A shared language for the supplier conversation
The PKI Consortium’s PQC Maturity Model (PQCMM) describes post-quantum maturity for products and services across six levels, from 0 to 5. It gives customers and suppliers a common framework for discussing readiness and migration requirements.
Cryptoramic brings supported maturity reports alongside discovered software and cryptographic evidence. You can see which products have reported maturity, which versions the report covers, and where follow-up is needed.
Ask about the version you actually depend on
A supplier’s general roadmap does not establish the readiness of every product it sells. Match the report to the identified product or service and its version. Keep the publisher, report date, validity, and stated assurance in view.
Use that context to prepare a supplier discussion: Which deployed versions are covered? What is the target maturity? What evidence is missing? Which upgrade or roadmap milestone changes the decision?
Make uncertainty visible
Unreported means missing matching evidence. It does not mean the product cannot support PQC. An old report, a report for another version, and an observed cryptographic weakness are different findings.
A self-assessment, third-party assessment, or certification assertion also carries different assurance. Importing a report does not independently verify the assertion or certify the supplier.
From procurement to migration planning
Consultants can help customers turn supplier evidence into targeted requests and assessment priorities. Procurement teams can use the model to discuss requirements for specific products and services; engineers can connect those discussions to the inventory they are responsible for.
Cryptoramic does not turn one product’s maturity level into an organization-wide rating. Review the PQCMM inventory guidance and procurement guidance for the model’s intended scope.
