Vendor & Supply Chain / Vendor Scorecard Builder
§5.3What this is for: Create vendor assessment scorecards for PQC readiness evaluation.
What a good answer looks like: Scores backed by something the vendor published, not by what they said on a call. The migrate catalog carries the proof and its date.
Worked example: Score two HSM vendors on the same six criteria — PQC Algorithm Support, FIPS 140-3 Validation, Hybrid Mode Support, Crypto Agility, Published PQC Roadmap, SBOM/CBOM Delivery — and compare the totals, with the migrate catalog as the evidence for each score.
Runtime and privacy: This planning tool runs in your browser. Use synthetic or approved organizational data and review the site privacy terms before entering sensitive material.
For your role
- Executive / Business Leader
- Score each vendor on the six criteria, PQC Algorithm Support, FIPS 140-3 Validation, Published PQC Roadmap, Crypto Agility, SBOM/CBOM Delivery and Hybrid Mode Support: the weighted total ranks the vendors you depend on.
- GRC / Risk & Compliance
- Set each score with the migrate catalogue as evidence and fill the Observability Tooling Notes (crypto scanner, CVE feed, SIEM rules, zero-trust enforcement): the export is the vendor-assurance record.
Score your vendors across six PQC readiness dimensions. Use the sliders to set each score. Select your infrastructure in Step 1 for product-level scoring.
PQC Readiness — Portfolio average (across all products)
0
/100
How this is scored: each dimension score (0–100) is multiplied by its weight, then the six weighted scores are summed and divided by the total weight — a weighted average, not a plain average. For the two auto-detected dimensions (PQC Algorithm Support, FIPS 140-3 Validation), a product only counts toward the score once its reported readiness reaches the "hybrid or full" tier — roughly 70% of the way to fully deployed; planned, pilot, and narrative-only claims don't count.
Observability Tooling Notes (CSWP.39 §5.3)
Document which observability tooling this vendor relationship relies on. Educational — these notes export with the scorecard. Browse Cryptographic Discovery Platforms and SASE & Zero Trust for examples.
Vendor PQC Readiness — Export
Export the scorecard above as a shareable document. Includes observability tooling notes.
- /assess — compliance frameworks step— Step 5 captures policy + framework registry
- /compliance — framework explorer
- /leaders — stakeholder ecosystem
- /library — policy & governance docs
- NIST CSWP.39-upd1 — Considerations for Achieving Crypto Agility (Dec 2025, upd. Jun 2026)
- NIST IR 8547 — Transition to PQC Standards
- ENISA — Post-Quantum Cryptography Integration Study
- NIST Computer Security Resource Center (Americas)
- NIST News & Events (Americas)
- NSA Media Defense Portal (Americas)
- CISA Quantum Page (Americas)
- BSI Post-Quantum Cryptography (EMEA)
- ANSSI Cryptography Guidelines (EMEA)
Try it
Score two vendors on the six criteria. Which criterion carries the most weight?
Next step
Next in Vendor & Supply Chain: Contract Clause GeneratorContract Clause Generator is the next Vendor & Supply Chain tool in the Command Center.