Published ahead of its end-September plan. A pilot cycle runs in October, and v1.0 final publishes in November 2026. Open items are public on the roadmap, and corrections are published as dated entries on the errata page.
The Applied Quantum Cryptographic Concentration Framework (CCF) is a second-line method for measuring cryptographic concentration beneath the vendor layer – per important business service, at six layers where a single defect crosses nominally independent vendors. An institution running four HSM vendors, three TLS terminators and two certificate providers passes a substitutability test comfortably. Every one of those products can execute code descending from one upstream, terminate in one trust anchor, or generate keys from one design. CCF measures that.
The framework produces two figures per service. The Cryptographic Concentration Index describes how concentrated the executing estate is. Failure-domain reach describes how far one shared upstream failure travels. Where a supplier does not disclose, the reach is recorded as a bound, and non-disclosure becomes a number a procurement team can use.
Licensed under CC BY 4.0. Free to use, adapt and share, including for commercial purposes, with attribution to Steve Vaile and Marin Ivezic, Applied Quantum. The reference implementation and canonical test vectors are Apache-2.0 on GitHub.
The Applied Quantum
Cryptographic Concentration Framework
The Universal Framework sets out the complete method: units and metrics, evidence standards, an eight-phase assessment, and determinations a risk analyst can defend in review. It ships with a validation annex re-running the layer-6 reading over the 2017 ROCA record, where certificates on 760,000 Estonian ID cards were suspended on one shared generation design.
Every canonical figure in the family comes from the reference implementation, and the ten canonical test vectors fix each one exactly.
Computable Without Us
Reference Implementation & Test Vectors
The computation engine and ten canonical vectors, human-readable and as JSON fixtures. The vectors are script-generated and never hand-edited. Any implementation that reproduces all ten is conformant.
Discovery Coverage Attestation
A CCF instrument for demonstrating how a discovery run was performed without disclosing the inventory itself. The predicate type URI is reserved now, with three design decisions and one non-goal on the record. The full specification publishes in v1.1, Q1 2027.
Roadmap, Errata, Provenance, Census
Commitments with dates on the roadmap, corrections as dated entries on the errata page, the adjacent-work record at provenance, and the payments frontier census publishing its methodology now and its first snapshot with v1.0 final.
Six Layers Where One Defect Crosses Vendors
Substitutability tests ask whether a supplier can be replaced. CCF resolves each important business service to the components executing underneath and measures concentration where common-mode failure occurs. The index is computed per layer, and failure-domain reach is reported with it, co-equal.
Failure-domain reach – evidenced or bounded
Effective Coverage
Evidence standards
Defensible determinations
The Document Family
Payments
Layer-by-layer enumerations for card, interbank and settlement services, the payments consequence-threshold template, and the card-authorisation worked example behind the whitepaper’s figures.
Financial Services
Banking, capital markets and insurance enumerations with the correspondent-banking worked example. Banking is practitioner-tested. Capital markets and insurance validate toward v1.0 final, stated on the document’s face.
CBOM Conformance Statement
Which fields of the Applied Quantum CBOM Profile (v1.0-RC or later) CCF consumes, at which conformance level, for which layer. Every field it names is defined in the Profile.
Technical Companion
Obtaining the data: discovery approaches, evidence grading, and what is not obtainable today. Deliberately outside the framework, so the method does not age with tooling.
Five Instruments, Published Early
Data Request
What second line asks first line for, and what a complete response looks like. Deadlines, named non-response consequences, and an accountable individual on the coverage statement.
Supplier Lineage Disclosure Request
The supplier request behind the reach measurements. Attributed and anonymised response tiers, the three-state record, and a supplier that declines gets a range, with the range attributed.
Board Report Template
The institution-level figure with its five mandatory companions, limitations and the maturity gate. Reporting the figure without them is non-conformant.
Model Documentation Pack
Documentation sufficient for model-risk review of the computation and its inputs. Units, exclusivity, reach semantics and the canonical test vectors.
Discovery Coverage Attestation
The sixth instrument. Its predicate type URI is reserved at /predicates/coverage/v1 with the design decisions on the record. The specification publishes in v1.1, Q1 2027.
Run the Assessment in Three Moves
A second-line function can run the first cycle this quarter, on five to eight important business services, with its own staff and its own inventory.
Frameworks & the Data Contract
CCF is one of three openly published Applied Quantum properties, and it consumes a data contract owned by neither framework.
The CycloneDX property taxonomy CCF consumes, cited by minimum version: v1.0-RC or later. The CBOM Conformance Statement on this site states which Profile fields each CCF level requires. Owned by neither framework.
The eight-phase migration methodology at v2.1, with six sector extensions. CCF’s sector extensions follow its taxonomy, and where the PQC Framework governs the migration, CCF measures what sits beneath it.
The computation engine and the ten canonical test vectors, Apache-2.0, on the Applied Quantum organisation. Every figure in the published documents reproduces from them.
Research-driven professional services firm focused entirely on quantum technologies, from quantum computing and systems integration to strategy, sovereignty advisory, and quantum-safe security across all sectors.
Applied Quantum’s security-focused practice. Hands-on services including PQC readiness assessments, cryptographic inventory and CBOM, crypto-agility consulting, hybrid implementation, quantum risk assessment, and regulatory advisory.
Marin’s personal blog on quantum security with over 1 million monthly readers. In-depth practitioner analysis covering PQC migration, cryptographic inventory, CBOM, hybrid deployment, vendor governance, and sector deep dives.