PQCClear Research
The Score Is Evidence, Not a Verdict: Why PQCClear Doesn't Tell You What Risk to Accept
September 15, 2026 · PQCClear · 6 minute read
We're often asked, reasonably, what score is “good enough” to work with a vendor. The honest answer is that we don't decide that, and we don't think we should. Here's why, and what we do instead.
We Score the Evidence. We Don't Grade the Decision.
A bank might reasonably choose to keep working with a vendor still running TLS 1.0, if that vendor handles low-sensitivity data, has a credible remediation timeline, and the relationship is otherwise sound. Another bank might walk away from the exact same finding for a vendor touching core payment data. Neither decision is wrong. They’re both informed, institution-specific judgment calls, and that’s exactly how it should work.
PQCClear’s methodology produces a readiness score built from a fixed, consistent set of factors, applied the same way to every vendor. What it deliberately does not produce is a pass or fail line telling your institution which score is acceptable for your business. We’re not in a position to know that, and honestly, nobody outside your own institution is.
A Concrete Example
What a report actually shows
Illustrative
- Finding
- Deprecated TLS still permittedVendor still permits TLS 1.0 and 1.1 on a subset of internet-facing endpoints. No formal migration plan documented. No standing process to generate or maintain a cryptographic inventory.
- What we do
- Score it, flag it, name itScore each factor accurately, flag the deprecated protocol clearly, and note the absence of a migration plan and inventory process as findings in their own right, not softened or buried in an average.
- What we don't do
- Rule the vendor in or outWhether this vendor is acceptable to work with depends on what it handles for you, what your regulatory exposure looks like, and what your institution's own risk appetite allows. We give you the finding. You bring the context only you have.
That’s not a hedge or a way of avoiding responsibility for the assessment itself. The assessment is rigorous, consistent, and ours to stand behind completely. What belongs to you is the decision about what level of risk fits your institution, because that decision depends on things no third-party methodology can see: your portfolio, your regulatory posture, your existing relationship with that vendor, your own board’s risk tolerance.
We tell you what’s true. You decide what’s acceptable.
Why We're Careful About This, Even When It Would Be Easier Not to Be
It would be simpler, in some ways, to publish a single pass or fail threshold. It would also mean quietly imposing our own judgment about acceptable risk onto every institution that uses PQCClear, regardless of whether that judgment actually fits their situation. A methodology confident enough to say “here’s exactly what’s true” should be humble enough to stop short of saying “and here’s what you should do about it,” especially when the second part depends on things the methodology was never built to see.
There’s a second layer to this, beyond the score itself, worth its own space: what happens when a vendor’s own answers don’t agree with each other. That’s the subject of the next piece in this series.
See the evidence, make the call yourself
PQCClear gives your institution complete, honest evidence about vendor cryptographic risk, built for the risk decisions only your institution can make.
Get in touchThis piece reflects PQCClear’s own methodology and philosophy as of September 15, 2026. It does not disclose the specific weighting, question design, or internal scoring mechanics of PQCClear’s assessment platform, which remain proprietary. It should not be construed as legal, regulatory, or investment advice.
The vendor finding shown above is an illustrative composite written for this piece, not an excerpt from any real assessment.