Purpose – This study develops and empirically evaluates a Quantum Exposure Index (QEI) for characterizing quantum-related exposure observable from public-sector Transport Layer Security (TLS) infrastructures and supporting post-quantum migration prioritization. Methods – The framework integrates TLS protocol version, certificate public-key algorithm, classical key-strength equivalence, and Perfect Forward Secrecy into a normalized composite index. Component weights were derived through the Analytical Hierarchy Process, while non-intrusive TLS measurements from publicly accessible government infrastructures provided the empirical inputs. Sensitivity and sector-level analyses were conducted to examine the robustness and interpretability of the resulting exposure profiles. Findings – The evaluated infrastructures remain dependent on classical public-key cryptography and therefore retain exposure to future quantum-capable adversaries despite widespread adoption of modern TLS configurations and forward secrecy. The analysis further shows that cryptographic key strength and protocol configuration differentiate exposure profiles, whereas the continued reliance on quantum-vulnerable public-key primitives establishes a common exposure baseline. Classification outcomes are sensitive to interpretive thresholds, reinforcing the importance of continuous index values over categorical labels. Research Implications – The QEI provides a reproducible infrastructure-level baseline for prioritizing cryptographic inventories, monitoring migration progress, and supporting evidence-based post-quantum transition planning. Originality – This study combines operational TLS measurement, standardized cryptographic-strength mapping, and multicriteria weighting within a unified quantitative framework for assessing observable quantum exposure in public-sector infrastructures.
Copyrights © 2026