What the rating measures
The rating measures how far an organization has gone toward protecting its systems against a cryptographically relevant quantum computer. That is a machine able to run Shor's algorithm against RSA and elliptic-curve cryptography. The rating covers the systems in an agreed scope, usually the products and services a vendor sells to its customers.
It is not a general security certification, a FIPS 140-3 validation, or a guarantee against breach. It says how ready the in-scope systems are for post-quantum cryptography, and it rests on evidence we have checked.
The five levels
Each level includes everything in the levels below it.
- A cryptographic bill of materials (CBOM) in CycloneDX 1.6 format, covering in-scope applications, services, certificates, keys, libraries and hardware security modules
- Each entry lists the algorithm, key size, owner and the systems that depend on it
- Automated discovery refreshed within the last 90 days
- Risk ranking of every quantum-vulnerable asset, using data shelf life and migration time (Mosca's inequality)
- A migration roadmap with owners and target dates for every high-risk asset
- A readiness status on file for each critical third-party dependency
- A named executive owner for the migration
- All external TLS endpoints in scope negotiate a hybrid post-quantum key exchange, such as X25519MLKEM768, verified by our scan
- VPN and partner connections carrying sensitive data use ML-KEM or a hybrid equivalent
- Long-lived sensitive data is protected against harvest-now-decrypt-later collection
- Code signing, firmware signing and issuing certificate authorities use ML-DSA or SLH-DSA, or dual-sign during transition
- No in-scope RSA or elliptic-curve use remains, except documented exceptions with an end date
- Critical vendors have verified post-quantum support
How a rating is measured
- Public scan: we scan in-scope public endpoints for protocol versions, key exchange groups and certificate algorithms. This alone can show Q0 or support Q3.
- Uploaded evidence: the organization uploads its CBOM, roadmap and configuration exports. We check each file against the requirements above and report which ones are met. We never log in to its systems.
- Reporting only: a rating states what the evidence shows. Shorward does not advise on, recommend or carry out changes.
- Validity: a rating is valid for 90 days from verification. After that it lapses to Q0 unless it is re-scanned.
- Disclosure: the organization chooses whether to publish its rating. When it does, buyers can see the level, the scope, the verification date and a short evidence summary.
How the levels map to public guidance
| Level | Aligns with |
|---|---|
| Q1 | CISA, NSA and NIST quantum-readiness guidance (cryptographic inventory); UK NCSC discovery phase; US EO 14412 inventory requirement |
| Q2 | NIST IR 8547 transition timelines; EU coordinated PQC roadmap; ASD "questions to ask your vendors" |
| Q3 | FIPS 203 (ML-KEM); hybrid key exchange deployed by major browsers and cloud providers |
| Q4 | FIPS 204 (ML-DSA) and FIPS 205 (SLH-DSA); NSA CNSA 2.0 signing requirements |
Changes and disputes
This is a draft. We will publish every revision with a version number and date, and give rated organizations 90 days' notice before a stricter requirement applies to them. If an organization disagrees with its level, it can upload further evidence and the rating is measured again.