Quantum Academy begins operations on August 15, 2026. Enrollment opens soon.
Skip to content

Courses

PQC Vendor Governance and Supply Chain

Manage the Dependencies You Do Not Control

Most organizations depend on vendors for the majority of their cryptographic functionality, and a PQC migration is only as fast as its slowest critical vendor. This course addresses the vendor dependency problem directly: how to assess vendor PQC readiness, what contractual language to use, how to tier vendors by criticality, and what bridge patterns exist for when a critical vendor’s timeline slips. The “62% problem” — the majority of organizations that expect vendors to handle PQC for them — is why this competency matters.

Who Should Take This Course

Vendor managers, procurement professionals, supply chain security specialists, third-party risk managers, and security architects managing cryptographic dependencies.

What You Will Learn

This course provides hands-on technical depth in a specific dimension of PQC migration, aligned with the PQC Migration Framework. You will gain practical, applicable skills you can use immediately in migration work.

Course Outline

Module 1 — The Vendor Dependency Problem

Why vendor dependencies are the binding constraint in most migrations. Mapping cryptographic dependencies across the supply chain. The “62% problem”: the gap between expecting vendors to handle PQC and verifying that they will. Software supply chain and the role of SBOM/CBOM.

Module 2 — Assessing Vendor Readiness

Structured assessment of vendor PQC plans. Questions that reveal genuine readiness versus marketing. Evaluating vendor roadmaps and timeline credibility. Technical validation of vendor PQC claims. Building a vendor readiness scoring model.

Module 3 — Contractual and Procurement Mechanisms

Contractual language for cryptographic migration obligations. Requirements for new contracts and amendments to existing agreements. Procurement criteria for PQC readiness. Service-level agreements for cryptographic transition. Managing the legal and commercial dimensions of vendor PQC requirements.

Module 4 — Criticality Tiering and Bridge Patterns

Tiering vendors by criticality and migration impact. Bridge patterns for when a critical vendor’s timeline slips: gateway-based protection, compensating controls, and contingency planning. Managing the residual risk of vendor dependencies that cannot migrate on schedule.

Format and Delivery

Online (self-paced) — US$499. Approximately 4 hours. 90-day access.

Live online (instructor-led) — US$499. Scheduled sessions.

Corporate delivery — Custom in-person or online delivery for teams. Contact training@quantumacademy.com.

Prerequisites

A working understanding of PQC fundamentals is recommended. Consider Post-Quantum Foundation or PQCS certification for background. Some courses assume security engineering experience.

Certificate of Completion

Upon completion, you will receive a Quantum Academy certificate of completion. CPE credits earned may apply toward Quantum Academy certification maintenance.

Pricing

OptionPrice
Online (self-paced)US$499
Live online (instructor-led)US$499

All prices are in US dollars.