TL;DR: PKI Maturity Model 2.0.0 introduces an extension framework. Therefore a risk profile or industry context can add emphasis without forking the model. The first extension, PQC Readiness, is published and openly marked as under development.

An organisation can reach the top maturity level on every current requirement and still carry material cryptographic risk. Still, quantum-vulnerable foundations do not show up in the score.

Every maturity model faces the same pressure. Someone needs it to say more about their sector, their regulator, or their particular risk. So the model either grows until it fits nobody. Alternatively it gets forked privately and stops being comparable.

PKI Maturity Model 2.0.0 takes a third path. It defines a framework for optional overlays. Instead, these add emphasis or extra criteria without touching the core definition.

How an extension works

An extension follows the same hierarchy as the model itself: modules, then categories, then requirements. Consequently it is readable by anyone who already knows the model.

It can do three things. It may add extension-specific maturity criteria to existing categories. It may apply weight overlays to existing requirements or categories. And it may define its own scoring and reporting while still producing the standard report.

The scoring concept is worth stating simply. An extension introduces an additional maturity signal called Relevance. Also, it adjusts importance through Overlays. Your baseline maturity is then blended with that signal, weighted by the extension’s emphasis.

Design principle What it guarantees
Non-destructive Extensions never modify the base model definition
Composable Several extensions may coexist, each scored independently against the same baseline
Consistent scoring Scoring works the same way in full requirement-based assessment and category-based self-assessment
Model-shaped Extensions use the same modules, categories, and requirements hierarchy
The four design principles behind the extension framework.

Non-destructive is the principle that makes the rest safe. An extension cannot alter the core. Therefore enabling one never invalidates a baseline assessment. And you can remove it again without recalculating anything.

There is a machine-readable contract too. The framework publishes a JSON Schema for extension definitions. Therefore tooling can validate an extension rather than trusting it.

The PQC Readiness extension

The first published extension addresses quantum-safe transition. Its argument is the one in the callout above. The quantum threat changes what maturity means, because a programme can score well while resting on vulnerable foundations.

That is a present-day concern rather than a future one. Harvest-now, decrypt-later makes long-lived confidentiality a risk today. Moreover, your migration timetable does not change that.

The extension adds PQC-specific criteria alongside the baseline categories. It also applies weight overlays to the requirements most relevant to migration. Its primary audience is certificate authority and trust service provider operators. Similarly, enterprise PKI architects, auditors, and consultants are in scope.

What is finished, and what is not

The extension is marked under development, and the working group is specific about where the boundary sits. We would rather repeat that clearly than let a preview read as a finished product.

Scope State
Governance module, categories 1 to 4 Complete — full Level 1 to 5 criteria, assessor guidance, evidence examples, and overlay weights
Management, Operations, Resources modules Outline only — PQC-critical considerations identified, Level 1 to 5 criteria not yet developed
Version Under development, moving to 1.0.0 when all modules are fully developed and the working group endorses the content
Current development state of the PQC Readiness extension.

One design question is also still open, and it is a genuine one. Overlay placement has two candidate approaches. One applies governance-centric multipliers to the Governance categories. Alternatively, capability-centric multipliers apply to crypto-agility and PQC training. The current definition follows the governance-centric design. Specifically, that is what the self-assessment tool exercises today. Resolving it is a working-group decision.

Coverage gaps are documented as well. Persona coverage is incomplete for certificate-consuming organisations, software vendors, and cryptographic governance at the AI system layer. Importantly, all three are recorded as known gaps for a later revision. Therefore anyone expecting the extension to answer those questions today should read the status notes first.

A preview that names its unfinished parts is more useful than one that hides them.

Where the pieces live

The framework, its structure and scoring documentation, and the JSON Schema live with the core model. The published extensions live in a separate catalog, so the core repository no longer ships individual extension content.

That separation has a practical benefit. An extension can iterate at its own pace and declare which model versions it is compatible with, without waiting for a core release.

Why we think this is the right shape

OmniTrust contributes to the PKI Maturity Model working group, and extensions are the part of 2.0.0 we find most interesting.

A single model cannot serve a certificate authority, a bank, and a device manufacturer equally well. But three forked models cannot be compared at all. In practice that defeats the purpose of measuring maturity. Overlays keep one comparable baseline while letting a sector emphasise what matters to it.

The framework is new and the first extension is unfinished. Therefore this is the moment when feedback is cheapest to act on. If you assess PKI programmes, the open overlay-placement question is a good place to start.


Key Takeaways

  • 2.0.0 adds an extension framework: optional overlays that add criteria or weighting without modifying the core model.
  • Extensions are non-destructive, composable, consistently scored, and shaped like the model, with a JSON Schema contract.
  • Scoring blends baseline maturity with an extension Relevance signal, weighted by extension Overlays.
  • PQC Readiness is the first published extension, at version 0.2.0 and under development.
  • Its Governance module is complete, while Management, Operations, and Resources are outlined only.
  • Also, overlay placement remains an open working-group question.

For the core model changes behind this framework, read what changed in PKI Maturity Model 2.0.0, and start with from ad-hoc to governed operations if the model is new to you. PQC readiness begins with knowing what you run. So building a cryptographic asset inventory is the practical first step. To discuss an assessment, get in touch.