The core idea

Mosca's inequality, applied to every finding.

Dr. Michele Mosca's inequality is the quantum-readiness north star. It says your data is at risk if the time it must remain confidential, plus the time you need to migrate, exceeds the time until a cryptographically-relevant quantum computer arrives.

MOSCA INEQUALITY
tp + td > tq
tp
time to migrate / protect
td
data shelf-life
tq
time to Q-Day
How weighting works

Each finding has three dials.

ResilQ assigns every finding three temporal coordinates plus a primitive class. The weighting function aggregates them into a per-asset and per-layer score, then rolls up into the estate-level QARS-NI.

  • Quantum sensitivity — RSA, ECC, DH are quantum-vulnerable. AES-256, SHA-3 hold up.
  • Data shelf-life — derived from asset tags or supplied per-asset by the customer.
  • Migration cost — calibrated against the remediation tier (1, 2, or 3) for the finding.
  • Exposure — internet-facing assets carry a multiplier; air-gapped a divisor.
Score bands

Four bands. One language for everyone.

CRITICAL
0–30

Active quantum-vulnerable primitives in production. Migration is overdue.

HIGH
30–60

Significant exposure. Migration must start this fiscal year.

MODERATE
60–85

Hybrid posture in place. Targeted remediation needed.

READY
85–100

Quantum-safe posture across all three layers. Maintenance mode.

Research lineage

QARS-NI is a published framework.

QARS-NI extends the original QARS scoring work from the Kaunas University of Technology Cybersecurity Competence Center for the network-infrastructure domain. Our methodology is publicly documented, peer-reviewed, and re-implementable — we believe a defensible score must be one you can verify, not one you must trust.

The scoring source for the Sovereign edition ships with the deployment, and every finding includes the full input vector that produced it.

Reference reading
  • Mosca, M. — "Cybersecurity in an era with quantum computers: will we be ready?" (IEEE S&P, 2018)
  • NIST — FIPS 203 (ML-KEM), FIPS 204 (ML-DSA), FIPS 205 (SLH-DSA) (2024)
  • NSA / CNSS — CNSA 2.0 algorithm requirements (2022)
  • ETSI — TR 103 619, "Migration strategies and recommendations to Quantum-Safe schemes" (2020)
  • KTU KSKC — "Quantum-Adjusted Risk Scoring for network infrastructure" (MDPI, 2026)
Get started

Ready to see your score?

Free pilot · 25 assets · QARS-NI report in 72h.

Audit now View pricing