BTC Tools

Signature · Institutional → Quantum Core Institute

Quantum Readiness Score

A self-assessment against QCI-QS1. Score your organization across the five Q-Risk pillars and get a number a board can act on, held honest by the same ceiling gates a QCI assessor applies, so the score reflects evidence, not optimism.

Standard: QCI-QS1 v2.2 · Q-Risk Score (0–100) · QRAF governance · QASI inventory

Score each pillar on the 0–5 maturity scale

28 / 100
Behind

Plans may exist on paper. Execution is weak or absent.

020406080100

Score-ceiling gates

A low first score is normal. Most organizations that take QCI-QS1 seriously land their baseline in the Behind band. A 28 with a credible plan to reach 55 beats a self-flattering 70 with no evidence behind it.
Validate this with a QCI Assessment →
This is a self-score, not an audited one. Under QCI-QS1, any pillar above Level 1 needs a retrievable evidence artifact, a ticket #, document path, or export. Level 5 requires externally validated evidence; self-attestation doesn't qualify. When in doubt, score down.

What this leaves out. QCI-QS1 self-score, not an audit. Self-attestation does not satisfy Level 5 evidence requirements. Process maturity, third-party dependencies, and supply-chain key exposure need separate review.

BTC Tools · Quantum Core InstituteSelf-assessment against QCI-QS1 v2.2. Not a certified Q-Risk Score.

FAQ

What does it actually mean for an organization to be quantum-ready?

Quantum readiness is not a binary state. It's a maturity continuum across several independent dimensions, and most organizations are at very different stages on each.

The five dimensions the score assesses:

Cryptographic inventory: Do you know which systems, keys, and data stores use cryptography that quantum computers will eventually break (RSA, ECC, Diffie-Hellman)? Most organizations have never done this audit. Without an inventory, migration is impossible.

Algorithm migration: Have you moved or begun moving to NIST post-quantum standards? CRYSTALS-Kyber for key encapsulation, CRYSTALS-Dilithium and FALCON for digital signatures were standardized in 2024. These are the target.

Key management infrastructure: Can your HSMs, PKI, and certificate lifecycle tools handle post-quantum algorithms? Many cannot yet — hardware and software upgrades are required, not just configuration changes.

Supply chain and vendor assessment: Your quantum readiness is bounded by your least-ready critical vendor. If your cloud provider, payment processor, or financial infrastructure runs on classical cryptography with no PQC roadmap, your perimeter exposure remains even if your internal systems are migrated.

Governance and timeline: Does your CISO or CTO have a documented quantum risk policy? Is there a board-level understanding of the timeline and budget implications? Organizations that treat this as purely a technical problem will be caught without budget when hardware migration timelines compress.

Why the score matters now:

NIST finalized PQC standards in 2024. CISA has issued guidance recommending migration roadmaps begin immediately for critical infrastructure. For organizations holding Bitcoin or operating in financial services, quantum readiness is becoming a regulatory and fiduciary question, not just a technical one.

Which post-quantum algorithms should we be adopting?

Use the NIST-standardized set. These were finalised in 2024 after a multi-year competition and are the only algorithms enterprise security teams should treat as production-ready.

  • ML-KEM (CRYSTALS-Kyber): key encapsulation. Replaces RSA-OAEP and ECDH for key establishment
  • ML-DSA (CRYSTALS-Dilithium): digital signatures. General-purpose, larger signature size
  • SLH-DSA (SPHINCS+): stateless hash-based signatures. Conservative backup choice, very large signatures
  • FN-DSA (FALCON): digital signatures, smaller than Dilithium, more complex to implement safely

In production, hybrid schemes — classical + PQ in parallel — are the safe transition pattern. They protect against both classical attack and against an unforeseen weakness in a relatively new PQ scheme.

Where do organizations typically fail this assessment?

Three failure modes account for nearly every low score:

  • No cryptographic inventory. The team that owns security has no list of where RSA, ECC and Diffie-Hellman are actually used inside the org. Migration is impossible without this list — and building it is a 3–9 month exercise, not a week
  • Vendor dependency unaccounted for. The CISO has a plan for internal systems but no contractual commitment from cloud providers, identity providers, or payment processors. The actual perimeter is wider than the team being measured
  • No board mandate or budget. The technical team understands the timeline, but there's no executive sponsor and no multi-year capital allocation. Migration projects without budget slip indefinitely
Is regulatory pressure on PQ migration real, or theoretical?

Increasingly real. The trajectory:

  • 2022: NSM-10 (US) — federal agencies required to inventory cryptographic systems
  • 2024: NIST PQ standards finalised; CISA issues migration guidance
  • 2025: federal contracting language begins to reference PQ-readiness as a procurement criterion
  • 2026+: financial regulators in EU, UK and APAC publishing supervisory expectations for systemically important institutions

For regulated financial services, treasury offices and custodians, the question is no longer whether to have a PQ roadmap, but how detailed and credible the roadmap is. The readiness score is a structured way to answer that question to a board, auditor or regulator.

Methodology

Self-assessment across five Q-Risk pillars producing a 0–100 composite, with ceiling gates that cap the score when evidence is absent.

Pillar Weights
w = {Gov 20, Visibility 20, Data 20, Migration 25, 3rd-Party 15}
Per-Pillar Maturity
level_i ∈ [0, 5]
Raw Composite
Score_raw = Σᵢ (level_i ÷ 5) · w_i
Ceiling Gates
QASI < threshold → cap 60; vendors un-attested → cap 70; agility unproven → cap 80
Final Score
Score_final = min(Score_raw, ceiling)
Bands
Exposed 0–19 · Behind 20–39 · Mobilizing 40–59 · Advancing 60–79 · Defensible 80–100

Paper plans without evidence cannot lift the ceiling. Most organizations baseline in Behind — a credible plan to reach Advancing is the realistic first objective.

Get the signal, not the noise

Weekly Bitcoin cycle alerts — MVRV, Pi Cycle, and power-law position in one email.

© 2025–2026 Satoshi Institute Inc. | All Rights Reservedbtccalcs.com — Not financial advice.