Self-Service Engineering Diagnostic

PCI DSS v4.0 CBOM & Quantum Readiness Scorecard

Evaluate your payment architecture against PCI DSS Requirement 4.2.1.1, NIST FIPS 203/204 standardizations, and 'Harvest Now, Decrypt Later' (HNDL) risks. Complete the 8 questions below for an instant vulnerability index.

Evaluation Progress0 of 8 Answered

1. Cryptographic Inventory & CBOM (PCI DSS Req 4.2.1.1 & 12.3.3)

Under active QSA enforcement of PCI DSS v4.0.1 (specifically Requirements 4.2.1.1 and 12.3.3, strictly mandatory since March 31, 2025): QSAs actively issue formal findings of QSA non-conformance if an automated, machine-readable Cryptographic Bill of Materials (CBOM) is missing across Cardholder Data Environment (CDE) switches. Do you maintain an automated, machine-readable inventory?

2. Asymmetric Public-Key Algorithms in Transaction Routing

What cryptographic algorithms protect authorization messages between your API gateways, merchant endpoints, and clearing switches?

3. Cardholder Data Retention Window & HNDL Risk Exposure

How long are encrypted Primary Account Numbers (PANs), cardholder metadata, or tokenization mapping tables retained in your databases and backup archives?

4. Payment HSMs, TR-31 Key Blocks & Storage Capacity (PCI PTS HSM v5.0)

Under PCI PTS HSM v5.0, PCI PIN Security Phase 3 (TR-31 key block wrapping mandate), and the September 2026 NIST FIPS 140-2 sunset, have you evaluated your HSM fleet (Thales payShield, Atalla AT1000, IBM Crypto Express CEX cards) for ML-KEM-768 key block database bloat (1,184-byte keys causing 7.4× storage expansion)?

5. ISO 8583 / Core Switch Latency Budgeting

Have you benchmarked the impact of expanded post-quantum handshakes (>1,500 byte TCP MTU) on sub-10ms switch processing SLAs?

6. Legacy Heavy Iron & Switch Crypto-Agility (IBM zSystems & HP NonStop)

Are cryptographic calls decoupled via an abstraction layer across your core transaction infrastructure (e.g. IBM zSystems mainframes, HP NonStop Tandem servers running BASE24, or cloud microservices)?

7. Third-Party Vendor & Card Scheme Dependencies

Have you audited whether your upstream payment processors, card brand connections, and SaaS tokenization vendors support PQC algorithms?

8. C-Suite, QSA & CNSA 2.0 Post-Quantum Migration Strategy

Does your organization have a board-approved post-quantum migration budget and roadmap aligned with the January 1, 2027 CNSA 2.0 Procurement Gate, active PCI DSS Req 12.3.3 cipher review standards, and QSA expectations?

Assessment Result
0 / 100
Incomplete Assessment

Please answer all questions above to calculate your organization's Quantum Vulnerability Index and PCI DSS v4.0 CBOM compliance profile.