Manage the Dependencies You Do Not Control
Most organizations depend on vendors for the majority of their cryptographic functionality, and a PQC migration is only as fast as its slowest critical vendor. This course addresses the vendor dependency problem directly: how to assess vendor PQC readiness, what contractual language to use, how to tier vendors by criticality, and what bridge patterns exist for when a critical vendor’s timeline slips. The “62% problem”, the 62% of executives who told the 2025 IBM Institute for Business Value and Cloud Security Alliance study that they expect vendors to handle the quantum-safe transition for them – is why this competency matters.
Course Outline
Module 1. The Vendor Dependency Problem
Why vendor dependencies are the binding constraint in most migrations. Mapping cryptographic dependencies across the supply chain. The “62% problem”: the gap between expecting vendors to handle PQC and verifying that they will. Software supply chain and the role of SBOM/CBOM.
Module 2. Assessing Vendor Readiness
Structured assessment of vendor PQC plans. Questions that reveal genuine readiness versus marketing. Evaluating vendor roadmaps and timeline credibility. Technical validation of vendor PQC claims. Building a vendor readiness scoring model.
Module 3. Contractual and Procurement Mechanisms
Contractual language for cryptographic migration obligations. Requirements for new contracts and amendments to existing agreements. Procurement criteria for PQC readiness. Service-level agreements for cryptographic transition. Managing the legal and commercial dimensions of vendor PQC requirements.
Module 4. Criticality Tiering and Bridge Patterns
Tiering vendors by criticality and migration impact. Bridge patterns for when a critical vendor’s timeline slips: gateway-based protection, compensating controls, and contingency planning. Managing the residual risk of vendor dependencies that cannot migrate on schedule.
Prerequisites
A working understanding of PQC fundamentals is recommended. Consider Post-Quantum Foundation or PQCS certification for background. Some courses assume security engineering experience.
Certificate of Completion
Upon completion, you will receive a Quantum Academy certificate of completion. CPE credits earned may apply toward Quantum Academy certification maintenance.
Who this course is for
Third-party risk managers, procurement and vendor management, security architects who set supplier requirements, and the GRC staff who verify them. Suppliers themselves get a clear view of what they will be asked.
If your concern is your own estate rather than your suppliers’, the discovery and migration courses come first.
What you’ll be able to do afterward
- Set post-quantum requirements for suppliers that can be verified rather than merely promised
- Read a vendor’s PQC roadmap critically and separate shipped capability from intent
- Map cryptographic dependencies across the supply chain, including the ones your vendors inherit
- Close the gap between expecting vendors to handle PQC and verifying that they are
- Build bridge plans for the critical vendor whose timeline slips
What you leave with
You leave with the course handbook, a PDF of the full material with the instructor notes written out in place of the slides’ bullet points, and a PDF copy of Quantum Ready, included at no extra cost. The handbook is yours to keep. For most organizations, that shared reference is the clearest return on a training budget.
Enrollment includes 180 days of access to the online on-demand course. Where that course is not yet published, the 180 days start on the day it is.
Where this course fits
Post-Quantum Foundation or PQCS Specialist Training give the grounding this course builds on. Neither is enforced. PQC for GRC for the assurance framing, and PQCV Validator Training for the credential.
Why we teach this
The course is built on the Applied Quantum PQC Migration Framework, published openly under Creative Commons at pqcframework.org and written by the practitioners who teach here. The people who teach this course are running migration programs inside organizations now, and the course covers what those programs hit.
About this program
Quantum Academy credentials are private professional credentials issued by Quantum Academy, a trade name of Post-Quantum Institute. They are not government-issued licenses, accredited degrees, or academic credit, and earning one does not guarantee employment, promotion, regulatory approval, or any other specific outcome.
Quantum Academy programs are educational and informational only, and are not legal, compliance, or engineering advice.