Security badges fail when they make broad claims. The right model is narrower: a badge should link to evidence about a particular endpoint, verification level, assessment date and expiry date.
That evidence can help customers, auditors and procurement teams understand whether a public website has taken a practical step toward post-quantum readiness. It cannot replace internal discovery, supplier review, code review, penetration testing or a full cryptographic inventory.
For this reason, badge wording should avoid absolute claims such as "quantum proof" or "fully secure." It should use scoped language such as "T1 Transport Ready" or "T2 PQC Active for the assessed public endpoint."