QARS-NI.
One number, transparent maths.
QARS-NI — the Quantum-Aware Risk Score for Network Infrastructure — translates thousands of cryptographic findings into a single, defensible number for the board, the auditor, and the regulator.
Mosca's inequality, applied to every finding.
Dr. Michele Mosca's inequality is the quantum-readiness north star. It says your data is at risk if the time it must remain confidential, plus the time you need to migrate, exceeds the time until a cryptographically-relevant quantum computer arrives.
time to migrate / protect
data shelf-life
time to Q-Day
Each finding has three dials.
ResilQ assigns every finding three temporal coordinates plus a primitive class. The weighting function aggregates them into a per-asset and per-layer score, then rolls up into the estate-level QARS-NI.
- Quantum sensitivity — RSA, ECC, DH are quantum-vulnerable. AES-256, SHA-3 hold up.
- Data shelf-life — derived from asset tags or supplied per-asset by the customer.
- Migration cost — calibrated against the remediation tier (1, 2, or 3) for the finding.
- Exposure — internet-facing assets carry a multiplier; air-gapped a divisor.
Four bands. One language for everyone.
Active quantum-vulnerable primitives in production. Migration is overdue.
Significant exposure. Migration must start this fiscal year.
Hybrid posture in place. Targeted remediation needed.
Quantum-safe posture across all three layers. Maintenance mode.
QARS-NI is a published framework.
QARS-NI extends the original QARS scoring work from the Kaunas University of Technology Cybersecurity Competence Center for the network-infrastructure domain. Our methodology is publicly documented, peer-reviewed, and re-implementable — we believe a defensible score must be one you can verify, not one you must trust.
The scoring source for the Sovereign edition ships with the deployment, and every finding includes the full input vector that produced it.
- Mosca, M. — "Cybersecurity in an era with quantum computers: will we be ready?" (IEEE S&P, 2018)
- NIST — FIPS 203 (ML-KEM), FIPS 204 (ML-DSA), FIPS 205 (SLH-DSA) (2024)
- NSA / CNSS — CNSA 2.0 algorithm requirements (2022)
- ETSI — TR 103 619, "Migration strategies and recommendations to Quantum-Safe schemes" (2020)
- KTU KSKC — "Quantum-Adjusted Risk Scoring for network infrastructure" (MDPI, 2026)