Skip to main content

QRS Scoring & Risk Assessment

Applies to:
Quantum Readiness Score (QRS)Per-asset RiskSeverity & PriorityMigration Planning

Two complementary scores​

The scanner produces two different scores. Don't confuse them:

ScoreScopeRangeUsed for
Quantum Readiness Score (QRS)A whole scan / organization / domain0–100Executive posture, benchmarking, the PDF report
Per-asset riskA single finding (cert, key, endpoint)0–10Ranking and prioritizing individual assets

The QRS is the headline number on the dashboard and the PDF report. The per-asset risk is what orders the findings table.

Quantum Readiness Dashboard in DuoKey Cockpit


The Quantum Readiness Score (QRS)​

The QRS is a composite 0–100 score aggregated from four weighted signals:

QRS signal weights
Algorithm Resilience40%
Crypto Agility30%
Harvest Exposure20%
Migration Posture10%
weighted sum
Quantum Readiness Score0-100

The Quantum Readiness Score is a weighted composite of four signals that sum to 100.

QRS = Algorithm Resilience · 40%
+ Crypto Agility · 30%
+ Harvest Exposure · 20%
+ Migration Posture · 10%

Each signal is normalized to its weight bucket, so the per-signal numbers shown in the report (e.g. "18 / 40") sum to the overall total.

Readiness bands​

The total maps to a band. The internal band names are paired with the readiness labels shown to readers (the report uses readiness terminology rather than risk verdicts):

ScoreBandReport labelHNDL exposure
90–100Quantum-Safe ReadyADVANCED READINESS—
70–89Hybrid MigrationDEVELOPING READINESS—
40–69Quantum-VulnerableEARLY READINESSModerate HNDL exposure
0–39Critical RiskLOW READINESSHigh HNDL exposure
Note
HNDL = Harvest Now, Decrypt Later — traffic an adversary can record today and decrypt once a cryptographically-relevant quantum computer exists.

Scoring profile (jurisdiction-aware)​

The AEAD sub-signal is graded against one of two scoring profiles, selected from the report's target jurisdiction:

ProfileApplies toAEAD rule
Civilian (default)NIST SP 800-131A, ENISA, ANSSI, BSI TR-02102, CRYPTREC, UAE CSC, KSA NCA…AES-256-GCM, AES-128-GCM and ChaCha20-Poly1305 all count as strong
NSS / CNSA 2.0US federal National Security Systems only (jurisdiction us_nss)AES-256 only — AES-128-GCM and ChaCha20-Poly1305 are not accepted
Caution
CNSA 2.0 is only applied when the operator explicitly selects the us_nss jurisdiction. It is never inferred from us alone — civilian US is NIST/FIPS-aligned and accepts AES-128-GCM.

Signal breakdown​

The report's "Score & signal breakdown" page shows exactly how each signal was earned, down to the sub-signal:

QRS score and signal breakdown report page

01 · Algorithm Resilience — 40 pts​

Sub-signalMaxHow points are earned
Asymmetric primitives20100% PQC (ML-KEM + ML-DSA) = 20 · hybrid majority (≥50% endpoints) = 14 · partial hybrid (<50%) = 8 · 100% classical RSA/ECDSA = 4 · RSA-1024 or SHA-1 in signature = 0 (floor)
AEAD layer10Civilian: AES-256-GCM = 10 · ChaCha20-Poly1305 = 9 · AES-128-GCM = 8 · CBC mix = 3 · weak/legacy = 0. CNSA 2.0: AES-256-GCM = 10, everything else = 0
Key sizes & curves10RSA-3072+ or P-384+ = 10 · RSA-2048 or P-256 = 6 · mixed, no weak = 3 · weak (RSA < 2048 / non-NIST curve) = 0

02 · Crypto Agility — 30 pts​

Sub-signalMaxHow points are earned
TLS 1.3 adoption1010 × (share of endpoints negotiating TLS 1.3)
Hybrid suite support88 if a hybrid suite (e.g. X25519MLKEM768) is accepted, else 0
Cert rotation cadence5≤90d = 5 · ≤200d = 3 · ≤398d = 1 · >398d = 0
Algorithm diversity40–1 CA = 0 · 2 CAs = 2 · 3+ CAs = 4
CAA records22 if CAA present at the apex, else 0
DNSSEC algorithm11 if DNSSEC enabled, else 0

03 · Harvest Exposure — 20 pts​

Sub-signalMaxHow points are earned
PFS coverage12forward-secrecy share × 0.12
Priority load88 − min(8, 2 × critical findings + high findings)
RSA key-transport floor—Global −10 penalty if any endpoint still offers RSA key transport (no forward secrecy)

04 · Migration Posture — 10 pts​

Sub-signalMaxHow points are earned
Hybrid ML-KEM penetration7≥50% endpoints negotiate hybrid = 7 · partial (>0, <50%) = 4 · offered but not negotiated = 2 · none = 0
Cert-lifecycle laggard3Longest-lived leaf: ≤90d = 3 · ≤200d = 1 · >200d = 0

Score 48 / 100 → EARLY READINESS (Quantum-Vulnerable band, moderate HNDL exposure):

  • 01 Algorithm Resilience 18/40 — Asymmetric 4/20 (100% classical, RSA-2048, ECDSA 0%, no hybrid), AEAD 8/10 (AES-128-GCM, civilian profile), Keys 6/10 (RSA-2048, acceptable through 2030 per NIST IR 8547).
  • 02 Crypto Agility 11/30 — TLS 1.3 10/10, Hybrid suite 0/8, Cert rotation 1/5 (avg 354d), Algorithm diversity 0/4 (single CA), CAA 0/2, DNSSEC 0/1.

Per-asset risk (0–10)​

Each individual finding also gets a quantum risk score (0.0–10.0) from the algorithm it uses, which maps to a severity and a priority. This is what ranks the findings list.

Algorithm → risk score​

AlgorithmKey size / curveRiskSeverityRationale
RSA< 2048-bit10.0CriticalWeak classically and quantum-broken by Shor
RSA2048-bit8.0HighCurrent standard, quantum-vulnerable
RSA3072-bit6.0Medium~128-bit classical security
RSA4096-bit5.0Medium~152-bit classical security, still quantum-vulnerable
ECDSAP-2568.0HighBroken by Shor
EdDSA (Ed25519/Ed448)—7.0HighModern but quantum-vulnerable
DSAAny9.0CriticalDeprecated and quantum-vulnerable
DH / DHEAny8.0HighDiscrete-log, quantum-vulnerable
3DES / DES—10.0CriticalDeprecated — replace immediately
RC4—10.0CriticalBroken cipher
MD5—9.0CriticalBroken hash
SHA-1—8.0HighCollision-vulnerable (not quantum-related)
AES / ChaCha20-Poly1305—2.0LowSymmetric — quantum-safe (Grover only halves strength)
SHA-256/384/512—1.0InfoQuantum-safe hash
ML-KEM-768 (FIPS 203)Level 31.0LowPost-quantum, recommended
Hybrid (X25519 + ML-KEM)—1.5LowDefense-in-depth transition
Note
If a finding carries business context (CMDB CI, environment, business unit), it is attached to the finding and used to inform prioritization. The risk score itself is driven by the cryptographic algorithm, not by guessed business weights.

Severity & priority​

SeverityPrioritySuggested timeline
CriticalP0Immediate
HighP1Within 3 months
MediumP2Within 6 months
LowP3Within 12 months
InfoP4Monitor

The QRS report​

Every scan can be exported as a branded Quantum Risk Assessment PDF — cover, executive summary, score & signal breakdown, cryptographic inventory, sector guidance for the selected jurisdiction, and a prioritized remediation plan.

Quantum Risk Assessment report cover