About

About the Cryptographic Concentration Framework

The Cryptographic Concentration Framework (CCF) is an open, second-line method for measuring cryptographic concentration beneath the vendor layer – per important business service, at six layers where a single defect crosses nominally independent vendors. It was developed by Steve Vaile and Marin Ivezic and is published by Applied Quantum under CC BY 4.0.

The framework exists because the standard test misses the failure mode. Vendor-substitutability regimes ask whether a supplier can be replaced, and an institution running four HSM vendors, three TLS terminators and two certificate providers passes comfortably. Resolved to the components executing underneath, every one of those products can descend from one upstream implementation, terminate in one trust anchor, or generate keys from one design. The 2017 ROCA event shows the failure mode: one key-generation library, certificates on 760,000 Estonian ID cards suspended, across products that looked independent on a vendor list. The question came up repeatedly in Applied Quantum’s post-quantum migration practice, where vendor registers that looked diverse kept resolving to shared cryptographic ancestry, and the framework was built to give risk functions a defensible way to measure it.

CCF produces two figures per service. The Cryptographic Concentration Index describes how concentrated the executing estate is at each layer, and failure-domain reach describes how far one shared upstream failure travels, evidenced where lineage is disclosed and bounded where it is not. Effective Coverage runs beside them. The family comprises twelve documents at v1.0-RC: the Universal Framework, the Payments and Financial Services extensions, a payments whitepaper, the CBOM Conformance Statement, the Technical Companion, a sensitivity concept note and five instruments. The input data contract is the Applied Quantum CBOM Profile, cited by minimum version and owned by neither framework. Every canonical figure comes from the reference implementation, Apache-2.0 on GitHub, with ten canonical test vectors that fix each one exactly.

The framework is deliberately bounded. It deliberately excludes loss estimation, likelihood and CVSS scoring, and discovery tooling. Version 1.0-RC published in August 2026, ahead of its end-September plan. A pilot cycle runs in October, v1.0 final publishes in November 2026, and the open items, corrections and adjacent-work record are public on the roadmap, errata and provenance pages.

The Authors

Steve Vaile

Steve Vaile is Director of Post-Quantum Cryptography and Resilience for banking and financial services at Applied Quantum, and co-author of the Cryptographic Concentration Framework and the Applied Quantum CBOM Profile. He brings over thirty years of experience across technology, financial services, telecommunications and international operations, and his advisory work assesses cryptographic dependencies and third-party, counterparty and concentration risk across financial ecosystems.

The dependency analysis at the heart of this framework has been his territory since the 1990s. From 1994 to 2007 he worked in operational causal analysis at MAXM, IBM RiverSoft, and EMC’s SMARTS and Voyence lines, tracing faults in banking, telecommunications and defence networks to the shared infrastructure behind them. He later advised on Cambodia’s national credit bureau, working with the IMF and the National Bank of Cambodia on its regulatory framework and reaching full adoption across the country’s banks and microfinance institutions.

Since 2024 he has also served as Director of Post-Quantum Cryptography and Resilience at Quantum Security Defence (QSECDEF), providing board-level governance across an international quantum-security community of 1,400+ members. Before his quantum-security work he spent thirteen years as CEO and chairman of an international hospitality group operating across seven countries, and he began his career as a Royal Navy engineer.

Marin Ivezic

Marin Ivezic is the founder and CEO of Applied Quantum, an EU firm operating globally with a quantum lab in Delft, and the author of PostQuantum.com, a personal blog on quantum security with over one million monthly readers. He brings over thirty years at the intersection of cybersecurity, cryptography and enterprise risk, and over twenty-five years of involvement with quantum technologies.

A former Fortune Global 500 CISO and CTO, he has held regional and global leadership positions at IBM, Accenture, PwC and KPMG. His classical cryptography career spans more than two decades of cryptographic upgrade programmes across some of the world’s largest enterprises, and his post-quantum work includes readiness programmes generating over 120,000 tasks for organisations in financial services, telecommunications and critical infrastructure.

He is the author of Quantum Ready, Quantum Sovereignty and Quantum Systems Integration, and chairs the Quantum Policy Forum.

Organisations

Applied Quantum

A research-driven professional services firm focused entirely on quantum technologies and post-quantum security. An EU firm operating globally, with a quantum lab in Delft, serving financial services, payments, government & defence, telecommunications, critical infrastructure, healthcare and digital assets.

Secure Quantum

Applied Quantum’s dedicated quantum security arm, delivering PQC migration programmes, quantum risk assessments, cryptographic inventory and CBOM work, and crypto-agility implementation.

CBOMProfile.org

The Applied Quantum CBOM Profile, the CycloneDX property taxonomy this framework consumes as its input data contract. Referenced by the PQC Migration Framework and by CCF, and owned by neither.

PQCFramework.org

The Applied Quantum PQC Migration Framework, the eight-phase migration methodology at v2.1, whose sector taxonomy CCF’s extensions follow. Where it governs the migration, CCF measures what sits beneath it.

PostQuantum.com

Marin’s personal blog on quantum security, with over one million monthly readers. Practitioner analysis of PQC migration, cryptographic inventory, CBOM and vendor governance, further reading behind this framework, never a normative source.

CCFramework.org

This site is the framework’s home. The twelve documents, the five instruments, the reserved Discovery Coverage Attestation, the reference implementation links, and the public record: roadmap, errata, provenance and the census methodology.