QCAS Version 1.1 Standard
QCA Assurance v1.1
The Quantum Cryptographic Assurance Standard (QCAS v1.1) provides a formal methodology for validating cryptographic resilience against quantum threats. Issued in 2024, this standard comprises 32 technical controls across 8 domains, referencing 22 international standards. It provides 3 validation verdicts across 2 operational scopes to ensure forensic governance and evidentiary rigor for boards and regulators.
Formal Requirements
Scope and Foreword
QCAS v1.1 establishes technical requirements for Post-Quantum Cryptography transition. Scope includes all FIPS-related modules; Out of Scope includes legacy non-networked air-gapped systems.
Normative References
Primary alignments include NIST FIPS 140-3, FIPS 203 (ML-KEM), 204 (ML-DSA), 205 (SLH-DSA), CNSA 2.0, ISO/IEC 19790, and the ETSI QKD security frameworks.
General Requirements
Asset owners must maintain a machine-readable Cryptographic Bill of Materials (CBOM) and demonstrate active crypto-agility through documented API-driven abstraction layers.
CONTROL DOMAINS
Summary of Core Controls
Algorithmic Integrity (ALG)
QCAS-ALG-01 through 04. Focuses on the transition from classical RSA/ECC to lattice-based schemes. Requires validation of public-key reuse policies and entropy source verification.
Key & Identity Management
QCAS-KMS-01 to 05. Mandates quantum-resistant key derivation functions (KDF) and strict identity-based access controls for private key material and HSM-based orchestration.
Hybrid Systems & Agility
QCAS-HBY-01 to 04. Evaluates hybrid 'Classical + PQC' implementations to ensure backward compatibility does not introduce vulnerabilities to the quantum-safe layer during migration.
Inventory & Certificate Ops
QCAS-INV-01 to 06. Requirement for real-time certificate discovery and automated rotation. Focuses on lifecycle automation to prevent outages during the PQC transition phase.
Global Alignment & Verdicts
Governance is measured via the Validation Verdict Framework: Compliant, Conditionally Compliant (remediation required), or Non-Compliant. QCAS aligns with the Global Standards Alignment Matrix, covering the US SEC Cyber Rules, EU DORA, Singapore’s MAS guidelines, and Australian APRA CPS 234 requirements. This ensures that legal and technical stakeholders operate from a unified source of cryptographic truth.
Annex B (Revision History): Initial Draft v1.0 (Jan 2024); Current Standard v1.1 (June 2024) addressing finalized NIST PQC parameters. For technical inquiries or standard certification, contact the QCAS Secretariat via SITG-Consulting. This framework serves as the definitive record for cryptographic assurance. Evidence over assumption. Control over narrative.