What is a quantum-risk assessment?
A quantum-risk assessment examines how ready an organization is for the move away from vulnerable cryptography. A screening is a quick, unverified indication. A self-assessment is the organization's own evidence-based determination against QCI-QS1. An independent assessment is one where a competent reviewer who did not build or run the controls examines the record and evidence. None of these is QCI certification.
New to this? Read Q-Risk Score and how scoring gates work first.
In one sentence: Screening points, self-assessment measures, independent assessment verifies.
Why it matters
The three produce different kinds of result. QCI-QS1 requires every claim to say whether it is a self-assessment or an independent assessment, so the two are never confused (QCI-1.2-03).
Three kinds of assessment
| Type | Who does it | Evidence | Useful when |
|---|---|---|---|
| Screening | Anyone, using a questionnaire | Answers only, not verified | Deciding where to start |
| Self-assessment | The organization | Its own conformance record and evidence | Running the program and reporting quarterly |
| Independent assessment | A competent reviewer who did not design, implement or operate the controls | Examined record and evidence; written statement | Board, customer or regulator reliance; Level 5 in any pillar (QCI-4.8-02) |
Is QCI-QS1 certification?
No. The standard states: "Use of this standard shall not be described as QCI certification unless separately authorized by an established QCI certification scheme" (QCI-1.2-03). QCI-P1 states that no such scheme exists at this version, and that an independent assessment is not QCI certification.
QCI-QS1 is not a government standard and has no government endorsement or accreditation. Organizations may say they were "assessed against" the standard, with nonconformities disclosed (QCI-1.2-02).
Independence and conflicts of interest
- An independent assessor did not design, implement or operate the controls and has no responsibility for the assessed outcome (QCI-QS1 Clause 3 definition).
- QCI-P1 excludes assessors who took part in producing the results or worked on the organization's program in the previous four quarters.
- QCI's own policy goes further: QCI does not issue an independent determination on its own readiness or implementation work, even after its 12-month cooling-off period. See the assessment independence policy.
What organizations should do
- Use the free screening to decide where to start.
- Run a self-assessment with a full conformance record.
- Commission independent assessment when others will rely on the result.
- Label every result with its assessment type.
Evidence an auditor should expect
Rows marked "QCI requirement" come from the standard. Rows marked "Editorial suggestion" are QCI's practical advice and are not requirements.
| Artifact | Scope | Owner | Currency | Verification | Basis |
|---|---|---|---|---|---|
| Conformance record | Every requirement in scope | Quantum Risk Owner | Each assessment | Check result, assessor and date per requirement | QCI requirement (QCI-1.2-01) |
| Assessor independence declaration | Each independent assessment | Assessor | Each engagement | Check no design, implementation or operating role | Editorial suggestion |
How NIST or other primary authorities address it
This concept originates with QCI in QCI-QS1. NIST and other standards bodies do not define or endorse it.
How QCI-QS1 addresses it
QCI-QS1 defines assessment types and claim wording. QCI-P1 explains independent assessment. QCI's independence policy sets the firm's own conflict rules.
| Requirement | Clause | Relationship | Pillar | Gate |
|---|---|---|---|---|
| QCI-1.2-03 | 1.2 | explicit requirement | — | — |
| QCI-1.2-02 | 1.2 | explicit requirement | — | — |
| QCI-1.2-01 | 1.2 | explicit requirement | — | — |
| QCI-4.8-02 | 4.8 | explicit requirement | — | — |
Common mistakes
- Calling a screening result a score.
- Calling an assessment a certification.
- Using a reviewer who helped build the controls as the independent assessor.
Questions for the board
- Which of our reported results are self-assessed, and which are independently assessed?
Questions
Can we say we are QCI certified?
No. Use of QCI-QS1 may not be described as QCI certification unless an established QCI certification scheme authorizes it (QCI-1.2-03), and none exists at this version (QCI-P1).
Is a self-assessment worth less?
It is a different kind of result. QCI-P1 calls both legitimate; the rule is that they are labeled and never confused.
Can the firm that helped us prepare also assess us?
Not under QCI's policy. QCI does not issue an independent determination on its own readiness or implementation work.
Sources
- QCI-QS1 Quantum Readiness and Post-Quantum Cryptography Governance Standard, Quantum Core Institute, Version 2.3, September 23, 2026, Clause 1.2. Supports: Conformance claims, assessment type and the score's meaning.
- QCI-P1 Independent Assessment under QCI-QS1, Quantum Core Institute, Overview publication aligned to QCI-QS1 v2.3. Supports: Self-assessment versus independent assessment; what an assessed result means; not certification.
- QCI-QS1 Quantum Readiness and Post-Quantum Cryptography Governance Standard, Quantum Core Institute, Version 2.3, September 23, 2026, Clause 3. Supports: Definition of independent assessor.
- QCI-QS1 Quantum Readiness and Post-Quantum Cryptography Governance Standard, Quantum Core Institute, Version 2.3, September 23, 2026, Clause 4.8. Supports: Assessor competence and sampling.
Related learning
Back to Governance and assurance · All Knowledge Center topics
Page history
- Published
- Not yet recorded
- Standard edition
- QCI-QS1 v2.3 (September 23, 2026)
Cite this page
Quantum Core Institute. (n.d.). What is a quantum-risk assessment?. https://quantumcoreinstitute.com/learn/governance/quantum-risk-assessment
Link: https://quantumcoreinstitute.com/learn/governance/quantum-risk-assessment