ZeroHour
arXiv cs.CRpublished ()ingested Mohamed Aly Bouke

A Global Readiness and Sovereignty Capability Model for Post-Quantum Cryptography Migration

infoResearchimportance 32
AI summary · glm-5.3-flash

Researchers propose a Readiness-Sovereignty Capability Model scoring 57 countries on post-quantum cryptography readiness and sovereignty.

The RSCM model decomposes cryptographic sovereignty into indigenous capacity, indigenous post-quantum control, and external dependency, with a gate requiring demonstrated creation in at least one core layer. Applied to 57 documented cryptographic actors, 20 countries clear the maker gate (15 full-stack, 5 research makers), 11 hold strong general capacity without post-quantum control, and 25 are dependent. Readiness correlates with independent cyber indices up to rank correlation 0.70, while post-quantum creation shows no significant correlation with commitment (0.22).

  • Fifteen countries qualify as full-stack post-quantum makers, five as research makers
  • Twenty-five of 57 assessed actors remain dependent on external cryptography
  • Gate agreement shows quadratic-weighted kappa of 0.71 with stability checks
  • Framework links PQC migration policy to measurable national sovereignty
ProductsRSCM
Full article249 words · extracted from arxiv.org · click to collapse

Cryptographic dependence predates the quantum era, but the migration to post-quantum cryptography (PQC) opens a rare window to reshape it, because the algorithms, implementations, hardware, and standards adopted now can lock in dependence or sovereignty for decades. This paper introduces the Readiness-Sovereignty Capability Model (RSCM), a national measurement model that operationalizes PQC readiness together with cryptographic sovereignty, which current maturity models score only as readiness and the sovereignty literature defines without measuring. RSCM decomposes sovereignty into three distinct constructs, indigenous cryptographic capacity, indigenous post-quantum control, and external dependency, and certifies a post-quantum maker only through a gate requiring demonstrated, institutionally sustained creation in at least one core layer, whether design, implementation, or validation. Applying it to fifty-seven documented cryptographic actors coded from cited public evidence, and testing that coding with an independent second coder, a plausible-state bootstrap, and convergent-validity checks, we find that twenty countries clear the gate, fifteen as full-stack makers and five as research makers, eleven hold strong general capacity without post-quantum control, one is a ready adopter, and twenty-five are dependent. The gate cells show substantial weighted agreement, a quadratic-weighted kappa of 0.71, and the maker classification is stable in its core though uncertain at the threshold. Readiness tracks independent cyber indices at rank correlations up to 0.70, while post-quantum creation shows no significant correlation with the commitment index, a rank correlation of only 0.22 that separates control from readiness. The paper contributes the framework, the evidence-graded assessment, and policy directions for building indigenous quantum-safe capacity.

Text extracted automatically; images, tables and formatting may be missing. Original: https://arxiv.org/abs/2609.18477