Decision

    What is a quantum-risk assessment?

    A quantum-risk assessment examines how ready an organization is for the move away from vulnerable cryptography. A screening is a quick, unverified indication. A self-assessment is the organization's own evidence-based determination against QCI-QS1. An independent assessment is one where a competent reviewer who did not build or run the controls examines the record and evidence. None of these is QCI certification.

    New to this? Read Q-Risk Score and how scoring gates work first.

    In one sentence: Screening points, self-assessment measures, independent assessment verifies.

    Why it matters

    The three produce different kinds of result. QCI-QS1 requires every claim to say whether it is a self-assessment or an independent assessment, so the two are never confused (QCI-1.2-03).

    Three kinds of assessment

    Screening, self-assessment and independent assessment
    TypeWho does itEvidenceUseful when
    ScreeningAnyone, using a questionnaireAnswers only, not verifiedDeciding where to start
    Self-assessmentThe organizationIts own conformance record and evidenceRunning the program and reporting quarterly
    Independent assessmentA competent reviewer who did not design, implement or operate the controlsExamined record and evidence; written statementBoard, customer or regulator reliance; Level 5 in any pillar (QCI-4.8-02)

    Is QCI-QS1 certification?

    No. The standard states: "Use of this standard shall not be described as QCI certification unless separately authorized by an established QCI certification scheme" (QCI-1.2-03). QCI-P1 states that no such scheme exists at this version, and that an independent assessment is not QCI certification.

    QCI-QS1 is not a government standard and has no government endorsement or accreditation. Organizations may say they were "assessed against" the standard, with nonconformities disclosed (QCI-1.2-02).

    Independence and conflicts of interest

    • An independent assessor did not design, implement or operate the controls and has no responsibility for the assessed outcome (QCI-QS1 Clause 3 definition).
    • QCI-P1 excludes assessors who took part in producing the results or worked on the organization's program in the previous four quarters.
    • QCI's own policy goes further: QCI does not issue an independent determination on its own readiness or implementation work, even after its 12-month cooling-off period. See the assessment independence policy.

    What organizations should do

    1. Use the free screening to decide where to start.
    2. Run a self-assessment with a full conformance record.
    3. Commission independent assessment when others will rely on the result.
    4. Label every result with its assessment type.

    Evidence an auditor should expect

    Rows marked "QCI requirement" come from the standard. Rows marked "Editorial suggestion" are QCI's practical advice and are not requirements.

    Expected evidence
    ArtifactScopeOwnerCurrencyVerificationBasis
    Conformance recordEvery requirement in scopeQuantum Risk OwnerEach assessmentCheck result, assessor and date per requirementQCI requirement (QCI-1.2-01)
    Assessor independence declarationEach independent assessmentAssessorEach engagementCheck no design, implementation or operating roleEditorial suggestion

    How NIST or other primary authorities address it

    This concept originates with QCI in QCI-QS1. NIST and other standards bodies do not define or endorse it.

    How QCI-QS1 addresses it

    QCI-QS1 defines assessment types and claim wording. QCI-P1 explains independent assessment. QCI's independence policy sets the firm's own conflict rules.

    QCI-QS1 v2.3 mappings
    RequirementClauseRelationshipPillarGate
    QCI-1.2-031.2explicit requirement——
    QCI-1.2-021.2explicit requirement——
    QCI-1.2-011.2explicit requirement——
    QCI-4.8-024.8explicit requirement——

    Common mistakes

    • Calling a screening result a score.
    • Calling an assessment a certification.
    • Using a reviewer who helped build the controls as the independent assessor.

    Questions for the board

    • Which of our reported results are self-assessed, and which are independently assessed?

    Questions

    Can we say we are QCI certified?

    No. Use of QCI-QS1 may not be described as QCI certification unless an established QCI certification scheme authorizes it (QCI-1.2-03), and none exists at this version (QCI-P1).

    Is a self-assessment worth less?

    It is a different kind of result. QCI-P1 calls both legitimate; the rule is that they are labeled and never confused.

    Can the firm that helped us prepare also assess us?

    Not under QCI's policy. QCI does not issue an independent determination on its own readiness or implementation work.

    Sources

    1. QCI-QS1 Quantum Readiness and Post-Quantum Cryptography Governance Standard, Quantum Core Institute, Version 2.3, September 23, 2026, Clause 1.2. Supports: Conformance claims, assessment type and the score's meaning.
    2. QCI-P1 Independent Assessment under QCI-QS1, Quantum Core Institute, Overview publication aligned to QCI-QS1 v2.3. Supports: Self-assessment versus independent assessment; what an assessed result means; not certification.
    3. QCI-QS1 Quantum Readiness and Post-Quantum Cryptography Governance Standard, Quantum Core Institute, Version 2.3, September 23, 2026, Clause 3. Supports: Definition of independent assessor.
    4. QCI-QS1 Quantum Readiness and Post-Quantum Cryptography Governance Standard, Quantum Core Institute, Version 2.3, September 23, 2026, Clause 4.8. Supports: Assessor competence and sampling.

    Back to Governance and assurance · All Knowledge Center topics

    Page history

    Published
    Not yet recorded
    Standard edition
    QCI-QS1 v2.3 (September 23, 2026)

    Cite this page

    Quantum Core Institute. (n.d.). What is a quantum-risk assessment?. https://quantumcoreinstitute.com/learn/governance/quantum-risk-assessment

    Link: https://quantumcoreinstitute.com/learn/governance/quantum-risk-assessment