Working Groups

Members

The PKI Consortium brings together leading organizations committed to trustworthy digital identities and secure communication.

Browse all members →
Edit on GitHub

Working Groups PQCPQC Maturity Model (PQCMM)Adopting the Model

Playbooks

Practical adoption paths for small organizations, large organizations, enterprises, governments, regulated sectors, and critical infrastructure using the PQC Maturity Model.

Choose the Right Starting Point

Every organization can use the PQC Maturity Model (PQCMM), but not every organization needs the same operating model. The right approach depends on supplier risk tier, data lifetime, procurement formality, and available security expertise.

Organization or use caseStart here
Limited procurement or security staffSmall Organizations
Established procurement and vendor-risk functionsLarge Organizations
Formal governance, audit, or public-sector procurementEnterprises and Governments
Regulated, critical infrastructure, public trust, or high-assurance useRegulated and Critical Infrastructure

Common Pattern

All playbooks use the same simple pattern:

  1. Buy — set a minimum level and assurance method before purchase or renewal.
  2. Evaluate — require an assessment or certification report and check mandatory gates.
  3. Contract — record commitments, reassessment triggers, evidence handling, and milestones.
  4. Monitor — keep a supplier inventory and reassess after major changes or renewal.

This keeps adoption simple while still supporting stronger controls where risk requires them.

Starting Thresholds

Use these as examples, then adapt them to your risk appetite and regulatory context.

Product or serviceTypical starting requirement
Low-risk business software with short-lived dataLevel 1 or roadmap to Level 2
Standard production service using cryptographyLevel 2 with evidence
Identity, certificate, signing, key-management, or security infrastructureLevel 3 or higher; independent assessment preferred
Hardware security module, trust-service infrastructure, code signing, firmware signing, or critical data protectionLevel 4 or higher; independent assessment expected
Government high assurance, public trust, or strategic critical infrastructureCertification or highest-assurance route where required