You've worked through four full units. You understand the threat. You know the standards. You've built a CBOM, evaluated vendors, and completed a PKIMM self-assessment. Now comes the question every serious learner eventually asks:
"Can I get certified in this?"
The answer is yes, but it requires a careful distinction. The word "certified" means two different things in the PKIC ecosystem, and mixing them up will cause real confusion in professional conversations.
This lesson clears it up completely. By the end, you'll be able to explain the difference in plain language, to a colleague, to a hiring manager, or to a PKIC working group, without hesitation.
The PQCMM, Post-Quantum Cryptography Maturity Model, is a framework published by the PKI Consortium. Officially, it assesses the post-quantum readiness of products and services across six levels (0–5). This course also adapts those same levels as a personal learning scaffold, see the note in Lesson 0.4. The product-certification meaning is what this lesson covers; the learner-scaffold use is the course's own extension, not PKIC's definition.
The word "certified" in the PKIC ecosystem refers to this: a product, software, hardware, or a service, can be evaluated and formally certified as meeting PQCMM requirements at a specific maturity level. That certification belongs to the product, not to the person who built it or uses it.
A vendor submits a product, a hardware security module, a certificate authority platform, a cryptographic library, for formal assessment. If it meets PQCMM criteria, the product receives PKIC certification.
The PKIC certification program framework is published. As the program matures and more products are assessed, the registry will grow. Check current listings at pkic.org/wg/pqc/pqcmm/products/.
When you complete this course and pass the capstone, you earn a certificate that demonstrates your understanding of PQC migration, the PQCMM framework, and PKIMM knowledge requirements. This is your credential.
Important: Completing this course does not give you a PKIC product certification. It gives you a completion certificate that demonstrates fluency in the framework, which is genuinely valuable, and exactly what employers and PKIC working groups are looking for. Be precise about this distinction in your resume and conversations.
To understand what certification means in practice, you need a clear picture of the six PQCMM levels. Officially these levels describe a product or service. The ladder below uses the official PQCMM level names. The descriptions and organizational illustrations are this course's learner-scaffold framing (see Lesson 0.4), not PKIC's product-scope criteria. Click each level to see how this course frames that stage.
No awareness of the quantum threat. No inventory. No plan.
Knows the threat exists. No formal plan yet.
At least one quantum-safe algorithm in production. Partial inventory.
Full CBOM exists. Migration plan documented. Training underway.
Migration actively monitored. Metrics tracked. Governance formalized.
Fully migrated. Crypto-agile. Continuous improvement embedded.
When a product carries PKIC certification, it means the product has been formally evaluated against the PQCMM framework by a qualified assessor and confirmed to meet the criteria for a specific maturity level. This is a rigorous process, not a self-declaration.
The PKIC certification program framework is published. As the program matures and more products are assessed, the registry will grow. Check current listings at pkic.org/wg/pqc/pqcmm/products/.
Vendors who pursue PKIC certification for their products submit to one of three assurance routes. (Lesson 5.2 covers these in detail.) The highest assurance route involves an independent third-party assessor reviewing the product's cryptographic design, implementation, documentation, and test results against published PQCMM criteria.
Why this matters for you: When you're evaluating vendors, a skill you built in Unit 2, looking for PKIC certification is one of the strongest signals available that a product's PQC claims are not just marketing. A certified product has been assessed by someone other than the vendor. The PKIC certification program framework is published. As the program matures and more products are assessed, the registry will grow. Check current listings at pkic.org/wg/pqc/pqcmm/products/.
PKIC certification tells you that a product met the PQCMM criteria at a point in time. It does not mean the product is secure against all threats, that it is the right fit for your organization's specific architecture, or that it will remain certified indefinitely without renewal. Use it as one signal in your evaluation, a strong one, alongside FIPS validation status, your CBOM analysis, and your organization's specific migration timeline.
The certificate you earn by completing this course and passing the capstone is a personal completion credential. It demonstrates:
This makes your certificate directly relevant to PKIMM Knowledge and Training compliance evidence, which is precisely why the dual certificate architecture was designed the way it was. Your personal certificate serves the individual. The PKIMM-aligned compliance document serves the organization.
ITSM.40.001 milestones map onto PQCMM evidence. CCCS ITSM.40.001 section 3.1.3 requires departments to develop an education strategy for staff at all levels. Section 3.1.4 requires procurement policy updates: PQC requirements in contract clauses, CMVP-certified cryptographic modules, and cryptographic agility. Those artefacts map directly onto PQCMM level progression. An education strategy and vendor requirements are Level 2 evidence. Executed training records and procurement clauses in force are Level 3–4 evidence. The April 2026 departmental plan is a PQCMM-aligned artefact, not a parallel paperwork exercise. If you work in or with a Government of Canada department, the work in this course produces the evidence ITSM.40.001 asks for.
You've been building toward this. The certificate you're about to earn is a meaningful credential, not because the word "certified" appears on it, but because of what you had to demonstrate to get it. PKIC working group participants respect people who understand the framework deeply, and your course certificate shows you've done that work.
One practical move: when you join PKIC as a member and introduce yourself in a working group, you can reference this course directly. Say you've completed a PQCMM-aligned course covering Levels 0–5 and produced a PKIMM evidence package. That framing is accurate, concrete, and immediately credible to practitioners who understand the framework. It's the right vocabulary for the right audience.
Here's what the PKIC certification distinction means for your vendor conversations: when a vendor tells you their product is "quantum-safe" or "PQC-compliant," you now have a specific follow-up question: Has this product been formally assessed for PKIC certification, or are you self-declaring?
Self-declaration is not worthless, Lesson 5.2 explains why, but it carries different weight than third-party assessment. As an SMB, you probably don't need your own organization to pursue PKIC certification. But you should require your critical infrastructure vendors to demonstrate where on the PQCMM scale their products sit, and how they got there.
For your organization's PKIMM assessment, the personal completion certificate you earn here directly supports the Knowledge and Training evidence package. Enrollment records plus quiz scores plus capstone completion creates an auditable trail showing that responsible personnel received training, which is a weighted requirement in the PKIMM model.
If your organization is targeting Level 3 or Level 4 in a formal PKIMM assessment, the PKIMM-aligned compliance certificate produced by your capstone is designed to be submitted as direct compliance evidence. You're not just learning the framework, you're producing the documentation that demonstrates you've internalized it.
Every term below comes from the PKIMM and PQCMM glossary. These are the words to use in professional conversations.