Observatory · Methodology

How CRQC verifies evidence

The observatory is structured data first and editorial content second. This page is the contract behind every band, chip and date shown elsewhere on the site.

Dataset as of 2026-09-06
Evidence classes
A1

Normative primary

Sources

Statutes, executive orders, final NIST standards, RFCs, regulator rules, formal national policy

Permitted use

Can support 'requires', 'must', 'standardised' or exact deadline language

A2

Authoritative guidance

Sources

NCSC, CSE, ASD, ANSSI, ENISA, CSA, national CSIRTs, NIST guidance

Permitted use

Can support official recommendations and roadmaps

A3

Official implementation evidence

Sources

Government pilots, certification databases, regulator assessments

Permitted use

Can support claims that a deployment or certification occurred

B

Scientific

Sources

Peer-reviewed journals and conferences

Permitted use

Technical feasibility, migration studies, performance and security evidence

C

First-party industry

Sources

Cloudflare, Google, Microsoft, AWS, Sectigo, DigiCert, the OpenSSL project

Permitted use

Authoritative only for that organisation's own product or roadmap

D

High-quality secondary

Sources

Reputable technical and news analysis

Permitted use

Discovery and context; should be paired with or replaced by primary evidence

E

Discovery only

Sources

Vendor marketing aggregations, social posts, unsourced timelines

Permitted use

Never sufficient for a material CRQC claim

Document status vocabulary
draftproposedadoptedfinaleffectivesupersededwithdrawn

Status prevents the most common error in post-quantum coverage today: treating a draft transition proposal as if it were final regulation.

Readiness bands
  • Observed
  • Planning
  • Mobilizing
  • Executing
  • Broad transition
  • Evidence insufficient
Readiness dimensions

Policy

Published strategy, named authority, explicit scope

Deadline maturity

None → aspirational → dated milestones → enforceable requirement

Technical standards

Algorithm and protocol adoption

Execution evidence

Pilots, certifications, product support, regulatory assessments

Supply-chain enablement

Libraries, cloud, HSM, PKI, network and device availability

Evidence confidence

Quality and directness of the underlying sources

CRQC deliberately does not publish a single composite score such as "United States 87/100". A single number creates false precision and hides which layer of the problem a jurisdiction is actually solving.

Editorial rules
  • ·Readiness bands measure observable preparation; technology records separately report sourced capability evidence without folding it into those scores.
  • ·A high band does not mean a jurisdiction is safe; a low band may mean thin public documentation.
  • ·Draft documents are labelled draft, and their dates are described as proposals.
  • ·Relevance to an industry is never rewritten as a legal obligation for that industry.
  • ·First-party vendor evidence is authoritative only for that vendor's own product or roadmap.
  • ·Where no authoritative public timeline exists, CRQC records an evidence gap rather than a low score.
  • ·Every material claim carries an authority, evidence class, document status and review date.
Vocabulary

Terms used across these records — ML-KEM, SLH-DSA, logical qubits, crypto-agility, bindingness — are defined in the post-quantum glossary.