Preparation for the Post-Quantum Certified Validator Exam
A PQC migration is only as good as its verification. Every algorithm swap, every hybrid implementation, every protocol upgrade must be tested, validated, and confirmed before it can be trusted in production. The gap between “deployed” and “verified” is where migrations fail silently, a misconfigured fallback that allows classical-only connections, a hybrid implementation that negotiates correctly in the lab but breaks under production load, a certificate chain that validates in one client but not another.
PQCV Validator Training develops the testing, verification, and validation competencies needed to ensure PQC implementations actually work as designed. This is not just quality assurance in the conventional sense. PQC verification requires understanding the cryptographic properties being tested, the adversarial conditions that reveal implementation flaws, and the compliance evidence that auditors, regulators, and insurers will demand.
Why This Certification Exists
PQC migration creates a verification challenge that most organizations are not equipped to handle. Traditional security testing validates whether systems are configured correctly. PQC verification must additionally confirm that cryptographic transitions are complete (no legacy algorithm fallbacks remain active), that hybrid implementations behave correctly under adversarial conditions (not just normal traffic), that implementations from different vendors and platforms interoperate, and that the evidence trail meets audit and regulatory requirements.
Without dedicated verification competence, organizations face two risks: deploying PQC implementations that contain exploitable weaknesses, and being unable to demonstrate compliance to regulators, auditors, insurers, and clients. The PQCV certification addresses both.
Course Outline
Module 1. PQC Test Strategy Design
Designing a verification program that covers the full scope of PQC migration. Defining what “verified” means for different system types and risk levels. Test strategy frameworks that map verification activities to migration phases. Determining test scope, coverage criteria, and resource requirements. The relationship between verification and the governance requirements of the broader migration program. Building a test strategy that satisfies technical validation needs, compliance requirements, and audit expectations simultaneously.
Module 2. Functional and Correctness Testing
Verifying that PQC algorithm implementations produce correct results. Testing key generation, encapsulation/decapsulation (for ML-KEM), and signing/verification (for ML-DSA, SLH-DSA, FN-DSA). Validating parameter selection and security level configuration. Testing cryptographic operations under boundary conditions, high load, and resource constraints. Verifying that implementations conform to NIST standards (not just “use a post-quantum algorithm” but “use ML-KEM-768 with the exact parameters specified in FIPS 203”).
Module 3. Downgrade Attack Testing and Negative Testing
The most critical verification activity in PQC migration. Downgrade testing: can an attacker force a connection to fall back to a classical-only algorithm? Rollback testing: if a hybrid implementation is deployed, can it be made to negotiate without the post-quantum component? Negative testing: once a system is designated as “post-quantum only,” does it actually refuse connections using legacy algorithms? The test scenarios, tools, and methodology for adversarial verification: man-in-the-middle simulation, algorithm stripping attacks, and protocol confusion testing.
Module 4. Interoperability Testing
PQC migration involves components from multiple vendors, and interoperability is not guaranteed even when all claim PQC support. Cross-vendor testing: do implementations from different libraries produce compatible outputs? Cross-platform validation: does a certificate chain created with one implementation validate on another? Certificate chain verification with post-quantum certificates: handling the larger signature sizes and their impact on chain validation. Testing with different TLS libraries, HSM firmware versions, and client implementations. Structured approaches to interoperability regression testing during the transition period.
Module 5. Performance Validation
PQC algorithms have different performance characteristics from their classical predecessors. Key generation, encapsulation/decapsulation, and signing/verification are generally slower. Key and signature sizes are larger, affecting bandwidth and storage. Benchmarking methodology: establishing baseline performance, measuring PQC overhead, testing under production-representative load, and defining acceptable performance thresholds. Handshake latency measurements for PQC-enabled TLS. The difference between lab benchmarks and production performance. Identifying performance bottlenecks that require architectural changes versus those that are within acceptable overhead.
Module 6. Security Validation
Beyond functional correctness and performance: testing implementation security. Verifying that deprecated algorithms are properly rejected. Testing key management procedures for PQC keys. Validating random number generation quality (PQC algorithms depend on high-quality randomness). Assessing implementation resistance to known side-channel attack patterns. Verifying that cryptographic libraries are up to date and patched. Security validation checklists for each NIST standardized algorithm.
Module 7. Evidence, Compliance, and Sign-Off
Producing verification evidence that withstands audit scrutiny. Structuring test results as evidence dossiers that map to specific compliance requirements (ISO 27001, SOC 2, PCI DSS, CMMC, FedRAMP, DORA, NIS2). The difference between testing documentation (what you did) and evidence documentation (what it proves). Migration sign-off processes: who has authority to accept migration results, what evidence they need to make that decision, and how to handle conditional acceptance. Ongoing validation requirements: migration verification is not a one-time event but an ongoing assurance function.
Format and Delivery
This program is available online on-demand, live online, in person, and as private team training; current prices for each format are in the booking section below. Live online and in-person sessions include 180 days of access to the online on-demand course. Where that course is not yet published, the 180 days start on the day it is. Training format and exam format are independent: however you train, the exam is delivered as a proctored assessment, under arrangements confirmed when you book.
Live online and in-person sessions run 24 hours of instruction across four days, six hours of teaching each day within a seven and a half hour schedule that includes lunch and breaks. The online on-demand course covers the same material at a self-paced pace of roughly 40 hours.
Prerequisites
- Active PQCS – Post-Quantum Certified Specialist certification
What Comes Next
After completing this course, you are eligible to sit for the PQCV certification exam. Earn PQCM + PQCA and PQCV, and you are automatically awarded PQCX – Post-Quantum Certified Expert.
Pricing
| Option | Price |
|---|---|
| Online (self-paced) | US$2,499 |
| Live online (instructor-led) | US$2,999 |
| In-person (instructor-led) | US$3,499 |
| Online training + PQCV exam bundle | US$2,999 |
| In-person training + PQCV exam bundle | US$3,999 |
All prices are in US dollars.
Who this course is for
Security testers, penetration testers, QA engineers, compliance auditors, security consultants, and technical assessors who will be responsible for verifying PQC implementations. This course is also appropriate for security architects and engineers who need to define validation criteria and acceptance tests for PQC migration programs.
What you’ll be able to do afterward
- Design test strategies for PQC implementations covering functional correctness, security properties, performance, and interoperability
- Test hybrid key exchange and hybrid signature implementations for correct behavior under normal and adversarial conditions
- Conduct downgrade attack testing to verify that fallback to classical-only algorithms is prevented where policy requires it
- Validate PQC certificate chains across multiple client implementations and platforms
- Perform interoperability testing between PQC implementations from different vendors and libraries
- Benchmark PQC implementation performance against defined thresholds and service-level requirements
What you leave with
You leave with the course handbook, a PDF of the full material with the instructor notes written out in place of the slides’ bullet points, and a PDF copy of Quantum Ready, included at no extra cost. The handbook is yours to keep. For most organizations, that shared reference is the clearest return on a training budget.
Enrollment includes 180 days of access to the online on-demand course. Where that course is not yet published, the 180 days start on the day it is.
Where this course fits
An active PQCS certification is required before this training. The path runs Foundation, then PQCS, then here. PQC Vendor Governance extends validation outward to suppliers, and PQC for GRC connects it to the assurance and audit side.
Why we teach this
The course is built on the Applied Quantum PQC Migration Framework, published openly under Creative Commons at pqcframework.org and written by the practitioners who teach here. The people who teach this course are running migration programs inside organizations now, and the course covers what those programs hit.
Certificate of Completion
Upon completion, you will receive a Quantum Academy certificate of completion. This is not a professional certification.
About this program
Quantum Academy credentials are private professional credentials issued by Quantum Academy, a trade name of Post-Quantum Institute. They are not government-issued licenses, accredited degrees, or academic credit, and earning one does not guarantee employment, promotion, regulatory approval, or any other specific outcome.
Quantum Academy programs are educational and informational only, and are not legal, compliance, or engineering advice.