A Q-Advantage rating · methodology v1.0

The post-quantum vendor rating

Post-quantum vendors are selling into procurement reviews on the strength of their own marketing. PQC Arena rates them on 10 dimensions of cryptographic substance — whether the cryptography is correct, fast, integrated, agile, and honestly represented — so “why this vendor over that one” has an answer that survives an audit.

Who it's for

CISOs and procurement teams choosing between post-quantum suppliers, and the suppliers who want a claim they can substantiate.

The problem

The governance layer these vendors sell into has said publicly that performance differences are significant and under-tested. Most vendor material contains no performance numbers at all.

What it is

A relative, editorial rating against criteria published in advance, with every finding cited to a source you can open yourself.

Dimensions
10
Requirements
59
Tiers
6
Vendor categories
4
Tier threshold
7 of 10
Ratings published
None yet
Current state, stated plainly

The criteria are published. No vendor has been rated.

That is the intended order, not a delay. Criteria published before any verdict are what make a rating a procurement reference rather than an attack, and they give every vendor notice of the bar before it is applied. The assessment work is under way; a tier appears when there is enough evidence to justify one and not before.

The scale

6 tiers

Ratings are relative, not points-weighted — a vendor is compared against its peer set rather than scored out of a total.

Platinum

Leads on cryptographic substance across nearly every dimension, with independently verified correctness and performance, and discloses its own limitations without being asked.

Gold

Strong across most dimensions with independent verification available, and no conformance failures. Gaps exist and are visible rather than hidden.

Silver

Solid on the fundamentals, with meaningful gaps — commonly in independent verification, transparency, or protocol integration depth.

Bronze

Real post-quantum capability exists, but substantiation is thin: claims outrun published evidence on several dimensions.

Underperform

Falls short on a dimension that cannot be traded off — most directly, failing correctness against the standard the vendor itself claims. A conformance gate lands a vendor here regardless of its other scores.

Unavailable

Not enough public signal to rate, and no cooperation offered. This is explicitly not a judgement about quality: a vendor here has not been found wanting, it has not been assessable. In a market this young, expect this tier to be populated rather than empty.

Unavailable is not the bottom of the scaleA vendor in Unavailable has not been found wanting — it has not been assessable. There was not enough public signal to rate it and no cooperation was offered. It is rendered outside the ramp deliberately, and it is never sorted below Bronze. In a market this young, expect that tier to be populated rather than empty.
How the evidence is gathered

Four evidence tracks. The first three need nothing from the vendor.

Cooperation is an upgrade to the evidence, never a condition of being rated fairly. A vendor that never replies is still assessed.

1. Public claims auditNo cooperation needed

Read what the vendor publishes — documentation, case studies, whitepapers — and score what is and is not substantiated. This is the primary track, and it runs whether or not a vendor ever replies.

2. Independent testingNeeds a public surface

Where an implementation has a public SDK, library or endpoint, run it through Q-Shield directly. This is what turns correctness and performance from claims into measurements taken on named hardware, at a stated iteration count, traceable to a run you can inspect.

3. Certification-registry checksNo cooperation needed

Read the public registries — module validation lists, root-program inclusion — and record what was actually validated, at what scope, rather than what is marketed.

4. Vendor cooperationOptional, never required

Vendors are invited to provide deeper access, and get advance notice of the criteria and a pre-publication correction window. No fee is charged and none is accepted. A vendor that declines is still rated on tracks 1–3.

Boundaries

What PQC Arena is not

Not a benchmark of algorithms

That is Q-Shield, which measures the standardised algorithms themselves on real hardware every day. Arena rates the companies that implement them.

Not a measure of deployers

The PQC Readiness Index observes how institutions have configured themselves. Arena compares suppliers a buyer must choose between. Rating a deployer and rating a supplier are different acts and are kept apart.

Not a computed score

There is no 1–100 figure and no weighted formula. Several dimensions are irreducibly qualitative, and a number would give them a precision they do not have. The defensibility rests on published criteria, per-claim citation, right of reply, and the conformance gates.

Not for sale

No vendor pays for placement, for a tier, or for the timing of one. A rated party may buy data and reports like anyone else, and if it does, that fact is printed on its own rating.

The ratings are not published yet

The criteria are public so you can judge the bar before anyone is measured against it.

If you are choosing between post-quantum suppliers, or you are one and want to know how you will be assessed, get in touch. We will tell you when there are results to read.

A vendor in the pool, or think you should be? Cooperation gets you advance notice of the criteria and a pre-publication window to correct factual errors. It does not buy a better result.