PQCClear Research
How cryptographic risk should be assessed, and why we think so
Findings and methodology philosophy drawn from our own vendor assessment work. Published for the banks, credit unions, and vendors who have to trust the reasoning behind a readiness score, not only the number it lands on.
Also on the site
Regulatory analysis, examiner briefs, and plain-English explainers live in PQCClear Intelligence.
All research
The Score Is Evidence, Not a Verdict: Why PQCClear Doesn't Tell You What Risk to Accept
We're often asked, reasonably, what score is good enough to work with a vendor. The honest answer is that we don't decide that, and we don't think we should. A methodology confident enough to say what's true should stop short of saying what you ought to do about it.
Read the researchReading Between the Lines: How PQCClear Surfaces Contradictions in Vendor Answers
A vendor completing every question isn't the same as a vendor whose answers are internally consistent. Some answer combinations simply can't both be true, and that disagreement is a finding in its own right rather than something a scoring average should quietly smooth over.
Read the researchWhy Your PQC Timeline Shouldn't Depend on Proof of a Quantum Breakthrough
Most conversations about post-quantum urgency eventually circle back to the same question: how would we actually know when to worry? A recent, carefully argued piece from independent quantum security researcher Marin Ivezic makes a case worth taking seriously. We may not get a clear answer to that question, and planning as though we will is a mistake.
Read the researchWhy Vendor Category Should Shape Cryptographic Risk Assessment
Industry analysts have started arguing that cryptographic exposure can't be a single, uniform number across every vendor. We agree, and we think the argument doesn't go far enough. The category a vendor falls into shouldn't just change how you read a score. It should change how the assessment itself is built.
Read the research