Manage the Dependencies You Do Not Control
Most organizations depend on vendors for the majority of their cryptographic functionality, and a PQC migration is only as fast as its slowest critical vendor. This course addresses the vendor dependency problem directly: how to assess vendor PQC readiness, what contractual language to use, how to tier vendors by criticality, and what bridge patterns exist for when a critical vendor’s timeline slips. The “62% problem” — the majority of organizations that expect vendors to handle PQC for them — is why this competency matters.
Who Should Take This Course
Vendor managers, procurement professionals, supply chain security specialists, third-party risk managers, and security architects managing cryptographic dependencies.
What You Will Learn
This course provides hands-on technical depth in a specific dimension of PQC migration, aligned with the PQC Migration Framework. You will gain practical, applicable skills you can use immediately in migration work.
Course Outline
Module 1 — The Vendor Dependency Problem
Why vendor dependencies are the binding constraint in most migrations. Mapping cryptographic dependencies across the supply chain. The “62% problem”: the gap between expecting vendors to handle PQC and verifying that they will. Software supply chain and the role of SBOM/CBOM.
Module 2 — Assessing Vendor Readiness
Structured assessment of vendor PQC plans. Questions that reveal genuine readiness versus marketing. Evaluating vendor roadmaps and timeline credibility. Technical validation of vendor PQC claims. Building a vendor readiness scoring model.
Module 3 — Contractual and Procurement Mechanisms
Contractual language for cryptographic migration obligations. Requirements for new contracts and amendments to existing agreements. Procurement criteria for PQC readiness. Service-level agreements for cryptographic transition. Managing the legal and commercial dimensions of vendor PQC requirements.
Module 4 — Criticality Tiering and Bridge Patterns
Tiering vendors by criticality and migration impact. Bridge patterns for when a critical vendor’s timeline slips: gateway-based protection, compensating controls, and contingency planning. Managing the residual risk of vendor dependencies that cannot migrate on schedule.
Format and Delivery
Online (self-paced) — US$499. Approximately 4 hours. 90-day access.
Live online (instructor-led) — US$499. Scheduled sessions.
Corporate delivery — Custom in-person or online delivery for teams. Contact training@quantumacademy.com.
Prerequisites
A working understanding of PQC fundamentals is recommended. Consider Post-Quantum Foundation or PQCS certification for background. Some courses assume security engineering experience.
Certificate of Completion
Upon completion, you will receive a Quantum Academy certificate of completion. CPE credits earned may apply toward Quantum Academy certification maintenance.
Pricing
| Option | Price |
|---|---|
| Online (self-paced) | US$499 |
| Live online (instructor-led) | US$499 |
All prices are in US dollars.