industry · quantum risk
Is Vendor risk PQC Quantum Proof? Cyber Program & PQC
Verdict
Vendor risk programs must add PQC and hybrid questions with evidence standards. Marketing “quantum-safe” claims without algorithms, versions, and timelines are incomplete.
Overview
Most enterprises inherit cryptography from vendors. Questionnaires, RFPs, and SOC reports need crypto-specific depth.
Ties to Wave 5 claims methodology on this site for evaluating public claims.
Program inventory focus: SaaS and appliances hide classical crypto behind roadmaps and NDAs. Typical classical surfaces: Vendor TLS and product crypto; Subprocessor chains. Cross-read /security/program and /assessment. Educational only—not compliance advice.
Cryptographic profile
- Signatures: Vendor TLS and product crypto, Subprocessor chains
- Hash: Contract and assessment artifacts
- Public-key exposure: SaaS and appliances hide classical crypto behind roadmaps and NDAs.
What breaks
- Checkbox “encryption in transit” only
- No residual risk for classical-only critical SaaS
Mitigations
- Standard PQC questionnaire
- Tier vendors by data shelf life and exposure
- Contractual roadmap and notification clauses
FAQ
Reject vendors without PQC today?
Risk-based: require roadmaps and compensating controls; prioritize critical tiers.
Open source?
Still inventory libraries and maintainer crypto practices.
Key concepts (technical dictionary)
Terms used on this page — open a definition: