Skip to content
Theos Quantum Θ mark
Risk & scoring

What the risk tiers mean

Four tiers, four score bands with no gaps and no overlaps, and the action each one is expected to trigger

Reviewed 24 Jul 2026 7 min read
On this page — 6 sections

A score of 71 is not an instruction. A tier is. AutoPQC places every scored asset, and every estate, into one of four tiers, and each tier carries an expected action and a place in the migration sequence. This page gives the bands, explains why the boundaries sit where they do, and states what a tier does not authorise.

Four tiers, four bands

The bands are contiguous and exclusive. Every integer from 0 to 100 belongs to exactly one tier, and no integer belongs to two. There is no band that requires a judgement call about which side of it a score falls on.

TierBandWhat it meansDefault sequencing
Acute85–100A defeated primitive on a reachable asset holding long-lived data. Captured traffic stays valuable well beyond any plausible migration schedule.First wave. Remediation design starts before anything else in the backlog, and hybrid deployment is the usual first move.
Elevated65–84The primitive is quantum-exposed and the asset is inside the migration programme. One or two dimensions are moderating the score rather than the underlying problem being smaller.Second wave. Planned in the same programme as Acute, scheduled behind it, and not deferred to a later budget cycle.
Watch40–64Either the primitive holds today and the data outlives it, or the primitive is exposed but nothing reaches it. Real, and not urgent.Third wave, or a standing review item. Re-examined at every method version bump rather than migrated now.
Contained0–39Conformant cryptography, or exposure with no reachable path and no meaningful horizon. Nothing to do.No action. Kept in the inventory so that a configuration drift is visible.
One label per tier. These four words are the only tier names we use, anywhere.

The pilot estate scored 75 / 100, which places it in Elevated. Its worst cohorts sat in Acute. An estate tier is a summary of a distribution, so it is always read next to the distribution, never instead of it. See How the exposure score is built for the roll-up arithmetic.

Why the boundaries sit where they do

Each boundary corresponds to something in the arithmetic, not to a round number chosen for the look of it.

85. Fragility at its maximum contributes 30 points. To clear 85, an asset needs 55 of the remaining 70 available from Horizon, Reachability, Change Cost and Substitution Gap. In practice that requires at least two of them to be high. Acute therefore cannot be reached on a bad algorithm alone, which is the point: a broken primitive protecting nothing, reachable by nobody, is not an emergency.

65. This is the fragility floor. An asset whose primitive is completely defeated and which is meaningfully reachable cannot be tiered below Elevated even if its data is short-lived and the fix is a one-line configuration change. The floor and the band boundary are the same number by construction.

40. Below 40, the score is no longer dominated by fragility. An asset here is usually one whose cryptography is currently sound but whose data will outlive the algorithm’s expected life. That belongs in a review cycle, not in a migration wave.

A sound primitive can still reach Watch

A conformant algorithm protecting data with a fifty-year retention obligation on a public endpoint can land in the high 40s or low 50s. That is intentional. The finding is telling you that the crypto-agility of that asset matters more than its current algorithm choice. See Designing for crypto-agility.

The pilot estate, tier by tier

An estate tier of Elevated is a mean. The distribution behind it is what a programme is actually run from. Taking the pilot cohorts from How the exposure score is built and tiering each one gives the shape below. Cohort membership follows the illustrative cohort means used there; the asset counts are the pilot’s real figures.

TierAssetsShare of the estateWhat it contained
Acute1331%Internet-facing TLS termination, and the code-signing and firmware keys
Elevated1638%Internal service-mesh mTLS, and RSA key wrapping on archived backups
Watch717%Batch file transfer using SHA-1 for integrity and 3DES for confidentiality
Contained614%Data at rest under AES-256-GCM with SHA-384
Total42100%36 of the 42 were classified vulnerable — every asset outside Contained
The six Contained assets are exactly the six not classified vulnerable in the pilot run.

Two things are worth reading off this. The first wave is 13 assets, not 42, which is what makes a migration programme tractable. The second is that the estate score of 75 sits in Elevated while nearly a third of the estate sits in Acute, so acting on the estate figure alone would understate the urgency. We publish both for that reason. How to read your first exposure report walks through the same distinction on your own data.

One label, used everywhere

Tier naming is a discipline, not a style choice. We use exactly four labels and we never substitute a synonym for any of them. There is no “moderate”, no “medium”, no “severe”, no colour used as a name, and no numeric severity that has to be mentally converted. If you read Elevated in the console, the PDF report, the CBOM export, an API response or a Posture Attestation, it is the same band, computed the same way.

The reason is auditability. An auditor reading a report from March and a report from October should not have to establish whether two words mean the same thing. The tier vocabulary is fixed for the life of a method major version, and a change to it is a major bump with the notice period described in How the method is versioned.

  • Tier names never carry a modifier. There is no “high Elevated” or “borderline Acute”.
  • A score is always published next to its tier, so a 65 and an 84 are distinguishable even though both are Elevated.
  • Estate tiers and asset tiers use the same four labels and the same four bands.
  • Where the fragility floor set the tier, the record says so and shows the unfloored score.

How assets move between tiers

The useful question about a tier is what it takes to leave it. Because the score is a transparent weighted mean, this is arithmetic rather than guesswork, and the platform shows the arithmetic for the remediation options it proposes.

  1. 1

    Deploy a hybrid mode

    A hybrid key establishment that combines a classical group with ML-KEM moves Primitive Fragility down without changing Horizon or Reachability. On our worked TLS example this is the single largest available move, and it is reversible, which is why we usually sequence it first. See Hybrid modes and keeping your rollback.

  2. 2

    Replace the primitive outright

    Fragility falls to near zero and Substitution Gap follows it, because there is no longer a substitution outstanding. This is what takes an asset to Contained.

  3. 3

    Reduce reachability

    Removing a public path or terminating a transcript inside a controlled boundary lowers up to 20 points. It is a genuine mitigation and it is not a fix, because the underlying primitive is unchanged.

  4. 4

    Correct a declared input

    If a retention obligation was overstated at intake, correcting it changes Horizon and may change the tier. This is handled as a recorded override, not an edit. See Why a specific asset was flagged.

Re-scoring happens on the next scheduled run, or on demand after a remediation lands. Historical scores are retained so a tier change has a visible cause and a date, which is what an auditor asks for. What to hand an auditor covers the export format.

What a tier does not authorise

Tiers are our recommendation about ordering. They are not a decision about your budget, your change freeze or your regulatory position, and they do not carry a date.

A tier isA tier is not
A place in a remediation queueA deadline
A statement about cryptographic exposureA compliance finding or a compliance pass
Comparable between assets in the same estateA rating comparable between one organisation and another
Recomputed from published inputsA judgement we will not show you the workings for

No dated obligation attaches to a tier

We do not set your remediation deadlines and we publish no service level attached to a tier. Where a genuine external deadline exists it comes from a regulator, not from us: CNSA 2.0 for national security systems, and DORA for in-scope financial entities since 17 January 2025. See CNSA 2.0 and the federal timeline and DORA and financial-sector obligations. An Acute tier is our strongest recommendation and nothing more.

Every tier assignment traces back to a detector observation through a recorded evidence chain. Here is what that chain contains.See how a finding is justified