All posts

PQC Basics · Part 8 of 10

PQC Readiness Score vs. Certificate vs. CBOM: What Should You Actually Look At?

August 23, 2026 ·  PQCClear  ·  6 minute read

Seven posts in, you have the full picture: why an inventory matters, what a CBOM actually contains, why the timeline compressed, why vendors matter, and what a real answer looks like. This post covers the last practical gap. Once that information exists, what form does it take, and which one should you be looking at?

Three Forms, Three Different Questions

A vendor’s cryptographic posture usually shows up in one of three forms: a score, a certificate, or a full report. They’re not competing formats. They answer different questions.

Like a credit score

A readiness score

A single number summarizing overall posture. Fast to compare across many vendors at once. Doesn't explain itself on its own; it's a triage tool, not a technical document.

Best for

Scanning a large vendor list to see who needs closer attention first.

Like a credit report

A verification certificate

A defined, dated confirmation that an assessment happened, usually with an expiration so it can't be treated as permanent. Meant to be shown to someone else and checked independently, not just taken on faith.

Best for

A vendor demonstrating readiness externally, and a bank getting a fast, checkable starting signal.

Like the loan file

A full CBOM report

Every algorithm, every key size, every finding, in full detail. Not something you skim across a hundred vendors. It's what you read when a specific vendor needs a real technical look, or an examiner asks for the underlying evidence.

Best for

A bank's own deep assessment of a High or Critical vendor, and examiner-ready documentation.

Naming What These Look Like in Practice

Since this series has stayed deliberately generic so far, here’s where we’ll name names. This is what PQCClear specifically calls each of the three forms above, since it’s easier to reason about with real examples in front of you rather than abstractions.

  1. 01

    PQC Readiness Score. A numeric score built from a vendor's questionnaire answers and, where applicable, scanner findings. Useful for comparing vendors at a glance. Not the whole story on its own.

  2. 02

    PQC Verified certificate. A dated badge, independently checkable in a public lookup, confirming a vendor completed a full questionnaire-plus-scanner assessment. It expires, so it can't sit unrenewed and still be trusted at face value.

  3. 03

    Full CBOM and findings report. The detailed technical record behind the score and the certificate. What a bank's own High or Critical tier assessment produces, and what gets handed to an examiner when they ask for the evidence rather than the summary.

Put together, the three forms cover the three moments where you actually need this information: scanning a portfolio (score), getting a fast independent starting signal (certificate), and doing the real work of an assessment or handing something to an examiner (full report). Reaching for the wrong one at the wrong moment is where most of the confusion in this space actually comes from, not from the underlying concepts being hard.

A number tells you where to look. A report tells you what you’ll find there.

That closes the second act of this series. We’ve gone from why keep an inventory at all to what to actually do with a vendor’s answer once you have one. The last two posts turn to a question we raised early and set aside: once all of this information exists, who should actually be able to see it, and how should it be protected?

Act 3: who gets to see all of this

Two posts left. Part 9 asks a question most organizations haven’t thought carefully about yet: not whether a CBOM should exist, but who should actually be allowed to look at one once it does.

Read part 9
PQC readiness scorePQC Verified certificateCBOM reportvendor assessment

PQC Basics is an ongoing series from PQCClear explaining post-quantum cryptography readiness in plain language, one idea at a time. This post represents PQCClear’s own editorial explanation and should not be construed as technical, legal, or regulatory advice.

The three named formats in the second half of this post describe PQCClear’s own products. Key sources: the CycloneDX specification, which defines the cryptographic bill of materials format referenced here; the Interagency Guidance on Third-Party Relationships: Risk Management (Federal Reserve, FDIC, and OCC, June 2023) on the depth of due diligence expected at higher risk tiers.