Unit 0 · Lesson 0.4
20 minutes PQCMM pre-level 0

What a maturity model is and why PQCMM matters

The previous three lessons answered one question: should you care? The answer is yes. Now we need to answer a different question: how does this course work, and how will you know you're making progress? The answer is the PQCMM, the Post-Quantum Cryptography Maturity Model. It is the scaffold that gives this entire course its structure.
Unit 0 progress
A note on how this course uses PQCMM The PKI Consortium's PQCMM formally assesses the post-quantum readiness of products and services in the supply chain; it does not define an individual or organizational maturity scale. This course adapts the same six-level structure (0–5) as a personal learning scaffold, giving a learner with security or networking foundations a concrete way to locate their own understanding before they're ready to reason about product-level or organizational readiness. Where the course addresses organizational maturity, the PKIMM self-assessment in Unit 4, it uses PKIMM directly, as PKIC intends. This adaptation of PQCMM for individual learning progression is the course author's own extension, developed to solve a specific pedagogical gap, and is offered here as a candidate contribution to PKIC's Training and Certification Working Group should it prove useful.
By the end of this lesson you will be able to

Part 1 — What a maturity model is, and why this one matters
A maturity model is a framework that describes a progression from a starting state to an advanced state, organized into defined levels. Each level represents a meaningful, observable stage. You can locate yourself on the scale, understand what you currently have, and see what the next level requires.
The PQCMM was developed by the PKI Consortium and is designed for software and hardware products and services. This course additionally applies the same six levels to individual learners as its own adaptation (see the note above). It has six levels, numbered 0 through 5, using the official PQCMM names: None, Initial, Foundational, Advanced, Managed, and Optimized. In this course's learner scaffold, Level 0 (None) means no awareness or action. Level 5 (Optimized) means fully optimized, independently certified, and continuously improving.
This course uses the PQCMM levels as its unit structure. Each unit moves you, or your organization, from one level to the next. By the time you reach the capstone, you will have built real artifacts that demonstrate each transition.

Part 2 — The six levels
Level 0 — None

No PQC knowledge, planning, or action. Classical cryptography is in use with no awareness of migration requirements. This is the default state for any individual or organization that has not specifically engaged with PQC topics.

What this looks like: Classical algorithms only (RSA, ECC, AES). No PQC libraries. No migration planning. No awareness of NIST standards or deprecation timelines.

What moves you to the next level: Gain foundational awareness of what quantum computing is, why it threatens classical cryptography, and what the NIST standards are. Units 0 and 1 accomplish this.

Level 1 — Initial

PQC awareness exists. Some initial steps have been taken, perhaps evaluating libraries, reading NIST documentation, or identifying which systems need attention. No production deployment yet.

What this looks like: At least one team member has studied PQC. NIST standards are known. An initial asset list may exist. No quantum-safe algorithm has been deployed.

What moves you to the next level: Deploy at least one quantum-safe algorithm in a non-production or pilot environment and establish a migration plan with assigned owners.

Level 2 — Foundational

At least one quantum-safe algorithm is live in a production system meeting relevant standards. The organization has demonstrated it can deploy and operate post-quantum cryptography in a real environment.

What this looks like: A production system uses ML-KEM, ML-DSA, or SLH-DSA. The deployment meets FIPS validation or equivalent. Basic monitoring of the deployed system is in place.

What moves you to the next level: Expand deployment to additional systems. Begin full cryptographic inventory (CBOM) to identify all remaining RSA/ECC dependencies.

Level 3 — Advanced

A complete cryptographic bill of materials (CBOM) exists for the relevant scope. Every cryptographic dependency has been identified, documented, and assigned a migration priority.

What this looks like: CBOM covers all in-scope systems. Each asset is tagged with algorithm type, key size, certificate expiry, and migration priority. Ownership is assigned.

What moves you to the next level: Begin systematic migration according to the CBOM priority list. Track progress against the plan. Report to leadership on a defined schedule.

Level 4 — Managed

Migration is actively managed against a documented plan with governance, metrics, and executive visibility. The organization is executing, not just planning.

What this looks like: Migration dashboard exists. KPIs are tracked. Executive sponsor is named. Vendor assessments have been completed for critical third parties.

What moves you to the next level: Complete remaining migration items. Establish continuous monitoring for new cryptographic vulnerabilities. Prepare for external validation.

Level 5 — Optimized

Migration is complete. Post-quantum cryptography is embedded in standard operating procedures, vendor requirements, and audit frameworks. Continuous improvement is in place.

What this looks like: All RSA/ECC deprecated. PQC requirements in procurement contracts. Annual PQC audits scheduled. Organization contributes to standards bodies or industry working groups.

What moves you to the next level: Maintain and evolve. Engage with PKIC and NIST working groups. Prepare for algorithm agility as post-quantum standards evolve.


Part 3 — How the PQCMM maps to this course
Each unit corresponds to a PQCMM level transition. You are not just studying levels, you are building artifacts that demonstrate each one.
UnitPQCMM transitionPrimary output
Unit 0 — FoundationPre-level 0'Why I'm learning this' statement
Unit 1 — Awareness0 → 1Annotated glossary
Unit 2 — Production-ready1 → 2Vendor evaluation worksheet
Unit 3 — Inventory2 → 3CBOM for fictional org
Unit 4 — Managed migration3 → 4PKIMM self-assessment + checklists
Unit 5 — Optimized4 → 5Personal PQC readiness roadmap
CapstoneSynthesisFull PKIMM evidence package

Part 4 — PQCMM vs PKIMM, two related frameworks
You will encounter two frameworks throughout this course. It is worth being precise about what each one is for.
PQCMM
Post-Quantum Cryptography Maturity Model
Product- and service-focused framework for assessing PQC readiness of software and hardware. Six levels (0–5).

PKIC scope: products and services
Course adaptation: individual learners (see the note in this lesson)
PKIMM
PKI Maturity Model
A CMMI-inspired framework for assessing the maturity of an organization's entire PKI program across 16 categories and five levels. Compliance-focused. Produces auditable evidence artifacts.

Scope: organizational PKI programs
The two frameworks are complementary, not competing. Officially, the PQCMM tells you where a product or service is on the migration journey. This course also uses those six levels to locate a learner. The PKIMM tells you how mature an organization's PKI program is overall. Unit 4 is where you engage with the PKIMM directly, completing a real self-assessment using the PKIC's online tool.

Part 5 — Where most people are right now
The most useful thing you can do with a maturity model is locate yourself on it honestly. This is not a test, it is a starting point for tracking real movement over the course.
Most individual learners start at Level 0 by definition, not because they lack knowledge or motivation, but because this course's learner-scaffold definition of Level 0 is simply 'no PQC-specific knowledge or action yet.' A first security or networking baseline (Security+, SSCP, equivalent experience, or adjacent IT work) gives you the classical cryptography foundation. This course provides the migration-specific layer on top of it.
Most organizations, even large ones, sit between Level 1 and Level 2 today. Many government contractors and regulated industries are being pushed toward Level 3. Level 4 and above is rare and represents where the industry is heading over the next three to five years.
Persona notes
A
The motivated learner. Most career learners start at Level 0 on PQC specifically, a first security or networking baseline covers classical cryptography foundations but not migration. That is exactly the gap this course fills.
B
The SMB decision-maker. Most SMBs are at Level 0. Vendors haven't flagged it yet. No budget line exists for it. This is the normal starting point, and it is exactly where this course begins.
C
The IT professional. Many IT teams are at Level 0 or Level 1 even at large organizations, they're aware of the term 'quantum' but haven't mapped it to their specific systems. The CBOM work in Unit 3 is where that changes.

Comprehension check
Question 1 of 3
What does it mean for an organization to be at PQCMM Level 2?
Question 2 of 3
What is the primary difference between the PQCMM and the PKIMM?
Question 3 of 3
Why does this course use the PQCMM as its organizing scaffold rather than a traditional syllabus?