Length: 2 Days

Quantum Cryptography Training Level 1

The CCEP credential verifies that a candidate can engineer cryptographic services across the system lifecycle, with PQC as a major design requirement rather than an isolated algorithm upgrade.

Credential Element Specification
Recommended preparation Three years of security, software, hardware, systems, PKI, or network engineering experience. Working knowledge of symmetric and public-key cryptography is expected.
Training pathway Five days of technical instruction, design laboratories, and an engineering capstone.
Assessment 150-minute, 100-question examination plus a design review and oral defense.
Passing standard 75 percent on the examination and satisfactory ratings on every critical capstone criterion.
Credential validity Three years
Renewal 50 continuing professional education hours, including at least 20 hours in cryptographic engineering or PQC, plus one documented engineering activity.

Intended Audience

  • Cryptographic and cybersecurity engineers
  • Systems, software, hardware, embedded, and network architects
  • PKI and key-management engineers
  • Product security and secure-development personnel
  • Technical reviewers responsible for cryptographic design assurance

Certification Outcomes

  1. Translate mission and security requirements into cryptographic services and measurable assurance requirements.
  2. Select primitives, parameter sets, protocols, libraries, modules, and key-management patterns without inventing custom cryptography.
  3. Design crypto-agile interfaces, formats, policy controls, lifecycle states, and transition mechanisms.
  4. Analyze randomness, key generation, storage, distribution, rotation, revocation, recovery, destruction, and audit.
  5. Evaluate performance, memory, bandwidth, hardware, timing, reliability, availability, and interoperability tradeoffs.
  6. Conduct threat modeling and design review for side channels, misuse, downgrade, parsing, fault, supply-chain, and operational risks.

Exam Domain Blueprint

Domain Weight Coverage
Requirements and architecture 20% Services; trust boundaries; misuse cases; assurance; crypto agility
Algorithms and protocols 20% Symmetric; classical public key; KEMs; signatures; composition; negotiation
Key and certificate engineering 20% Entropy; generation; storage; KMS and HSM; PKI; lifecycle
Implementation security 25% APIs; constant time; side channels; validation; errors; memory; supply chain
Verification and operations 15% Test vectors; interoperability; performance; monitoring; incident response

Training Modules

Module 1 Cryptographic Systems Engineering

  • Security services, assets, trust boundaries, and misuse cases
  • Requirements traceability and assurance levels
  • Build-versus-buy decisions and approved cryptographic modules

Module 2 Primitive and Protocol Selection

  • Symmetric cryptography, hashes, MACs, KDFs, KEMs, and signatures
  • PQC parameter sets and performance characteristics
  • Protocol composition, domain separation, binding, and negotiation

Module 3 Key Management and PKI

  • Entropy sources and deterministic random bit generators
  • Key generation, storage, backup, rotation, revocation, recovery, and destruction
  • Certificate profiles, enrollment, status, trust stores, and algorithm transitions

Module 4 Secure Implementation Architecture

  • Safe APIs, algorithm identifiers, serialization, parsing, and input validation
  • Constant-time design, side channels, fault attacks, zeroization, and secret handling
  • Hardware acceleration, HSM integration, constrained devices, and secure boot

Module 5 Crypto Agility and PQC Integration

  • Algorithm abstraction, policy-driven selection, versioning, and observability
  • Hybrid KEM and signature patterns, compatibility, and downgrade resistance
  • Migration coexistence and decommissioning

Module 6 Verification and Operational Assurance

  • Known-answer, negative, differential, fuzz, interoperability, and regression testing
  • Performance and resource benchmarking
  • Telemetry, audit, incident response, vulnerability handling, and supplier evidence

Practical Exercises

Exercise Candidate Task Evidence Produced
Requirements review Translate a mission scenario into cryptographic and assurance requirements Requirements traceability matrix
Architecture trade study Compare design alternatives using security, performance, and lifecycle criteria Trade study and decision record
Threat model Analyze attack paths across APIs, keys, protocols, modules, and operations Threat model with mitigations
Design review Inspect a proposed PQC-enabled architecture for composition and lifecycle flaws Engineering review report

Capstone Assessment

Candidates engineer a crypto-agile secure communications service that must support classical and PQC deployments, enterprise PKI, HSM-backed keys, constrained clients, signed updates, and phased migration. The design package includes requirements, architecture, algorithm and protocol decisions, key lifecycle, threat model, test strategy, operational controls, and residual risks.

Capstone Scoring

Criterion Weight Performance Evidence
Requirements traceability 15% Security and mission needs map to design and verification evidence
Cryptographic design 25% Sound primitive use, composition, parameters, and protocol behavior
Lifecycle engineering 20% Complete key, certificate, algorithm, and product lifecycle controls
Implementation assurance 20% Credible protection against misuse, side channels, faults, parsing, and dependency risks
Verification and operations 20% Testable acceptance criteria, monitoring, response, and maintainability

Knowledge and Skill Boundaries

Included Engineering established cryptographic primitives into systems, including architecture, implementation requirements, verification, and operations.

Excluded Designing a new cryptographic primitive for real-world deployment or certifying a module, algorithm, or implementation on behalf of NIST or another authority.

Request More Information