Lesson 5.1 established a critical distinction: PKIC product certification belongs to products, not people. Now we go one level deeper. Not all PKIC certification is the same, and the difference matters enormously when you're evaluating a vendor, advising an organization, or participating in a PKIC working group conversation.
The question is not just "Is this product certified?" The question is: "By what process was that certification achieved?"
The key insight of this lesson: Three distinct assurance routes exist. Each produces a different type of claim, carries a different level of credibility, and is appropriate for a different organizational context. Knowing which route applies, and being able to ask for it by name, is what separates a practitioner from someone who just knows the terminology.
Select each route to explore what it involves, what it produces, and when it's appropriate.
In a self-assessment, the organization (or vendor) evaluates its own product or migration status against the published PQCMM criteria. No external reviewer is involved. The organization reviews the criteria, collects internal evidence, scores each criterion, and declares its maturity level.
Self-assessment is the entry-level route. It is not meaningless, the PQCMM criteria are publicly defined and specific, so a conscientious self-assessment requires real internal examination. But the result is a self-declared claim, and buyers or assessors should weigh it accordingly.
Practical use: The PKIMM self-assessment you completed in Unit 4 is an example of this route applied to your own organization. That score is self-declared, which is why your written interpretation and supporting evidence matter. They transform the number into a credible artifact.
In a third-party assessment, an independent qualified assessor, someone with no financial interest in the outcome, reviews the product or organizational program against PQCMM criteria. The assessor examines documentation, interviews relevant personnel, reviews cryptographic design and implementation, and produces a formal assessment report.
The third-party route provides independent corroboration. The assessor's report carries weight that a self-declaration cannot, because the reviewer has no incentive to inflate the score. This is the route most enterprise procurement teams will require before accepting a vendor's PQC claims for high-sensitivity deployments.
What to look for: When a vendor offers a third-party assessment report, ask who conducted it. Look for assessors with verifiable PKI and cryptographic expertise, not just generic IT audit credentials. The assessor's independence and competence are both relevant.
PKIC certification is the highest assurance route. It follows the third-party assessment process but with a critical addition: the assessment is conducted by a PKIC-approved assessor using PKIC-administered criteria, and the resulting certification is formally issued by the PKI Consortium and logged in the PKIC certified products registry.
This is what it means when a product page says "PKIC certified." The certification is traceable, you can verify it against the published registry. It has a scope (which PQCMM level and which assessment criteria), a date, and a renewal requirement. It is the only route that produces a certification verifiable through a third-party database.
The PKIC certification program framework is published. As the program matures and more products are assessed, the registry will grow. Check current listings at pkic.org/wg/pqc/pqcmm/products/.
How to verify: If a vendor claims PKIC certification, ask for the product name as it appears in the PKIC registry and the certification date. The PKIC certification program framework is published. As the program matures and more products are assessed, the registry will grow. Check current listings at pkic.org/wg/pqc/pqcmm/products/. Once a product is listed, certification that cannot be verified in the registry is not PKIC certification. It may be a third-party assessment result being labeled incorrectly, which is a meaningful distinction.
This table covers the key dimensions of each route. Use it as a reference when evaluating vendor claims or advising on certification strategy.
The PKIC certification program framework is published. As the program matures and more products are assessed, the registry will grow. Check current listings at pkic.org/wg/pqc/pqcmm/products/.
| Dimension | Self-Assessment | Third-Party | PKIC Certified |
|---|---|---|---|
| Reviewer independence | None (self-declared) | Independent assessor | PKIC-approved assessor |
| Verifiable in public registry? | No | No (report is private) | Yes โ PKIC registry |
| Renewal required? | Recommended; not enforced | Varies by assessor | Yes โ required for continued listing |
| Appropriate for regulated industries? | Limited โ supplemental only | Often sufficient | Yes โ highest assurance |
| Typical preparation time | Weeks | 1โ3 months | 3โ6 months |
| Primary value | Internal planning baseline | Independent credibility | Market-facing credential |
DORA Chapter V is a third-party assurance use case. EU financial entities must assess, monitor, and manage ICT third-party risk and maintain a Register of Information for all ICT third-party arrangements. DORA does not name PQC, but an ICT risk framework that ignores quantum cryptographic risk is incomplete. When a bank asks whether your product has been self-assessed, third-party assessed, or PKIC certified, that question is often their DORA obligation landing on your questionnaire, not optional vendor curiosity.
Read each scenario. Choose the assurance route you'd recommend. The feedback explains the reasoning.
A startup has built a new hardware security module with ML-KEM and ML-DSA support. They're selling to SMBs and want to demonstrate PQC readiness on their product page. Budget is limited.
An established certificate authority platform vendor is targeting government and financial sector buyers who are required to document PQC readiness for their procurement decisions. The vendor has 18 months and adequate budget.
A hospital system's IT security team wants to document their PQC migration progress for an internal board report and to inform their PKIMM knowledge and training evidence package. They are not a product vendor, they are an end-user organization.
The assurance route vocabulary is one of the most useful things you can bring into PKIC working group conversations. When a discussion turns to vendor evaluation or procurement standards, being able to name the three routes, self-assessment, third-party, PKIC certified, and explain what distinguishes them demonstrates real practitioner knowledge.
If you're considering an entrepreneurial path in this space, understanding the certification pathway from both sides matters. Vendors building PQC products need to understand the route that fits their go-to-market stage. Consultants advising organizations need to understand which route to require from vendors. Both require the same foundational vocabulary you've just built.
For most SMBs, the practical question is: what should I require from my vendors? The answer depends on your organization's risk profile. For core infrastructure, your certificate authority, your VPN gateway, your identity platform, third-party assessment is a reasonable minimum bar. For ancillary tools, a credible self-assessment with supporting documentation may be sufficient.
The single most useful question you can now ask any vendor is: "Which assurance route did you use, and can you share the documentation?" A vendor who cannot answer that question clearly has not done the work. A vendor who can answer it with specifics, route, assessor, criteria version, date, has.
If you sell into the EU financial sector, DORA Chapter V makes your PQC readiness your client's compliance problem. Financial entities must assess ICT third-party cryptographic resilience. Being able to name your assurance route, and produce the documentation, is how you survive that questionnaire. NIS2 creates a parallel supply-chain question for essential and important entities outside finance.
For your organization's own PKIMM program, the self-assessment route is almost certainly the right starting point, and may be sufficient depending on your sector's regulatory requirements. The self-assessment you completed in Unit 4 using the PKIC tool is exactly this route, properly documented.
When you build your procurement requirements for PQC-relevant vendors, build a tiered requirement based on the system's criticality. Root CA infrastructure and HSMs warrant a third-party assessment requirement. Internal developer tools may be satisfied by a well-documented self-assessment. Formalizing this tiering in your procurement policy is a Level 4 governance behavior, it signals that your organization has moved from reactive assessment to systematic management.