governance defined, crypto-agility in place (ability to change primitives quickly) | 60–80 |
| 4 | Proactive | Roadmap aligned with NIST timelines, crypto-agile architecture, vendor ecosystem reviewed, capabilities developed | 80–100 |
Core concepts recognized by NIST, QRAMM, and industry frameworks
Inventory of all cryptographic assets (certificates, keys, libraries, protocols) that may be affected by the quantum transition. CBOM is the "step 0"—you cannot migrate what you have not discovered. Our Cryptography and Infrastructure axes assess this.
The ability to quickly swap cryptographic primitives without redesigning systems. Essential for a smooth PQC transition as standards evolve. Our model evaluates this from Level 3 onward and integrates it into the Cryptography axis.
The Quantum Readiness Index (QRI) is the numerical representation of the maturity model. Your QRI score (0–100) maps directly to a maturity level.
Get your QRI score and maturity level with our free assessment. No system access required.
Measure maturityMeasure your post-quantum maturity