tech · quantum risk
Is PQC questionnaire Quantum Proof? Cyber Program & PQC
Verdict
A PQC questionnaire is an evidence request, not a certificate of quantum safety. Score answers by specificity: algorithms, RFCs, versions, and pilot customers beat adjectives.
Overview
Sample question themes: TLS hybrid support, certificate algorithms, token signing, code signing, firmware update crypto, client compatibility, and deprecation of classical-only modes.
Use with procurement and security architecture—not only GRC checkbox tools.
Program inventory focus: Unverified answers create false assurance. Typical classical surfaces: Requested: algorithms, hybrid modes, cert profiles, HSM support. Cross-read /security/program and /assessment. Educational only—not compliance advice.
Cryptographic profile
- Signatures: Requested: algorithms, hybrid modes, cert profiles, HSM support
- Hash: Response evidence links
- Public-key exposure: Unverified answers create false assurance.
What breaks
- Yes/no only forms
- Accepting “AES-256” as full answer for handshakes
Mitigations
- Require algorithm names and versions
- Ask for negative space: what is not PQ yet
- Retest annually
FAQ
Share questionnaire publicly?
Your org’s version may be internal; this page is educational framing.
Key concepts (technical dictionary)
Terms used on this page — open a definition: