Unit 1 · Lesson 1.7
15 minutes PQCMM 0 → 1 Ecosystem orientation

The PKIC ecosystem — who does what

You now have the vocabulary, the standards, the migration targets, and the timeline. The final lesson in Unit 1 maps the ecosystem, the organizations, bodies, and working groups whose decisions shape how PQC migration actually happens in practice. You need to know who these players are before you can engage with them or evaluate their output.
Unit 1 progress — final lesson
By the end of this lesson you will be able to

Part 1 — The PKI Consortium (PKIC)
The PKI Consortium is a voluntary, nonprofit, industry-led collaborative group of 390+ member organizations focused on advancing trustworthy PKI. It is the organization that produced both the PQCMM and the PKIMM, the two frameworks this course is built around. Understanding what PKIC is, and what it is not, is essential for reading its outputs accurately.
Glossary term #20
PKIC (PKI Consortium)
A voluntary, nonprofit, industry-led collaborative body of 390+ members, CAs, vendors, enterprises, governments, academics, focused on advancing trustworthy PKI and leading the industry's PQC migration. PKIC is not a regulatory body and cannot mandate compliance. It is an influence hub: it publishes frameworks (PQCMM, PKIMM), runs working groups, convenes industry, and produces reference documentation that regulators and standards bodies adopt. Membership is open.
The critical distinction: PKIC produces frameworks and guidance that regulators and standards bodies adopt and reference, but it does not enforce them. When a government agency or compliance framework cites the PKIMM or the PQCMM, it is because PKIC did the work of developing and publishing them. PKIC's power is convening and publication, not mandate.
PKIC operates through working groups. The PQC Working Group produced and maintains the PQCMM. The Training and Certification Working Group (TCWG) is a strong first group for a motivated learner and develops the PKI Reference Book and related training materials. Other active working groups cover certificate transparency, IoT, healthcare, and government PKI. Working group membership is open to all PKIC members and contributions are welcome.

Part 2 — The ecosystem map
The PQC migration ecosystem involves multiple types of organizations playing different roles. Select each player to understand what they do and why they matter to migration.

Part 3 — PKIMM and PQCMM: both from PKIC, different purposes
Two frameworks. Both from PKIC. Both referenced throughout this course. It is worth being precise about their relationship before the unit closes.
Learning scaffold for this course
PQCMM
Post-Quantum Cryptography Maturity Model. Six levels (0–5). Product- and service-focused. Officially assesses products and services in the supply chain. This course also uses those levels as a personal learning scaffold (see Lesson 0.4).
Produced by: PKIC PQC Working Group
Compliance evidence framework
PKIMM
PKI Maturity Model. Five levels, 16 categories. Organization PKI program-focused. CMMI-inspired. Produces auditable compliance evidence. The self-assessment in Unit 4 uses the PKIC's online PKIMM tool directly.
Produced by: PKIC · Used by: regulators, auditors, compliance teams
Glossary terms #9 and #10 (reinforced)
PKIMM & PQCMM
PKIMM: PKI Maturity Model. The PKI Consortium's CMMI-inspired framework for evaluating and improving PKI implementations across five maturity levels and 16 categories. Used to produce compliance evidence for auditors and regulators.

PQCMM: Post-Quantum Cryptography Maturity Model. A product- and service-focused framework from the PKI Consortium defining six levels (0–5) of PQC readiness for products and services. This course also uses those levels as a personal learning scaffold (see Lesson 0.4).

Part 4 — How to engage with the PKIC ecosystem
The PKIC ecosystem is not closed. Membership is open, working groups welcome contributors, and the reference materials are publicly available. For a learner completing this course, there are three concrete engagement paths.
Path 1 — Individual membership
Join PKIC as a member
Individual and organizational membership is open. Members get access to working group materials, can participate in drafting guidance documents, and receive early visibility into emerging standards. The capstone of this course includes PKIC membership as a recommended action step.
Path 2 — Working group participation
TCWG and PQC working groups
The PQC Working Group owns the PQCMM. The Training and Certification Working Group (TCWG) is a strong first group for a motivated learner. Contributing to TCWG discussions is high-value engagement: that group develops the PKI Reference Book and related training materials.
Path 3 — Reference materials
PKIC website and published resources
The PKIC website (pkic.org) hosts the PQCMM, PKIMM, conference talk recordings, and working group output. The reference book produced by TCWG is the primary expert-level resource for PQC migration practice. Unit 5 covers how to use these resources in your professional development.
Path 4 — PKIMM self-assessment
Use the PKIC online tool
The PKIMM self-assessment tool is publicly available at pkic.org. Unit 4 of this course walks you through completing a real PKIMM self-assessment. The output is a compliance-ready document you can submit as evidence in formal PKIMM assessments.

Part 5 — Unit 1 complete: the full glossary
You have reached the end of Unit 1. All 20 glossary terms from Appendix B of the course have now been introduced across Lessons 1.1 through 1.7. The Unit 1 assessment, a 20-term glossary quiz at 75% pass threshold, is the next step. Review the terms below before attempting the quiz.
Unit 1 lessons complete — 20 glossary terms introduced
All terms listed below were introduced across Lessons 1.1–1.7. The glossary quiz requires a written plain-language definition of each term in your own words. Use the definitions from this unit as your starting point, but write them in a way that makes sense to you.
1. Post-Quantum Cryptography (PQC) 2. FIPS 203 / ML-KEM 3. FIPS 204 / ML-DSA 4. FIPS 205 / SLH-DSA 5. Harvest Now Decrypt Later (HNDL) 6. Shor's Algorithm 7. Crypto-agility 8. CBOM 9. PKIMM 10. PQCMM 11. Hybrid Certificate 12. Certificate Authority (CA) 13. TLS 14. Key Encapsulation Mechanism (KEM) 15. Digital Signature 16. Lattice-Based Cryptography 17. Hash-Based Cryptography 18. Deprecation 19. Certificate Lifecycle Management (CLM) 20. PKIC

Comprehension check
Question 1 of 3
The PKI Consortium describes itself as a voluntary collaborative body, not a regulatory body. What does this mean in practice for its frameworks like the PQCMM and PKIMM?
Question 2 of 3
What is the CA/Browser Forum and what specific role does it play in the PQC migration of TLS certificates?
Question 3 of 3
Which organization is responsible for finalizing the cryptographic standards (FIPS 203, 204, 205) that underpin PQC migration?