Release Candidate

Published ahead of its end-September plan. A pilot cycle runs in October, and v1.0 final publishes in November 2026. Open items are public on the roadmap, and corrections are published as dated entries on the errata page.

The Applied Quantum Cryptographic Concentration Framework (CCF) is a second-line method for measuring cryptographic concentration beneath the vendor layer – per important business service, at six layers where a single defect crosses nominally independent vendors. An institution running four HSM vendors, three TLS terminators and two certificate providers passes a substitutability test comfortably. Every one of those products can execute code descending from one upstream, terminate in one trust anchor, or generate keys from one design. CCF measures that.

The framework produces two figures per service. The Cryptographic Concentration Index describes how concentrated the executing estate is. Failure-domain reach describes how far one shared upstream failure travels. Where a supplier does not disclose, the reach is recorded as a bound, and non-disclosure becomes a number a procurement team can use.

Licensed under CC BY 4.0. Free to use, adapt and share, including for commercial purposes, with attribution to Steve Vaile and Marin Ivezic, Applied Quantum. The reference implementation and canonical test vectors are Apache-2.0 on GitHub.

Release Candidate · v1.0-RC

The Applied Quantum
Cryptographic Concentration Framework

The Universal Framework sets out the complete method: units and metrics, evidence standards, an eight-phase assessment, and determinations a risk analyst can defend in review. It ships with a validation annex re-running the layer-6 reading over the 2017 ROCA record, where certificates on 760,000 Estonian ID cards were suspended on one shared generation design.

Every canonical figure in the family comes from the reference implementation, and the ten canonical test vectors fix each one exactly.

Version 1.0-RC · August 2026 · Steve Vaile and Marin Ivezic / Applied Quantum · CC BY 4.0

Ships With the Framework

Computable Without Us

Apache-2.0

Reference Implementation & Test Vectors

The computation engine and ten canonical vectors, human-readable and as JSON fixtures. The vectors are script-generated and never hand-edited. Any implementation that reproduces all ten is conformant.

Get the kit →

Reserved · Specification v1.1

Discovery Coverage Attestation

A CCF instrument for demonstrating how a discovery run was performed without disclosing the inventory itself. The predicate type URI is reserved now, with three design decisions and one non-goal on the record. The full specification publishes in v1.1, Q1 2027.

Read the reservation →

The Public Record

Roadmap, Errata, Provenance, Census

Commitments with dates on the roadmap, corrections as dated entries on the errata page, the adjacent-work record at provenance, and the payments frontier census publishing its methodology now and its first snapshot with v1.0 final.

See the roadmap →

“Switching vendors moves the contract, not the dependency.”
Framework Architecture

Six Layers Where One Defect Crosses Vendors

Substitutability tests ask whether a supplier can be replaced. CCF resolves each important business service to the components executing underneath and measures concentration where common-mode failure occurs. The index is computed per layer, and failure-domain reach is reported with it, co-equal.

1
Algorithm
fails through cryptanalysis
2
Implementation Lineage
a defect inherited by every descendant of one ancestor
3
Trust Root
mis-issuance · root compromise · deprecation
4
Key Custody Platform
firmware defect · validated-module recall
5
Protocol & Negotiation
downgrade to the weakest mutual option
6
Key Generation: Entropy & Design
silent, total, retroactive compromise
Runs Across Every Layer
Where a supplier does not disclose, the reach is recorded as a bound
Cryptographic Concentration Index
Failure-domain reach – evidenced or bounded
Effective Coverage
Evidence standards
Defensible determinations
All Published at v1.0-RC

The Document Family


CCF Payments Extension v1.0-RC

Sector Extension

Payments

Layer-by-layer enumerations for card, interbank and settlement services, the payments consequence-threshold template, and the card-authorisation worked example behind the whitepaper’s figures.

Download PDF →


CCF Financial Services Extension v1.0-RC

Sector Extension

Financial Services

Banking, capital markets and insurance enumerations with the correspondent-banking worked example. Banking is practitioner-tested. Capital markets and insurance validate toward v1.0 final, stated on the document’s face.

Download PDF →


CCF Payments Whitepaper v1.0-RC

Practitioner Whitepaper

Cryptographic Concentration in Payments

Measuring cryptographic concentration beneath the vendor layer. Why the substitutability test cannot detect shared-lineage concentration, what the public record shows, and what a payment institution can measure this quarter.

Download PDF →


CCF CBOM Conformance Statement v1.0-RC

Normative · Data Contract

CBOM Conformance Statement

Which fields of the Applied Quantum CBOM Profile (v1.0-RC or later) CCF consumes, at which conformance level, for which layer. Every field it names is defined in the Profile.

Download PDF →


CCF Technical Companion v1.0-RC

First Line

Technical Companion

Obtaining the data: discovery approaches, evidence grading, and what is not obtainable today. Deliberately outside the framework, so the method does not age with tooling.

Download PDF →


CCF Concentration Sensitivity Model Concept Note v1.0-RC

Concept Note · Optional

Concentration Sensitivity Model

An optional impairment-propagation analysis consuming measured framework outputs, with its open questions stated and worked publicly. The framework depends on none of it.

Download PDF →

The Operating Paperwork

Five Instruments, Published Early


CCF Instrument – Data Request v1.0-RC

Instrument · Phase 2

Data Request

What second line asks first line for, and what a complete response looks like. Deadlines, named non-response consequences, and an accountable individual on the coverage statement.

Download PDF →


CCF Instrument – Supplier Lineage Disclosure Request v1.0-RC

Instrument · Supplier-Facing

Supplier Lineage Disclosure Request

The supplier request behind the reach measurements. Attributed and anonymised response tiers, the three-state record, and a supplier that declines gets a range, with the range attributed.

Download PDF →


CCF Instrument – Determination Log v1.0-RC

Instrument · Judgment Trail

Determination Log

Determinations, exclusions and evidence grades, recorded before anything is computed from them and travelling with the assessment into review.

Download PDF →


CCF Instrument – Board Report Template v1.0-RC

Instrument · Reporting

Board Report Template

The institution-level figure with its five mandatory companions, limitations and the maturity gate. Reporting the figure without them is non-conformant.

Download PDF →


CCF Instrument – Model Documentation Pack v1.0-RC

Instrument · Model Risk

Model Documentation Pack

Documentation sufficient for model-risk review of the computation and its inputs. Units, exclusivity, reach semantics and the canonical test vectors.

Download PDF →

Instrument · Reserved

Discovery Coverage Attestation

The sixth instrument. Its predicate type URI is reserved at /predicates/coverage/v1 with the design decisions on the record. The specification publishes in v1.1, Q1 2027.

Read the reservation →

Getting Started

Run the Assessment in Three Moves

A second-line function can run the first cycle this quarter, on five to eight important business services, with its own staff and its own inventory.

Request
Phase 2
Issue the Data Request as written, with a deadline and a named non-response consequence
Take a CBOM conforming to the Applied Quantum CBOM Profile, v1.0-RC or later
The Conformance Statement says which fields, at which level, for which layer
Compute & Challenge
Phases 3–6
Resolve to exclusive executing units and compute the index per layer
Carry reach beside it, evidenced where lineage is disclosed and bounded where it is not
Dispatch the Lineage Disclosure Request where lineage is undisclosed, and log every judgment in the Determination Log
Report
Phase 7
One institution-level figure with its five mandatory companions
Limitations and the maturity gate stated, never optional
The assessment workbook and heat map template publish in September, per the roadmap
The Family

Frameworks & the Data Contract

CCF is one of three openly published Applied Quantum properties, and it consumes a data contract owned by neither framework.

Input Data Contract

Applied Quantum CBOM Profile

The CycloneDX property taxonomy CCF consumes, cited by minimum version: v1.0-RC or later. The CBOM Conformance Statement on this site states which Profile fields each CCF level requires. Owned by neither framework.

cbomprofile.org →

Sibling Framework

PQC Migration Framework

The eight-phase migration methodology at v2.1, with six sector extensions. CCF’s sector extensions follow its taxonomy, and where the PQC Framework governs the migration, CCF measures what sits beneath it.

pqcframework.org →

Machine-Readable

Reference Kit on GitHub

The computation engine and the ten canonical test vectors, Apache-2.0, on the Applied Quantum organisation. Every figure in the published documents reproduces from them.

github.com/appliedquantum →

Applied Quantum

Research-driven professional services firm focused entirely on quantum technologies, from quantum computing and systems integration to strategy, sovereignty advisory, and quantum-safe security across all sectors.

appliedquantum.com →

Secure Quantum

Applied Quantum’s security-focused practice. Hands-on services including PQC readiness assessments, cryptographic inventory and CBOM, crypto-agility consulting, hybrid implementation, quantum risk assessment, and regulatory advisory.

securequantum.com →

PostQuantum.com

Marin’s personal blog on quantum security with over 1 million monthly readers. In-depth practitioner analysis covering PQC migration, cryptographic inventory, CBOM, hybrid deployment, vendor governance, and sector deep dives.

postquantum.com →

Stay Current