What is a defensible quantum-risk posture?
A defensible posture is one where every claim about quantum readiness can be traced to current, scoped evidence, and its limits are stated openly. It shows what is protected, what is not, and why. It is not immunity, guaranteed security or legal compliance. In QCI-QS1 v2.3, "Defensible readiness" is also the name of the 81–100 score band, which additionally requires all three gates to pass.
New to this? Read What evidence should an auditor expect for quantum readiness? first. After this, continue with What is a quantum-risk assessment?.
In one sentence: Defensible means you can show your evidence and your limits, not that you cannot be harmed.
Why it matters
When questioned by a regulator, auditor or customer, an organization needs to show how it knows what it claims. Overstated claims are harder to defend than honest gaps.
Four tests of a defensible claim
- Traceable: it links to attributable, dated evidence (QCI-4.8-01).
- Scoped: it names the boundary and does not imply enterprise-wide coverage for a restricted assessment (QCI-1.2-03).
- Current: its evidence is not stale (QCI-5.1-04).
- Honest about limits: it states limitations, accepted residual risk and non-comparable trends (QCI-8.1-02).
The everyday word versus the QCI band
Band boundaries are from QCI-QS1 v2.3 (September 23, 2026). Check the current edition before citing them.
| Use | Meaning |
|---|---|
| Everyday (this page) | Claims can be supported with evidence and their limits are stated |
| QCI-QS1 v2.3 band, 81–100 "Defensible readiness" | Higher evidence-supported maturity with all score gates passed; not a security or compliance guarantee (QCI-6.5-01) |
Limits of an assessed result
- A score measures evidence-supported readiness maturity. It is not a probability of compromise, a guarantee of quantum resistance, a certificate of security or a determination of regulatory compliance (QCI-1.2-04).
- A result holds for its boundary, period and evidence date only.
- Accepted risk does not turn an unmet requirement into conformance (QCI-1.2-02).
What organizations should do
- State scope, date and assessment type with every reported result.
- Disclose gaps and limitations alongside the result.
- Remove claims you cannot trace to current evidence.
Evidence an auditor should expect
Rows marked "QCI requirement" come from the standard. Rows marked "Editorial suggestion" are QCI's practical advice and are not requirements.
| Artifact | Scope | Owner | Currency | Verification | Basis |
|---|---|---|---|---|---|
| Claim statement | Each published or reported result | Quantum Risk Owner | Each assessment | Check version, boundary, period, assessor, assessment type and record location | QCI requirement (QCI-1.2-03) |
How NIST or other primary authorities address it
This concept originates with QCI in QCI-QS1. NIST and other standards bodies do not define or endorse it.
How QCI-QS1 addresses it
QCI-QS1 defines the band and the meaning of the score; it does not define a separate "defensible posture" certification.
| Requirement | Clause | Relationship | Pillar | Gate |
|---|---|---|---|---|
| QCI-6.5-01 | 6.5 | explicit requirement | — | — |
| QCI-1.2-04 | 1.2 | explicit requirement | — | — |
| QCI-1.2-03 | 1.2 | explicit requirement | — | — |
| QCI-1.2-02 | 1.2 | explicit requirement | — | — |
Common mistakes
- Calling an organization "quantum-safe" because it scored in the top band.
- Quoting a score without its scope or date.
- Hiding exceptions to make a posture look stronger.
Questions for the board
- If challenged tomorrow, which of our quantum-readiness statements could we not support?
Questions
Does a score of 81 or more mean we are secure?
No. The band is "not a security or compliance guarantee" (QCI-6.5-01), and the score is not a certificate of security (QCI-1.2-04).
Does a defensible posture mean we comply with the law?
No. QCI-QS1 does not determine regulatory compliance. Legal obligations depend on your jurisdiction and sector.
Can a nonconforming organization have a defensible posture?
It can make defensible statements if it discloses its nonconformities. It may say it was assessed against the standard but not that it conforms (QCI-1.2-02).
Sources
- QCI-QS1 Quantum Readiness and Post-Quantum Cryptography Governance Standard, Quantum Core Institute, Version 2.3, September 23, 2026, Clause 6.5. Supports: Score bands, including 81–100 Defensible readiness.
- QCI-QS1 Quantum Readiness and Post-Quantum Cryptography Governance Standard, Quantum Core Institute, Version 2.3, September 23, 2026, Clause 1.2. Supports: Conformance claims, assessment type and the score's meaning.
- QCI-QS1 Quantum Readiness and Post-Quantum Cryptography Governance Standard, Quantum Core Institute, Version 2.3, September 23, 2026, Clause 4.8. Supports: Evidence traceability.
Related learning
Before this
Back to Governance and assurance · All Knowledge Center topics
Page history
- Published
- Not yet recorded
- Standard edition
- QCI-QS1 v2.3 (September 23, 2026)
Cite this page
Quantum Core Institute. (n.d.). What is a defensible quantum-risk posture?. https://quantumcoreinstitute.com/learn/governance/defensible-quantum-risk-posture
Link: https://quantumcoreinstitute.com/learn/governance/defensible-quantum-risk-posture