Quantum Academy begins operations on August 15, 2026. Enrollment opens soon.
Skip to content

Courses

Post-Quantum Certified Validator (PQCV) Training

Preparation for the Post-Quantum Certified Validator Exam

A PQC migration is only as good as its verification. Every algorithm swap, every hybrid implementation, every protocol upgrade must be tested, validated, and confirmed before it can be trusted in production. The gap between “deployed” and “verified” is where migrations fail silently — a misconfigured fallback that allows classical-only connections, a hybrid implementation that negotiates correctly in the lab but breaks under production load, a certificate chain that validates in one client but not another.

PQCV Validator Training develops the testing, verification, and validation competencies needed to ensure PQC implementations actually work as designed. This is not just quality assurance in the conventional sense. PQC verification requires understanding the cryptographic properties being tested, the adversarial conditions that reveal implementation flaws, and the compliance evidence that auditors, regulators, and insurers will demand.

Why This Certification Exists

PQC migration creates a verification challenge that most organizations are not equipped to handle. Traditional security testing validates whether systems are configured correctly. PQC verification must additionally confirm that cryptographic transitions are complete (no legacy algorithm fallbacks remain active), that hybrid implementations behave correctly under adversarial conditions (not just normal traffic), that interoperability holds across vendors and platforms, and that the evidence trail meets audit and regulatory requirements.

Without dedicated verification competence, organizations face two risks: deploying PQC implementations that contain exploitable weaknesses, and being unable to demonstrate compliance to regulators, auditors, insurers, and clients. The PQCV certification addresses both.

Who Should Take This Course

This course serves a broader audience than traditional security testing roles:

  • Security testers and penetration testers who will conduct technical validation of PQC implementations, including downgrade attack testing and hybrid behavior verification
  • QA engineers who need to design test strategies for cryptographic transitions that go beyond functional testing
  • Compliance auditors and internal audit teams who must verify that PQC migration programs meet regulatory and governance requirements and produce audit-ready evidence
  • External assessors and certification bodies who evaluate organizations’ PQC migration status for clients, regulators, or insurance underwriters
  • Procurement and vendor management professionals who need to verify vendor claims about PQC readiness and validate that supplier implementations meet contractual cryptographic requirements
  • Insurance underwriters and cyber risk assessors who evaluate PQC migration status as part of cyber insurance questionnaires and risk assessments
  • Security architects and engineers who need to define validation criteria and acceptance tests for migration programs they design
  • GRC professionals who must map PQC verification evidence to compliance frameworks and produce documentation for regulatory review

You should take this course if you need to answer any of these questions with evidence: Has this implementation been migrated correctly? Does the hybrid deployment behave as designed under adversarial conditions? Can we prove to an auditor that our migration is complete? Does this vendor’s PQC claim hold up under technical scrutiny?

What You Will Learn

After completing this course, you will be able to:

  • Design comprehensive test strategies for PQC implementations that cover functional correctness, security properties, interoperability, and performance
  • Test hybrid implementations for correct behavior under both normal conditions and adversarial scenarios (including downgrade attacks, rollback attempts, and algorithm confusion)
  • Conduct negative testing: verify that legacy algorithms are refused where policy requires refusal, and that fallback mechanisms cannot be exploited
  • Validate PQC certificate chains across vendors and platforms, identifying interoperability failures before they reach production
  • Benchmark PQC implementation performance against defined service-level thresholds, distinguishing acceptable overhead from deployment-blocking degradation
  • Produce verification evidence dossiers that satisfy audit requirements, regulatory expectations, and insurance assessments
  • Define migration acceptance criteria and execute sign-off processes that give stakeholders justified confidence
  • Evaluate vendor PQC claims through structured technical testing rather than relying on self-attestation

Course Outline

Module 1 — PQC Test Strategy Design

Designing a verification program that covers the full scope of PQC migration. Defining what “verified” means for different system types and risk levels. Test strategy frameworks that map verification activities to migration phases. Determining test scope, coverage criteria, and resource requirements. The relationship between verification and the governance requirements of the broader migration program. Building a test strategy that satisfies technical validation needs, compliance requirements, and audit expectations simultaneously.

Module 2 — Functional and Correctness Testing

Verifying that PQC algorithm implementations produce correct results. Testing key generation, encapsulation/decapsulation (for ML-KEM), and signing/verification (for ML-DSA, SLH-DSA, FN-DSA). Validating parameter selection and security level configuration. Testing cryptographic operations under boundary conditions, high load, and resource constraints. Verifying that implementations conform to NIST standards (not just “use a post-quantum algorithm” but “use ML-KEM-768 with the exact parameters specified in FIPS 203”).

Module 3 — Downgrade Attack Testing and Negative Testing

The most critical verification activity in PQC migration. Downgrade testing: can an attacker force a connection to fall back to a classical-only algorithm? Rollback testing: if a hybrid implementation is deployed, can it be made to negotiate without the post-quantum component? Negative testing: once a system is designated as “post-quantum only,” does it actually refuse connections using legacy algorithms? This module covers the test scenarios, tools, and methodology for adversarial verification, including man-in-the-middle simulation, algorithm stripping attacks, and protocol confusion testing.

Module 4 — Interoperability Testing

PQC migration involves components from multiple vendors, and interoperability is not guaranteed even when all claim PQC support. Cross-vendor testing: do implementations from different libraries produce compatible outputs? Cross-platform validation: does a certificate chain created with one implementation validate on another? Certificate chain verification with post-quantum certificates: handling the larger signature sizes and their impact on chain validation. Testing with different TLS libraries, HSM firmware versions, and client implementations. Structured approaches to interoperability regression testing during the transition period.

Module 5 — Performance Validation

PQC algorithms have different performance characteristics from their classical predecessors. Key generation, encapsulation/decapsulation, and signing/verification are generally slower. Key and signature sizes are larger, affecting bandwidth and storage. This module covers benchmarking methodology: establishing baseline performance, measuring PQC overhead, testing under production-representative load, and defining acceptable performance thresholds. Handshake latency measurements for PQC-enabled TLS. The difference between lab benchmarks and production performance. Identifying performance bottlenecks that require architectural changes versus those that are within acceptable overhead.

Module 6 — Security Validation

Beyond functional correctness and performance: testing implementation security. Verifying that deprecated algorithms are properly rejected. Testing key management procedures for PQC keys. Validating random number generation quality (PQC algorithms depend on high-quality randomness). Assessing implementation resistance to known side-channel attack patterns. Verifying that cryptographic libraries are up to date and patched. Security validation checklists for each NIST standardized algorithm.

Module 7 — Evidence, Compliance, and Sign-Off

Producing verification evidence that withstands audit scrutiny. Structuring test results as evidence dossiers that map to specific compliance requirements (ISO 27001, SOC 2, PCI DSS, CMMC, FedRAMP, DORA, NIS2). The difference between testing documentation (what you did) and evidence documentation (what it proves). Migration sign-off processes: who has authority to accept migration results, what evidence they need to make that decision, and how to handle conditional acceptance. Ongoing validation requirements: migration verification is not a one-time event but an ongoing assurance function.

Format and Delivery

Online (self-paced) — US$2,499. Approximately 40 hours including hands-on testing exercises. 180-day access.

Live online (instructor-led) — US$2,499. Multi-day sessions with live testing scenarios and group exercises.

In-person (instructor-led) — US$3,499. Multi-day at scheduled locations. Small-group format with dedicated lab environments.

Corporate delivery — Custom training for organizational teams of 10+. Contact training@quantumacademy.com.

Prerequisites

What Comes Next

After completing this course, you are eligible to sit for the PQCV certification exam. Earn PQCM + PQCA + PQCV → automatically awarded PQCX — Post-Quantum Certified Expert.

Pricing

OptionPrice
Online (self-paced)US$2,499
In-person (instructor-led)US$3,499
Online training + PQCV exam bundleUS$2,999
In-person training + PQCV exam bundleUS$3,999

All prices are in US dollars.