An assessment is only useful in an audit if its criterion can be read.

The question that reaches a risk team is not what the score is. It is how it was produced, what it was compared against, on what date, with what coverage, and what it explicitly does not conclude. A methodology that a third party cannot read does not support a decision recorded in minutes.

01The decision

Adopting — and being able to defend — a criterion for assessing cryptographic exposure that produces consistent evidence across entities, across cycles, and before an auditor who took no part in the collection.

What is at stake

  • Assessments without provenance do not hold when the assessor changes or the vendor is replaced.
  • An undocumented criterion prevents comparing two cycles: the difference may be in method, not in risk.
  • Numbers without a cutoff date age silently inside reports that keep circulating.
  • An assessment that promises more than it measures creates a compliance exposure of its own.
02Evidence

IEQ's methodology is published and citable: technical report 2026-S1 covers 39,903 organizations across 17 sectors under a CC-BY license, with a permanent DOI. The index's formal basis is available as a preprint on arXiv. The method is auditable without being reproducible: weights and calibrators remain proprietary.

IEQ's methodology is published and citable: technical report 2026-S1 covers 39,903 organizations across 17 sectors under a CC-BY license, with a permanent DOI. The index's formal basis is available as a preprint on arXiv. The method is auditable without being reproducible: weights and calibrators remain proprietary.

Source
IEQ Technical Report 2026-S1, Zenodo
Date
2026-S1 edition
Population
39,903 organizations published
Coverage
Sector aggregates with an anonymity floor of K = 30: no organization is individually exposed.

Limitation: The published base and the operational base are distinct collections with distinct cutoffs. Neither is a sample of the other, and results from one do not add to the other.

Open the source
03What holds the evidence up

For this persona, the relevant capability is not the score: it is what makes it checkable. Each item below exists so the readout can be audited by someone who did not produce it.

Published methodology

In production

Model, dimensions, and limits documented under an open license, with a citable DOI.

Provenance per number

In production

Source, cutoff date, run, population, and coverage accompany every value presented.

Anonymized sector ruler

In production

Comparison always against aggregates, with the anonymity floor stated.

Record of limits

In production

What the assessment does not conclude is part of the deliverable, not a footnote caveat.

04What goes on record

Documentation that survives a change of vendor, of assessor, and of cycle — which is the real test of compliance evidence.

  • The assessment criterion, with model and dimensions documented.
  • Collection cutoff date and identifier of the run used.
  • Population of the comparison ruler and anonymity floor.
  • Coverage per module and the fallbacks the model applied.
  • Contributors and the evidence origin for each.
  • Explicit limitations of what the readout does not support.

What it depends on

  • A scope definition: which entities and domains are covered.
  • An agreed cadence, when comparison across cycles is intended.
  • A defined owner for validating declared data, when the readout is in complete mode.
05What cannot be claimed from this

This section exists to be quoted. A risk report that reproduces the limits alongside the result is more defensible than one that reproduces only the number.

Observed

Public collection saw

  • Publicly verifiable cryptographic configuration on the cutoff date.
  • Publicly announced post-quantum readiness signals.

Calculated

The IEQ engine derived

  • Structural exposure on a common, comparable scale.
  • Relative position against anonymous sector aggregates.

Inferred

The model estimated

  • Secrecy shelf life from a sector prior, absent a declaration.
  • Fallback values when a module does not complete collection.

Out of scope

Other evidence decides

  • Compliance with any standard, attestation, or certification.
  • Actuarial probability of an incident or attack.
  • The date on which a relevant quantum computer will exist.
  • That two results are comparable when engine version, calibration, mode, or coverage changed.

What this comparison is measured against

Cutoff date
July 12, 2026
Run
producao_324k_20260712
Population
316,911 companies
Sectors
15 sectors in the engine taxonomy
Anonymity floor
K = 30

Limits of the comparison

  • The ruler is a static reference base, not a continuous measurement: there is no automatic update between one run and the next.
  • Comparison is always against anonymous aggregates, never against another organization's individual result.
  • A public-mode result does not compare to a complete-mode result, because the two readings start from different kinds of evidence.

Boundary

Where measurement ends

Adequacy programNot implemented

Measurement ends at: the technical change in the environment. Measuring exposure does not reduce it: reduction requires changing configuration, replacing certificates, switching negotiation policy, or migrating libraries — work carried out by the organization's own teams and suppliers.

This readout delivers

  • A documented, citable criterion, with published methodology.
  • Evidence with field-by-field provenance.
  • An explicit record of what the assessment does not conclude.

After the change, GWK

  • Re-collects public signals and recalculates IEQ on the same ruler, when contracted to do so.
  • States scope, mode, coverage, and run for both measurements, so the difference is interpretable.
  • Attributes the observed effect only to the scope actually changed and verified.

Not included

  • Executing the change: GWK does not alter the client's configuration, certificates, or infrastructure.
  • Deployment, assisted operation, or change management.
  • An adequacy program: it exists as a GWK engineering project, not as a contractable capability.

Read the method before contracting the readout

The methodology is published under an open license and can be reviewed by your team before any commercial conversation. If you would rather discuss how it applies to your context, that is what the technical session is for.