Implementation

    What should a quantum-risk board report contain?

    A quantum-risk board report states what was assessed and when, which edition of the standard applies, the main exposures, the evidence-backed readiness result including gate outcomes, gaps in evidence, supplier issues, decisions the board must take, the accountable owners and the next review. Under QCI-QS1 this is the quarterly governing-body insert. It must separate maturity improvement from verified reduction in exposure.

    New to this? Read What should boards know and ask about quantum risk? first. After this, continue with What evidence should an auditor expect for quantum readiness?.

    In one sentence: The report tells the board what is known, what is not, and what it must decide.

    Why it matters

    A report full of activity can hide unchanged exposure. QCI-QS1 says reporting shall not clear exposure because a plan or attestation exists (QCI-8.1-02).

    Required content (QCI-8.1-01)

    • Assessment boundary, date, edition and profile, and conformance status.
    • Pillar levels, raw and capped score (or why no total applies), band, gate outcomes and changes since last period.
    • Validated system and flow coverage, with numerators and denominators.
    • Unknown or out-of-date evidence and scope changes.
    • Principal confidentiality and verification exposures.
    • Production migration completion versus supplier or pilot capability.
    • Critical supplier readiness and exceptions.
    • Crypto-agility test coverage and limits.
    • Overdue milestones, failed tests, open high-impact findings and expiring exceptions.
    • Actions completed and planned; decisions on resources, priorities, acceptance or remediation.

    Illustrative outline

    This outline follows the informative Annex D template. Values are left as placeholders on purpose; they are not results from any organization.

    Illustrative board insert outline (no real data)
    SectionWhat to show
    Assessment identityScope, period, edition, assessor type (self or independent), conformance result
    ReadinessFive pillar levels, raw and final score, band, each gate result, change since last quarter
    VisibilitySystems and flows: validated count out of total; unknown and stale records
    ExposureTop confidentiality and verification risks; accepted residual risk
    ExecutionProduction changes accepted; tests run and failed; overdue milestones
    SuppliersCurrent adequate attestations versus missing or limited; top exceptions
    DecisionsWhat the board is asked to approve, owner, due date

    Reading it carefully

    • Counts of roadmaps, pilots or attestations are not counts of protected production services (Annex D).
    • A score of exactly 60, 70 or 80 does not mean the gate above it has passed (QCI-6.5-01).
    • Conformance status is reported separately from the score (QCI-1.2-04).

    What organizations should do

    1. Use the Annex D structure or map your existing risk pack to it.
    2. Show numerators and denominators, not percentages alone.
    3. List every decision requested with an owner and date.
    4. State material limitations and non-comparable trends.

    Evidence an auditor should expect

    Rows marked "QCI requirement" come from the standard. Rows marked "Editorial suggestion" are QCI's practical advice and are not requirements.

    Expected evidence
    ArtifactScopeOwnerCurrencyVerificationBasis
    Quarterly governing-body insertAssessment boundaryQuantum Risk OwnerAt least quarterlyCheck every QCI-8.1-01 element is presentQCI requirement (QCI-8.1-01)
    Archived score assessmentEach quarterQuantum Risk OwnerAt least quarterlyCheck evidence references, gate effects, nonconformitiesQCI requirement (QCI-6.5-01)

    How NIST or other primary authorities address it

    This concept originates with QCI in QCI-QS1. NIST and other standards bodies do not define or endorse it.

    How QCI-QS1 addresses it

    Clause 8 sets the mandatory content. Annex D is an informative template that may be built into an existing risk pack.

    QCI-QS1 v2.3 mappings
    RequirementClauseRelationshipPillarGate
    QCI-8.1-018.1explicit requirementP1—
    QCI-8.1-028.1explicit requirementP1—
    QCI-6.5-016.5explicit requirement——
    QCI-1.2-041.2explicit requirement——

    Common mistakes

    • Reporting a single score without gates, scope or conformance status.
    • Showing percentages without the counts behind them.
    • Presenting supplier roadmaps as protected services.

    Questions for the board

    • Did exposure actually fall this quarter, or did only documentation improve?
    • Which decisions in this report need our approval today?

    Questions

    Is there a required template?

    No. The content in Clause 8.1 is required; the Annex D template is informative and can be merged into an existing risk pack.

    Can the report show only the Q-Risk Score?

    No. It must also show gates, coverage, exposures, suppliers, decisions and conformance status, which is reported separately from the score (QCI-8.1-01, QCI-1.2-04).

    Is a sample available?

    QCI publishes a redacted sample governing-body insert with its board engagement description on the services page. It shows structure only.

    Sources

    1. QCI-QS1 Quantum Readiness and Post-Quantum Cryptography Governance Standard, Quantum Core Institute, Version 2.3, September 23, 2026, Clause 8. Supports: Governing-body reporting and decisions.
    2. QCI-QS1 Quantum Readiness and Post-Quantum Cryptography Governance Standard, Quantum Core Institute, Version 2.3, September 23, 2026, Annex D. Supports: Governing body insert template (informative).
    3. QCI-QS1 Quantum Readiness and Post-Quantum Cryptography Governance Standard, Quantum Core Institute, Version 2.3, September 23, 2026, Clause 6.5. Supports: Score bands, including 81–100 Defensible readiness.
    4. QCI-QS1 Quantum Readiness and Post-Quantum Cryptography Governance Standard, Quantum Core Institute, Version 2.3, September 23, 2026, Clause 1.2. Supports: Conformance claims, assessment type and the score's meaning.

    Back to Governance and assurance · All Knowledge Center topics

    Page history

    Published
    Not yet recorded
    Standard edition
    QCI-QS1 v2.3 (September 23, 2026)

    Cite this page

    Quantum Core Institute. (n.d.). What should a quantum-risk board report contain?. https://quantumcoreinstitute.com/learn/governance/quantum-risk-board-report

    Link: https://quantumcoreinstitute.com/learn/governance/quantum-risk-board-report