isquantumproof.com Technical dictionary

industry · quantum risk

Is Vendor risk PQC Quantum Proof? Cyber Program & PQC

Risk: high · Confidence: high · Reviewed: 2026-07-19

Verdict

Vendor risk programs must add PQC and hybrid questions with evidence standards. Marketing “quantum-safe” claims without algorithms, versions, and timelines are incomplete.

Overview

Most enterprises inherit cryptography from vendors. Questionnaires, RFPs, and SOC reports need crypto-specific depth.

Ties to Wave 5 claims methodology on this site for evaluating public claims.

Program inventory focus: SaaS and appliances hide classical crypto behind roadmaps and NDAs. Typical classical surfaces: Vendor TLS and product crypto; Subprocessor chains. Cross-read /security/program and /assessment. Educational only—not compliance advice.

Cryptographic profile

What breaks

  • Checkbox “encryption in transit” only
  • No residual risk for classical-only critical SaaS

Mitigations

  • Standard PQC questionnaire
  • Tier vendors by data shelf life and exposure
  • Contractual roadmap and notification clauses

FAQ

Reject vendors without PQC today?

Risk-based: require roadmaps and compensating controls; prioritize critical tiers.

Open source?

Still inventory libraries and maintainer crypto practices.

Key concepts (technical dictionary)

Terms used on this page — open a definition:

Full technical dictionary →

Related on this site