Quantum Academy begins operations on September 15, 2026. Enrollment opens soon.
Skip to content

Market Reality

What Vendors Do When You Ask Hard Questions

Marin Ivezic9 min read

12 minutes into a vendor call, you ask one question: which key-encapsulation algorithm does the product implement? Key encapsulation is the step that establishes a shared secret between two parties, and it is one of the public-key components a sufficiently powerful quantum computer would threaten, along with digital signatures. The answer runs 90 seconds. It mentions a defense ministry, a magazine cover, and two patent filings. It never names an algorithm.

You already have a finding. Not proof that the product is worthless, but a scoreable observation: a company that can name its algorithm names it in the first sentence.

Procurement teams have got much better at asking quantum vendors the right questions. Scoring the answers is where evaluations still stall, because a confident non-answer sounds a lot like an answer when you are outside your own technical depth. This guide is about reading the response.

The rule underneath all of this

A technical question gets a technical answer. When the answer is something else, the substitution is the data point, and it belongs in your evaluation notes alongside the missing certificate.

The rule works because these questions aren’t hard for a legitimate supplier. In August 2024, the National Institute of Standards and Technology (NIST) published Federal Information Processing Standards (FIPS) 203, 204, and 205, standardising ML-KEM (formerly CRYSTALS-Kyber) for key encapsulation, ML-DSA (formerly CRYSTALS-Dilithium) and SLH-DSA (formerly SPHINCS+) for digital signatures. A fourth signature scheme, FN-DSA, was still in draft at the time of writing. A vendor whose product is built on these standards names one and moves on. A vendor whose product is built on something else has to fill the silence with material of a different kind.

What follows are the four kinds of filler we see most often. None of them is proof of fraud on its own. All of them are recordable.

When the question becomes about you

The first family redirects attention from the product to the person asking.

Sometimes it is an accusation of bias: you’re asking because a large incumbent pays your firm, or because the industry wants to protect the status quo. Sometimes it is the appeal to suppressed genius, the claim that physics and cryptography operate as a closed guild that rejects revolutionary work to protect grant funding.

Scientific fields do resist new ideas, and history has examples of rejected work that turned out to be right. There is a difference, though, between a researcher who submits work, absorbs hostile review, and iterates, and a vendor who has submitted to nothing and calls the field corrupt when asked why. NIST’s post-quantum standardisation process opened in 2016 and ran for years of public cryptanalysis. Anyone could submit. Contributions came from universities, startups, and large companies alike. If a vendor holds a genuinely new quantum-safe algorithm, the route to credibility is public analysis, and refusing that route is a choice they should be asked to explain.

The third version is quieter and lands hardest on non-physicists. You just don’t understand the physics. It exploits the gap between security expertise and quantum mechanics, and it is designed to make you feel unqualified to keep asking.

Treat that one as a competence signal in reverse. In legitimate quantum technology, explaining a product to a technically literate non-specialist is basic professional practice. Anyone who cannot describe, in plain terms, what physical property their system relies on and what an attacker would have to defeat has not demonstrated depth. When a vendor cannot explain their product to you, the likeliest reason isn’t your ignorance.

When secrecy is offered as the answer

Companies do protect intellectual property, and some security work genuinely is classified. So the second family sounds reasonable: we can’t discuss that, for patent reasons, or NDA reasons, or national security reasons.

Draw the line in one place. Implementation details can be proprietary: optimised code paths, hardware acceleration, key management architecture. The choice of cryptographic algorithm never is. A cryptographic system should stay secure even when everything about it except the key is public. That is Kerckhoffs’s principle, published in 1883, and it has held for more than 140 years. A vendor claiming their algorithm must stay secret for the system to be secure is contradicting the foundation of the discipline they are selling into.

Classified programmes exist. A supplier pitching to commercial buyers while declining to name a cryptographic approach on national security grounds is doing something else.

The same family produces the private demonstration. We’ll show you under NDA. A demo proves that data goes in and comes out, which any classical encryption system also does. It cannot show resistance to a defined attack model, correctness of the underlying mathematics, or the absence of exploitable weakness. Those need security proofs and independent cryptanalysis. The useful counter-move is simple: offer to bring your own cryptographer. Confident engineering teams say yes.

When credibility is borrowed

The third family answers a question about the product with evidence about the company’s associations. Each of these has a legitimate version, and each has a hollow one.

Patents. A patent shows that paperwork met the formal requirements for filing. Examiners assess novelty and non-obviousness, not physical correctness or cryptographic security. Patent offices have accepted filings for perpetual motion machines. A patent is intellectual property protection, and it says nothing about efficacy.

Awards and magazine covers. Recognised bodies such as IEEE, the American Physical Society, the Institute of Physics or the European Physical Society publish their criteria, their committees, and their past winners. Alongside them runs a paid tier of “innovator to watch” lists and cover features where the editorial process consists of an invoice. Trade show “best of show” programmes often work the same way, with exhibitors applying and few being turned down. The test: would a practitioner in the field recognise the awarding body, and can you find the decision on its own public record?

Journals and pre-prints. Peer review is the strongest signal in this group and the easiest to counterfeit. Predatory journals sell publication; a smaller number are built by a group specifically to validate that group’s own claims, with the authors’ colleagues on the editorial board. The result is a closed loop that produces citations without scrutiny. Check three things: whether the journal is indexed in Web of Science or Scopus and absent from predatory-journal registries such as Cabells Predatory Reports, whether the authors publish elsewhere in recognised venues, and whether anyone outside their circle has cited the work. Think. Check. Submit. is a practical checklist for unfamiliar titles. For pre-prints, meaning papers posted before peer review, arXiv is the standard in physics and computer science and requires an endorsement from an established author before a newcomer can post. Servers without that filter accept anything. When a paper exists only on a no-filter server, ask why it isn’t on arXiv, and listen to whether the answer is about gatekeeping.

Partnerships. Buying a cloud provider’s compute does not make you their strategic partner. Being listed on a marketplace is not an endorsement by the marketplace. A vendor case study published by a large platform describes how a customer used that platform, written largely from information the customer supplied. Ask whether the partnership announcement exists on both websites, and whether the larger party has ever described the relationship in its own words.

Funding and accelerators. Later-stage investment from a firm with technical advisors carries some signal. Early-stage cheques carry much less, because seed investors are backing teams and markets and expect most of the portfolio to fail. At any stage, diligence examines the business case rather than the cryptography; investors rarely commission independent cryptanalysis. Accelerators and innovation centres vary just as widely, from highly selective programmes to memberships available to anyone who pays. Ask what the relationship actually is: a technology licence, a named research collaboration, a co-development agreement, or a desk and a mentor.

Credentials and speaking slots. Verify the institution, the field, and the publication record rather than the title. A doctorate in an unrelated discipline, presented as quantum expertise, is a different credential from a physics PhD with a paper trail. Conference talks split the same way: presentations at peer-reviewed venues are competitively selected, while many industry events include speaking slots in sponsorship packages. Check whether the event publishes a programme committee and a review process.

Testimonials. Satisfaction scores and customer quotes are marketing outputs. A serious vendor will have both testimonials and specifications. When the social proof is carrying the whole pitch, the specifications are missing for a reason.

When the topic changes

The fourth family is the hardest to catch in the moment, because each individual answer sounds cooperative. You ask about the algorithm and hear about energy efficiency. You ask about the security proof and hear about deployment speed. You ask about NIST standardisation and hear about 25 years of experience.

Any one of those answers would be fine in a different conversation. The pattern is what you record. Set yourself a timer: 15 minutes into the call, have you received a direct answer to your first question? If the honest answer is no, the evasion is deliberate and it is intended to outlast your patience.

What a real answer sounds like

For contrast, here is the shape of the responses we hear from teams building genuine post-quantum products.

They name the algorithms and the parameter sets, with the FIPS numbers attached. They state limitations without being pushed: a quantum key distribution (QKD) supplier will tell you the maximum range of a link and explain that going further requires trusted nodes, which reintroduces a classical security assumption at each relay. They point to evidence you can pull yourself, including a NIST submission package or a validated module certificate number. They invite your cryptographer into the room. And when their marketing does use simplified language, the substance appears the moment you scratch it, in the form of a named handshake, a named signature scheme, and a named standard.

Writing this into the procurement file

Reading the answers is a skill, and it survives contact with an evaluation committee only when it is written down. Three practices help.

Score the response, not only the claim. Add a column to your vendor matrix that records what kind of answer each technical question received: direct, partial, redirected, refused. Patterns across 10 questions carry more weight in a committee than any single exchange, and they give a non-technical approver something concrete to read.

Require artifacts with identifiers. A claim becomes verifiable when it comes with something you can look up without the vendor’s help. Useful examples: a module certificate number from NIST’s Cryptographic Module Validation Program, a NIST post-quantum submission package, an arXiv identifier, a joint announcement on the partner’s own domain, a public contract award notice, a conference programme committee. Ask for the identifier in the RFP itself, so the burden sits with the supplier before the call.

Keep one question in reserve for every shortlisted vendor. Which specific NIST-standardised algorithm does your product implement, and do you have a FIPS 140-3 validated module? A serious supplier answers in a sentence. Everyone else answers with everything except the answer.

Building the judgment behind the checklist

None of this requires you to become a cryptographer. It requires enough working knowledge of the standards, the validation regime, and the physics claims to know what a good answer looks like before you hear one. That knowledge is teachable, and we teach it as an assessable competence rather than a reading list.

Quantum Academy’s programs cover post-quantum standards, migration planning, and vendor assurance for the professionals who sit on the buying side of these conversations. You can review the current certification paths at quantumacademy.com/.

For the migration methodology that turns vendor selection into a sequenced program of work, see pqcframework.org. For deeper technical background on the marketing terminology behind these claims, the Quantum Snake Oil Dictionary at PostQuantum.com is the companion reading.