Skip to content

Methodology

Q-Day readiness methodology

NIST-aligned classification, Mosca inequality for harvest-now-decrypt-later, hybrid ML-KEM proof — with honest coverage limits.

Discovery scope

The scanner discovers TLS certificates, JWKS signing keys, SSH host keys, email STARTTLS, and uploaded PEM/CSV bundles. Live scans probe port 443 (and scenario-defined ports); unreachable endpoints are recorded in scan coverage, not as false-positive assets.

Classification (Shor / Grover)

Each asset is mapped to a quantum vulnerability status: broken, at-risk (Shor-vulnerable RSA/ECC), safe (symmetric or PQC-ready), or unknown. Shor logical-qubit estimates are order-of-magnitude references only.

Mosca inequality

X (data shelf-life) + Y (migration time) versus Z (years to cryptographically relevant quantum computing). When X + Y > Z, harvest-now-decrypt-later risk is elevated for long-lived ciphertext.

Readiness score formula

Composite 0–100 score from quantum-vulnerable asset share, HNDL exposure, PQC-ready endpoint credit, and remediation coverage. Bands: Critical / At Risk / Developing / Prepared.

Coverage confidence

Heuristic 0–95% based on classified asset count (40% base + 4% per asset, capped at 95%). This is not a guarantee — shadow APIs, HSMs, and offline keys may be missed.

Glossary

  • Readiness score0–100 composite score reflecting quantum-vulnerable asset share, HNDL exposure, PQC-ready endpoints, and remediation coverage. Higher is better. Reference
  • Readiness bandQualitative tier (Critical / At Risk / Developing / Prepared) derived from the readiness score for executive reporting. Reference
  • Coverage confidenceHeuristic 0–95% estimate of scan completeness based on classified asset count. Not a guarantee — shadow keys and offline HSMs may be missed.
  • Mosca inequality (X + Y > Z)Dr. Michele Mosca's harvest-now-decrypt-later test: data shelf-life (X) plus migration time (Y) versus years to cryptographically relevant quantum computing (Z). When X + Y > Z, intercepted ciphertext may be decrypted before you finish migrating. Reference
  • HNDL (Harvest Now, Decrypt Later)Adversaries record encrypted traffic today and decrypt it once a cryptographically relevant quantum computer exists. Long-lived secrets and archived ciphertext are most exposed. Reference
  • Already too lateAsset flagged when Mosca inequality holds for its data class — migration may not protect previously intercepted ciphertext.
  • HNDL exposedAsset flagged when Mosca inequality holds for its data class — migration may not protect previously intercepted ciphertext.
  • CRQC (Cryptographically Relevant Quantum Computer)A quantum computer capable of breaking widely deployed public-key cryptography such as RSA and elliptic-curve algorithms at scale. Reference
  • CiphertextEncrypted data — readable only with the correct key. HNDL adversaries store ciphertext today to decrypt later when quantum computers break the wrapping public-key layer.
  • Forward secrecyProperty of TLS 1.3 where session keys are ephemeral — passive capture of application data alone is insufficient without the handshake record.
  • Key encapsulation (KEM)Mechanism for securely exchanging symmetric keys. ML-KEM (FIPS 203) is the NIST-standardized post-quantum key encapsulation algorithm. Reference
  • ECDH (Elliptic Curve Diffie-Hellman)Key exchange using elliptic curves — quantum-vulnerable via Shor's algorithm. Used in most modern TLS handshakes.
  • STARTTLSEmail encryption upgrade from plaintext to TLS in transit. Often uses RSA or ECDH — inventory email paths alongside web TLS.
  • ML-KEMNIST FIPS 203 module-lattice key encapsulation — the standardized post-quantum replacement for RSA/ECDH key exchange in hybrid TLS. Reference
  • Shor logical qubitsOrder-of-magnitude estimate of logical qubits required to break this key size via Shor's algorithm. Estimates only — not a Q-Day prediction. Reference
  • SeverityBusiness impact tier (critical / high / medium / low / info) based on algorithm, exposure, and asset kind.
  • Quantum statusClassification: broken (deprecated now), at-risk (Shor-vulnerable), safe (symmetric / PQC-ready), or unknown. Reference
  • PQC readyEndpoint negotiates hybrid post-quantum key exchange (e.g. X25519MLKEM768) or uses NIST-approved PQC algorithms. Reference
  • Remediation coveragePercentage of identified gaps with an assigned remediation action and tracked status.
  • Crypto-agility scoreDistinct from readiness: measures how quickly keys and algorithms can be rotated without service disruption. Reference

Limitations

  • Endpoint-scoped inventory aid — not a formal cryptographic audit or penetration test.
  • RSA/ECC remain classically secure until cryptographically relevant QC exists.
  • Fixture replays use curated data; live scans reflect point-in-time negotiation.

References & standards

Authoritative primary sources cited in this report. Full methodology

  • Readiness score0–100 composite score reflecting quantum-vulnerable asset share, HNDL exposure, PQC-ready endpoints, and remediation coverage. Higher is better.
  • Readiness bandQualitative tier (Critical / At Risk / Developing / Prepared) derived from the readiness score for executive reporting.
  • Coverage confidenceHeuristic 0–95% estimate of scan completeness based on classified asset count. Not a guarantee — shadow keys and offline HSMs may be missed.
  • Mosca inequality (X + Y > Z)Dr. Michele Mosca's harvest-now-decrypt-later test: data shelf-life (X) plus migration time (Y) versus years to cryptographically relevant quantum computing (Z). When X + Y > Z, intercepted ciphertext may be decrypted before you finish migrating.
  • NIST IR 8547Transition to post-quantum cryptography standards
  • FIPS 203 (ML-KEM)Module-Lattice-Based Key-Encapsulation Mechanism
  • FIPS 204 (ML-DSA)Module-Lattice-Based Digital Signature Algorithm
  • FIPS 205 (SLH-DSA)Stateless Hash-Based Digital Signature Algorithm
  • NIST SP 800-208Stateful hash signatures for firmware/code signing
  • CNSA 2.0NSA Commercial National Security Algorithm Suite 2.0
  • NSM-10National Security Memorandum on post-quantum cryptography
  • PCI-DSS 4.0Payment card industry cryptographic agility requirements
  • CMMC / FedRAMPFederal contractor cryptographic inventory and migration
  • HIPAA Security RulePHI transmission security and risk analysis
  • EU Cyber Resilience ActCrypto-agility and vulnerability disclosure for digital products
  • ISO/IEC 27001Information security management — cryptographic controls
  • DORADigital Operational Resilience Act (EU financial sector)
  • SOC 2Trust services criteria — encryption and key management
  • GDPR Art. 32Security of processing — state-of-the-art encryption
  • FedRAMPFederal cloud security — FIPS-validated cryptography
  • CISA PQC RoadmapCISA guidance for migrating to post-quantum cryptography

Return to Q-Day assessment