Skip to content
Theos Quantum TQ globe markTHEOS QUANTUM
Risk & scoring

What the risk tiers mean

Four tiers, four score bands with no gaps and no overlaps, and the action each one is expected to trigger

Reviewed 22 Sept 2026 7 min read
On this page — 6 sections

A score of 71 is not an instruction. A tier is. AutoPQC places every scored asset, and every estate, into one of four tiers, and each tier carries an expected action and a place in the migration sequence. This page gives the bands, explains why the boundaries sit where they do, and states what a tier does not authorise.

Four tiers, four bands

The bands are contiguous and exclusive. Every integer from 0 to 100 belongs to exactly one tier, and no integer belongs to two. There is no band that requires a judgement call about which side of it a score falls on.

TierBandWhat it meansDefault sequencing
Acute85–100A defeated primitive on a reachable asset holding long-lived data. Captured traffic stays valuable well beyond any plausible migration schedule.First wave. Remediation design starts before anything else in the backlog, and hybrid deployment is the usual first move.
Elevated65–84The primitive is quantum-exposed and the asset is inside the migration programme. One or two dimensions are moderating the score rather than the underlying problem being smaller.Second wave. Planned in the same programme as Acute, scheduled behind it, and not deferred to a later budget cycle.
Watch40–64Either the primitive holds today and the data outlives it, or the primitive is exposed but nothing reaches it. Real, and not urgent.Third wave, or a standing review item. Re-examined at every method version bump rather than migrated now.
Contained0–39Conformant cryptography, or exposure with no reachable path and no meaningful horizon. Nothing to do.No action. Kept in the inventory so that a configuration drift is visible.
One label per tier. These four words are the only tier names we use, anywhere.

The synthetic reference estate scored 75 / 100, which places it in Elevated. Its worst cohorts sat in Acute. An estate tier is a summary of a distribution, so it is always read next to the distribution, never instead of it. See How the exposure score is built for the roll-up arithmetic.

Why the boundaries sit where they do

Each boundary corresponds to something in the arithmetic, not to a round number chosen for the look of it.

85. Fragility at its maximum contributes 30 points. To clear 85, an asset needs 55 of the remaining 70 available from Horizon, Reachability, Change Cost and Substitution Gap. In practice that requires at least two of them to be high. Acute therefore cannot be reached on a bad algorithm alone, which is the point: a broken primitive protecting nothing, reachable by nobody, is not an emergency.

65. This is the fragility floor. An asset whose primitive is completely defeated and which is meaningfully reachable cannot be tiered below Elevated even if its data is short-lived and the fix is a one-line configuration change. The floor and the band boundary are the same number by construction.

40. Below 40, the score is no longer dominated by fragility. An asset here is usually one whose cryptography is currently sound but whose data will outlive the algorithm’s expected life. That belongs in a review cycle, not in a migration wave.

A sound primitive can still reach Watch

A conformant algorithm protecting data with a fifty-year retention obligation on a public endpoint can land in the high 40s or low 50s. That is intentional. The finding is telling you that the crypto-agility of that asset matters more than its current algorithm choice. See Designing for crypto-agility.

The synthetic reference estate, tier by tier

The synthetic reference estate has an aggregate in Elevated. Its illustrative cohorts produce the distribution below. Both the counts and cohort means are teaching inputs, not customer observations. See How the exposure score is built for the arithmetic.

TierAssetsShare of the estateWhat it contained
Acute1331%Internet-facing TLS termination, and the code-signing and firmware keys
Elevated1638%Internal service-mesh mTLS, and RSA key wrapping on archived backups
Watch717%Batch file transfer using SHA-1 for integrity and 3DES for confidentiality
Contained614%Data at rest under AES-256-GCM with SHA-384
Total42100%36 of the 42 illustrative assets are outside Contained
The synthetic example has six assets in Contained and 36 outside it. These tiers are not a binary quantum-vulnerability classification.

Two things are worth reading off this. The first wave is 13 assets, not 42, which is what makes a migration programme tractable. The second is that the estate score of 75 sits in Elevated while nearly a third of the estate sits in Acute, so acting on the estate figure alone would understate the urgency. We publish both for that reason. How to read your first exposure report walks through the same distinction on your own data.

One label, used everywhere

Tier naming is a discipline, not a style choice. We use exactly four labels and we never substitute a synonym for any of them. There is no “moderate”, no “medium”, no “severe”, no colour used as a name, and no numeric severity that has to be mentally converted. If you read Elevated in the PDF report, the CBOM export or a Posture Attestation, it is the same band, computed the same way. Console and export API: Announced (roadmap).

The reason is auditability. An auditor reading a report from March and a report from October should not have to establish whether two words mean the same thing. The tier vocabulary is fixed for the life of a method major version, and a change to it is a major bump with the notice period described in How the method is versioned.

  • Tier names never carry a modifier. There is no “high Elevated” or “borderline Acute”.
  • A score is always published next to its tier, so a 65 and an 84 are distinguishable even though both are Elevated.
  • Estate tiers and asset tiers use the same four labels and the same four bands.
  • Where the fragility floor set the tier, the record says so and shows the unfloored score.

How assets move between tiers

The useful question about a tier is what it takes to leave it. Because the score is a transparent weighted mean, this is arithmetic rather than guesswork, and the platform shows the arithmetic for the remediation options it proposes.

  1. 1

    Deploy a hybrid mode

    A hybrid key establishment that combines a classical group with ML-KEM moves Primitive Fragility down without changing Horizon or Reachability. On our worked TLS example this is the single largest available move, and it is reversible, which is why we usually sequence it first. See Hybrid modes and keeping your rollback.

  2. 2

    Replace the primitive outright

    Fragility falls to near zero and Substitution Gap follows it, because there is no longer a substitution outstanding. This is what takes an asset to Contained.

  3. 3

    Reduce reachability

    Removing a public path or terminating a transcript inside a controlled boundary lowers up to 20 points. It is a genuine mitigation and it is not a fix, because the underlying primitive is unchanged.

  4. 4

    Correct a declared input

    If a retention obligation was overstated at intake, correcting it changes Horizon and may change the tier. This is handled as a recorded override, not an edit. See Why a specific asset was flagged.

Re-scoring happens on the next scheduled run, or on demand after a remediation lands. Historical scores are retained so a tier change has a visible cause and a date, which is what an auditor asks for. What to hand an auditor covers the export format.

What a tier does not authorise

Tiers are our recommendation about ordering. They are not a decision about your budget, your change freeze or your regulatory position, and they do not carry a date.

A tier isA tier is not
A place in a remediation queueA deadline
A statement about cryptographic exposureA compliance finding or a compliance pass
Comparable between assets in the same estateA rating comparable between one organisation and another
Recomputed from published inputsA judgement we will not show you the workings for

No dated obligation attaches to a tier

We do not set your remediation deadlines and we publish no service level attached to a tier. Where a genuine external deadline exists it comes from a regulator, not from us: CNSA 2.0 for national security systems, and DORA for in-scope financial entities since 17 January 2025. See CNSA 2.0 and the federal timeline and DORA and financial-sector obligations. An Acute tier is our strongest recommendation and nothing more.

Every tier assignment traces back to a detector observation through a recorded evidence chain. Here is what that chain contains.See how a finding is justified