The standard · methodology v1.0

Evaluation criteria

PQC Arena rates post-quantum vendors across 10 dimensions of cryptographic substance — whether the cryptography is correct, fast, integrated, agile, and honestly represented. This is the whole standard, in full, before anyone is measured against it.

Download .md
Dimensions
10
Requirements
59
Conformance gates
1
Vendor categories
4
Methodology
v1.0
Ratings published
None yet
Scope to

59 requirements across 10 dimensions

01

Algorithm correctness & standards conformance

Conformance gate6 requirements

Does the implementation actually compute the standardised algorithm correctly, against whichever standard it claims conformance to?

Conformance gate

Failing known-answer tests against the standard it claims, or still shipping pre-final parameter sets past a stated deadline, results in Underperform regardless of how the vendor scores on every other dimension.

Requirements · 6
Evidence sourceIndependent testing (Q-Shield) plus the relevant national standard body's own published test vectors.
References
02

Independently measured performance

6 requirements

What does the implementation actually cost to run, measured by someone with no stake in the answer?

Requirements · 6
  • Keygen / encapsulate / decapsulate and keygen / sign / verify timings, measured rather than quoted.

    • Reported with a distribution, not a single mean — median, p95 and p99 at a stated iteration count.

    • Measured on named hardware, at a stated liboqs or library version, traceable to a reproducible public run.

  • Measured on more than one architecture (x86-64 and ARM) so the numbers travel to the reader's estate.

  • Handshake-level cost measured in situ, not inferred by adding primitive timings together.

    TLS / networkPKI / CA
  • Key, ciphertext and signature sizes checked against the standard rather than taken from the datasheet.

  • Operations per second under sustained load, and the point at which the device saturates.

    HSM
  • Where an implementation is not independently testable, that is recorded as not assessed — never inferred from the vendor's own published figures, and never scored as zero.

Evidence sourceQ-Shield, Q-Advantage's daily benchmark harness — measurements taken on named hardware and published openly.
03

Protocol integration depth

5 requirements

Is this a raw primitive library, or something that actually terminates a real protocol?

Requirements · 5
  • Raw algorithm library only, versus integration into TLS, QUIC, SSH or IPsec.

    • Which protocols are supported, and at which layer the vendor's code sits.

    • Whether integration is a supported product or a reference sample.

  • Hybrid key exchange supported, and available in production rather than behind a branch or a flag.

  • Post-quantum authentication — signatures in the handshake and in the certificate chain — not only key exchange.

    • Key exchange alone addresses harvest-now-decrypt-later. It does not address a forged chain.

    • Where PQ authentication is not yet offered, whether the vendor says so plainly.

  • PQC and hybrid certificate issuance actually reaches a usable chain, including intermediates and revocation.

    PKI / CA
  • Integration is documented for practitioners — configuration, supported suites, failure modes — not only announced in a press release.

Evidence sourcePublic documentation, plus independent testing wherever a testable endpoint or SDK exists.
References
04

Crypto-agility

6 requirements

Can a customer change algorithms later without re-architecting — the question every regulator is converging on?

Requirements · 6
  • Algorithms are selectable through configuration rather than compiled in.

  • More than one algorithm family is supported for the same function, so a break in one is survivable.

    • Lattice and hash-based signatures both available, rather than a single lattice bet.

    • For KEMs, whether anything other than ML-KEM is offered.

  • A documented path exists for replacing an algorithm after deployment, including what happens to data already protected.

  • Hybrid and classical-only modes can both be expressed, since jurisdictions differ on which is required.

  • Cryptographic inventory or bill-of-materials output is available in a machine-readable form.

  • Algorithm changes are deliverable as a firmware update to devices already in the field.

    HSM
Evidence sourcePublic documentation.
References
05

Transparency & disclosure

6 requirements

Does the vendor show its work — publish methodology, cite third parties, and state its own limitations?

Requirements · 6
  • Performance claims are accompanied by actual numbers rather than adjectives.

    • "Minimal impact", "negligible overhead" and similar phrasing, with no figure attached, scores as no claim at all.

  • Third-party or independent validation is cited, and the citation is not circular — a source that itself cites the vendor does not count.

  • Test conditions behind any published figure are stated: hardware, software versions, iteration counts, and what was being measured.

  • Known limitations are disclosed by the vendor rather than found by a reviewer.

  • Technical claims are attributed to named people rather than to the company in the abstract.

  • A reader with the same hardware could in principle reproduce the vendor's published figure from what is published.

Evidence sourcePublic claims audit — reading the vendor's own published documentation, case studies and whitepapers.
06

Compliance & certification

7 requirements

What has actually been validated by an external body, as opposed to asserted?

Requirements · 7
  • FIPS 140-3 validation status, checked against the public CMVP Validated Modules list.

    HSMLibrary / SDKPKI / CA
  • Whether a module is validated, in process, or neither — three different states, reported as such and never collapsed into “FIPS compliant”.

  • The certificate's scope is read, not just its existence: what was validated is frequently narrower than what is marketed.

    • Which module, which version, and which operational environment the certificate actually covers.

    • Whether the PQC algorithms specifically are in scope, or only the classical ones.

  • Common Criteria evaluation status, with protection profile and assurance level, where applicable.

    HSMPKI / CA
  • Browser and OS root-program inclusion, and standing in good order with the relevant program requirements.

    PKI / CA
  • Sector-specific certifications relevant to the vendor's stated market.

  • Where CNSA 2.0 alignment is claimed, the claim matches the suite's actual algorithm and timeline requirements.

Evidence sourcePublic certification registries.
References
07

Deployment & support model

7 requirements

What is it actually like to buy, deploy and be supported on this — including whether the price is discoverable at all?

Requirements · 7
  • Pricing is published, indicative, or contact-only — recorded as found, without treating contact-only as disqualifying.

  • Trial availability and evaluation licensing: can an engineer try it before a sales conversation?

  • Contract flexibility — term length, exit terms, and whether migration off the product is contemplated.

  • Migration support offered, and whether it is included or a separate professional-services line.

  • Documentation is sufficient to deploy without a sales engagement.

  • Support model and response commitments are stated, including who carries the pager for a cryptographic defect.

  • A published vulnerability-disclosure process, and a track record of using it.

    • Where to report, and expected response time.

    • Whether past advisories were published, and how quickly patches followed.

Evidence sourcePublic documentation.
08

Interoperability & ecosystem

6 requirements

Does it work with anything the customer already has, or only with itself?

Requirements · 6
  • Compatibility with liboqs and the Open Quantum Safe integrations, as an interoperability baseline.

  • Participation in the relevant IETF work, and conformance to the hybrid-TLS design as it stands.

  • Demonstrated interoperation with at least one independent implementation, not only with the vendor's own client.

  • Keys, certificates and messages use standard encodings that another product can consume.

    PKI / CAHSMTLS / network
  • Language bindings, platform and architecture coverage relative to what the vendor's market actually runs.

    Library / SDK
  • Standard integration interfaces are supported for post-quantum key types, not only for classical ones.

    HSM
Evidence sourcePublic documentation plus Open Quantum Safe's own provider and integration list.
References
09

Track-record credibility

5 requirements

Is there evidence this has been deployed and survived contact with production?

Requirements · 5
  • A named production deployment, rather than a pilot described in the abstract.

    • Whether the customer is named, or only a sector is.

    • Whether the deployment is production or an evaluation.

  • Published case studies contain actual data rather than only qualitative claims.

  • Partnership and ecosystem announcements are recorded as what they are, and never counted as deployment evidence.

  • How long the deployment has run and at what scale, where either is discoverable.

  • Publicly known incidents or defects affecting the cryptographic product, and how the vendor handled them.

Evidence sourcePublic claims audit.
10

Roadmap & standards currency

5 requirements

Is the vendor keeping pace with a standards landscape that is still moving?

Requirements · 5
  • A stated timeline for algorithms still being standardised, rather than silence.

  • Evidence the vendor tracks standards revisions, and ships against final rather than draft text.

  • A stated policy for deprecating an algorithm, including notice periods for customers.

  • Alignment with the published regulatory timelines the vendor's market is actually held to.

  • Roadmap items are distinguishable from shipped features in the vendor's own material.

Evidence sourcePublic documentation.
References
Scoping

Requirements by dimension and vendor category

The scoping is itself a claim: it says which requirements each kind of vendor is held to, so a vendor can check it was applied consistently.

Overrides

Conformance gates

Failing one of these lands a vendor in Underperform regardless of how it does everywhere else.

1. Algorithm correctness & standards conformance

Failing known-answer tests against the standard it claims, or still shipping pre-final parameter sets past a stated deadline, results in Underperform regardless of how the vendor scores on every other dimension.

Scope

What kind of vendor Arena rates

Systems integrators and advisory practices are deliberately absent — they sell labour rather than implementations, and rating them on cryptographic substance would be a category error.

Library / SDK

Commercial PQC cryptographic libraries and developer SDKs.

50 requirements in scope
HSM

Hardware security modules shipping post-quantum firmware.

55 requirements in scope
PKI / CA

Certificate authorities and PKI platforms with PQC issuance.

54 requirements in scope
TLS / network

Network and transport security products shipping PQC support.

50 requirements in scope
How to read a citationEvery reference carries how well it was actually checked. Confirmed means the primary source text was read directly. Search-corroborated means it was consistent across sources but the primary was not read. Unverified means it is named as a lead and has not been checked — treat it as a pointer, never as a citation. A reference is never upgraded without someone reading the source.
The ratings are not published yet

The criteria are public so you can judge the bar before anyone is measured against it.

If you are choosing between post-quantum suppliers, or you are one and want to know how you will be assessed, get in touch. We will tell you when there are results to read.

A vendor in the pool, or think you should be? Cooperation gets you advance notice of the criteria and a pre-publication window to correct factual errors. It does not buy a better result.