Unit 2 deliverable
Vendor Evaluation Worksheet
PQC claim assessment — fictional vendor exercise
15–20 minutes PQCMM Level 1 → 2 Reusable with real vendors

Section 1 of 4
The vendor's product page — read carefully
Read the fictional product page below as if you encountered it in a real procurement process. Your job is to evaluate the PQC claims it makes. Take notes as you read, you will need them for Sections 2 through 4.
Enterprise cryptographic infrastructure, reimagined
Products
Solutions
Compliance
About
CipherVault TLS Gateway 4.2: Quantum-Ready Edition
CipherVault TLS Gateway 4.2 is our flagship enterprise TLS termination and inspection platform, now featuring our industry-leading post-quantum security architecture. Trusted by over 2,000 enterprises worldwide, CipherVault is the quantum-safe choice for organizations preparing for the post-quantum future.
✓ Quantum-Safe Certified NIST Post-Quantum Ready FIPS 140-3 Compliant ✓ Zero-Trust Architecture
Post-Quantum Security Features
CipherVault TLS Gateway 4.2 incorporates our proprietary QuantumArmor™ encryption engine, delivering comprehensive protection against both classical and quantum threats. Our engineering team has implemented post-quantum algorithms aligned with NIST's post-quantum cryptography initiative, ensuring your organization is prepared for the quantum era.

Key post-quantum capabilities:
Quantum-safe key exchange — QuantumArmor™ protects all TLS session establishment against future quantum attacks
Post-quantum certificate support — Full support for next-generation certificate formats as standards evolve
Hybrid transition mode — Seamless classical/quantum hybrid operation during the migration window
Future-proof architecture — Designed to accommodate emerging NIST standards as they are published
Technical Specifications
TLS versions
TLS 1.2, TLS 1.3
Key exchange
ECDH P-256, X25519, RSA-2048/4096, QuantumArmor™ QKE
Cipher suites
TLS_AES_256_GCM_SHA384, TLS_CHACHA20_POLY1305_SHA256, legacy suites configurable
Certificate types
RSA, ECDSA, "post-quantum compatible" (roadmap)
Platform
Linux x86-64, VMware ESXi, AWS/Azure/GCP marketplace
Version
4.2.1 (released September 2024)
Compliance & Certifications
FIPS 140-3 Validated: CipherVault cryptographic module holds FIPS 140-3 validation (certificate available on request). Our implementation meets the highest federal standards for cryptographic security.

NIST Post-Quantum Alignment: CipherVault engineering team actively monitors the NIST Post-Quantum Cryptography project and implements standards as they are finalized. CipherVault 4.2 incorporates post-quantum enhancements aligned with NIST guidelines.

Independent Security Assessment: CipherVault TLS Gateway has been assessed by third-party security researchers confirming the robustness of our cryptographic implementation.
QuantumArmor™ is a registered trademark of CipherVault Security Inc. Post-quantum certificate support is planned for a future release. Hybrid mode availability dependent on ecosystem readiness. See product documentation for implementation details.

Section 2 of 4
FIPS validation status assessment
Evaluate the vendor's FIPS validation claims using what you learned in Lesson 2.1. The key question: is this a FIPS-validated implementation or an algorithm-compliant claim?
Question 2.1
What type of FIPS claim is CipherVault making? Select the most accurate description.
Question 2.2
The vendor mentions "FIPS 140-3 validation" and says the certificate is "available on request." They provide no certificate number. Explain in your own words why the absence of a certificate number is a significant red flag, and what you would do next.
Hint: Recall from Lesson 2.1 — CMVP certificates are publicly searchable at csrc.nist.gov. A vendor with a legitimate certificate has nothing to gain by withholding the number and everything to gain by providing it.
0 / ~120 words
Question 2.3
The technical specifications list "QuantumArmor™ QKE" as a key exchange option, alongside ECDH P-256 and X25519. What is the problem with this listing from a standards-compliance perspective?
Hint: Consider Lesson 2.1's discussion of proprietary algorithm names vs FIPS-specified algorithms. Also consider Lesson 2.3's red flag #3.
0 / ~100 words

Section 3 of 4
PQCMM level assessment
Based on the evidence in the product page, what PQCMM level does CipherVault TLS Gateway 4.2 appear to meet? Use the level definitions from Lesson 0.4 and your judgment from this unit.
Question 3.1
Select the PQCMM level you believe this product meets based on the evidence presented. Then explain your reasoning.
0 / ~150 words
Question 3.2
What specific evidence would this vendor need to provide to justify a PQCMM Level 2 assessment? List at least three concrete pieces of evidence that are currently absent from this product page.
Level 2 definition: at least one quantum-safe algorithm is available in production and meets relevant standards. "Relevant standards" means FIPS 203, 204, or 205, not a proprietary equivalent.
0 / ~120 words

Section 4 of 4
Three due diligence questions
Write the three most important questions you would ask CipherVault before purchasing or renewing a contract. Each question must be specific, reference a concrete technical standard or validation mechanism, and have a verifiable answer. Do not write generic questions, write the questions you would actually ask in a vendor meeting.
Question 1 of 3
0 / ~80 words: A strong question names a specific standard or validation mechanism and has a yes/no or specific verifiable answer.
Question 2 of 3
0 / ~80 words
Question 3 of 3
0 / ~80 words

Scorecard
Overall vendor PQC claim evaluation
Rate each criterion based on the evidence in the product page. This scorecard is the summary artifact, it is what you would present to a procurement team or CISO.
CipherVault TLS Gateway 4.2: PQC claim scorecard
Criterion
Rating
Your verdict
Algorithm specificity — FIPS 203/204/205 named
FIPS validation — CMVP certificate or verifiable submission
Platform coverage — specific OS/hardware validated
Migration timeline — specific dates and version numbers
Hybrid mode — classical + PQC simultaneously supported
Save to your course folder as your Unit 2 submission
Worksheet preview — Unit 2 deliverable
Unit 2 deliverable complete
You have evaluated a real-world-style vendor PQC claim using the frameworks from all six Unit 2 lessons. This worksheet is reusable, the same framework applies to any vendor you encounter in actual procurement. Copy it to your course folder as your Unit 2 submission.

Unit 3 is next: Inventory, CBOM, and Crypto-Agility. You will build the cryptographic bill of materials that makes this kind of vendor evaluation systematic and scalable across your entire environment.