What should a quantum-risk board report contain?
A quantum-risk board report states what was assessed and when, which edition of the standard applies, the main exposures, the evidence-backed readiness result including gate outcomes, gaps in evidence, supplier issues, decisions the board must take, the accountable owners and the next review. Under QCI-QS1 this is the quarterly governing-body insert. It must separate maturity improvement from verified reduction in exposure.
New to this? Read What should boards know and ask about quantum risk? first. After this, continue with What evidence should an auditor expect for quantum readiness?.
In one sentence: The report tells the board what is known, what is not, and what it must decide.
Why it matters
A report full of activity can hide unchanged exposure. QCI-QS1 says reporting shall not clear exposure because a plan or attestation exists (QCI-8.1-02).
Required content (QCI-8.1-01)
- Assessment boundary, date, edition and profile, and conformance status.
- Pillar levels, raw and capped score (or why no total applies), band, gate outcomes and changes since last period.
- Validated system and flow coverage, with numerators and denominators.
- Unknown or out-of-date evidence and scope changes.
- Principal confidentiality and verification exposures.
- Production migration completion versus supplier or pilot capability.
- Critical supplier readiness and exceptions.
- Crypto-agility test coverage and limits.
- Overdue milestones, failed tests, open high-impact findings and expiring exceptions.
- Actions completed and planned; decisions on resources, priorities, acceptance or remediation.
Illustrative outline
This outline follows the informative Annex D template. Values are left as placeholders on purpose; they are not results from any organization.
| Section | What to show |
|---|---|
| Assessment identity | Scope, period, edition, assessor type (self or independent), conformance result |
| Readiness | Five pillar levels, raw and final score, band, each gate result, change since last quarter |
| Visibility | Systems and flows: validated count out of total; unknown and stale records |
| Exposure | Top confidentiality and verification risks; accepted residual risk |
| Execution | Production changes accepted; tests run and failed; overdue milestones |
| Suppliers | Current adequate attestations versus missing or limited; top exceptions |
| Decisions | What the board is asked to approve, owner, due date |
Reading it carefully
- Counts of roadmaps, pilots or attestations are not counts of protected production services (Annex D).
- A score of exactly 60, 70 or 80 does not mean the gate above it has passed (QCI-6.5-01).
- Conformance status is reported separately from the score (QCI-1.2-04).
What organizations should do
- Use the Annex D structure or map your existing risk pack to it.
- Show numerators and denominators, not percentages alone.
- List every decision requested with an owner and date.
- State material limitations and non-comparable trends.
Evidence an auditor should expect
Rows marked "QCI requirement" come from the standard. Rows marked "Editorial suggestion" are QCI's practical advice and are not requirements.
| Artifact | Scope | Owner | Currency | Verification | Basis |
|---|---|---|---|---|---|
| Quarterly governing-body insert | Assessment boundary | Quantum Risk Owner | At least quarterly | Check every QCI-8.1-01 element is present | QCI requirement (QCI-8.1-01) |
| Archived score assessment | Each quarter | Quantum Risk Owner | At least quarterly | Check evidence references, gate effects, nonconformities | QCI requirement (QCI-6.5-01) |
How NIST or other primary authorities address it
This concept originates with QCI in QCI-QS1. NIST and other standards bodies do not define or endorse it.
How QCI-QS1 addresses it
Clause 8 sets the mandatory content. Annex D is an informative template that may be built into an existing risk pack.
| Requirement | Clause | Relationship | Pillar | Gate |
|---|---|---|---|---|
| QCI-8.1-01 | 8.1 | explicit requirement | P1 | — |
| QCI-8.1-02 | 8.1 | explicit requirement | P1 | — |
| QCI-6.5-01 | 6.5 | explicit requirement | — | — |
| QCI-1.2-04 | 1.2 | explicit requirement | — | — |
Common mistakes
- Reporting a single score without gates, scope or conformance status.
- Showing percentages without the counts behind them.
- Presenting supplier roadmaps as protected services.
Questions for the board
- Did exposure actually fall this quarter, or did only documentation improve?
- Which decisions in this report need our approval today?
Questions
Is there a required template?
No. The content in Clause 8.1 is required; the Annex D template is informative and can be merged into an existing risk pack.
Can the report show only the Q-Risk Score?
No. It must also show gates, coverage, exposures, suppliers, decisions and conformance status, which is reported separately from the score (QCI-8.1-01, QCI-1.2-04).
Is a sample available?
QCI publishes a redacted sample governing-body insert with its board engagement description on the services page. It shows structure only.
Sources
- QCI-QS1 Quantum Readiness and Post-Quantum Cryptography Governance Standard, Quantum Core Institute, Version 2.3, September 23, 2026, Clause 8. Supports: Governing-body reporting and decisions.
- QCI-QS1 Quantum Readiness and Post-Quantum Cryptography Governance Standard, Quantum Core Institute, Version 2.3, September 23, 2026, Annex D. Supports: Governing body insert template (informative).
- QCI-QS1 Quantum Readiness and Post-Quantum Cryptography Governance Standard, Quantum Core Institute, Version 2.3, September 23, 2026, Clause 6.5. Supports: Score bands, including 81–100 Defensible readiness.
- QCI-QS1 Quantum Readiness and Post-Quantum Cryptography Governance Standard, Quantum Core Institute, Version 2.3, September 23, 2026, Clause 1.2. Supports: Conformance claims, assessment type and the score's meaning.
Related learning
Before this
Next
Back to Governance and assurance · All Knowledge Center topics
Page history
- Published
- Not yet recorded
- Standard edition
- QCI-QS1 v2.3 (September 23, 2026)
Cite this page
Quantum Core Institute. (n.d.). What should a quantum-risk board report contain?. https://quantumcoreinstitute.com/learn/governance/quantum-risk-board-report
Link: https://quantumcoreinstitute.com/learn/governance/quantum-risk-board-report