Pillar 1: Governance and accountability
Pillar 1 measures whether quantum risk is actually governed: a named sponsor and Quantum Risk Owner, approved policy and risk appetite, a resourced roadmap, a working quarterly cycle and governing-body oversight. It is levelled from 0 to 5 against Clause 6.6 of QCI-QS1 v2.3 and contributes 4 points per level, up to 20 of the 100 points.
New to this? Read Q-Risk Score and how scoring gates work first. After this, continue with Pillar 2: Crypto visibility and QASI completeness.
In one sentence: P1 asks whether someone owns quantum risk and whether the oversight cycle actually runs.
How this pillar differs from quantum risk governance in general
Quantum risk governance is the broad management discipline: who owns the risk, how decisions are made and how the governing body is informed. Pillar 1 is narrower. It is a scored assessment of whether those arrangements exist and are evidenced inside a defined assessment boundary, levelled from 0 to 5 against the Clause 6.6 rubric.
An organization can describe a sound governance model and still receive a low P1 level if approvals, minutes, roadmaps or reporting records are missing, stale or contradictory. The pillar measures evidenced maturity, not intent. Practical guidance on setting up governance belongs to the governance and board topics, not to this scoring page.
Evidence required at each level
Levels are cumulative. An organization receives the highest level for which every criterion at that level and all lower positive levels is supported. Unsupported, contradictory or stale evidence fails the affected criterion, and fractional levels are not allowed (QCI-6.1-01).
| Level | Required evidence |
|---|---|
| 0 | One or more level 1 criteria are unsupported. |
| 1 | Named sponsor and Quantum Risk Owner; documented initial scope and initial quantum-risk entry. |
| 2 | Approved policy, roles, risk appetite, obligations register, resourced roadmap and exception process; a completed governing-body briefing. |
| 3 | At least one quarterly inventory–assessment–action–report cycle completed; roadmap actions have recorded outcomes; incident procedures cover all applicable Clause 4.4 scenarios. |
| 4 | Two consecutive quarterly cycles completed on time; every overdue action and resource shortfall escalated with an authorized decision; incident exercise coverage current and corrective actions controlled. |
| 5 | Independent review confirms all P1 criteria and evidence traceability; no overdue high-impact governance nonconformity; governing body has reviewed program effectiveness and approved resulting actions. |
How NIST or other primary authorities address it
This concept originates with QCI in QCI-QS1. NIST and other standards bodies do not define or endorse it.
How QCI-QS1 addresses it
P1 is levelled against the rubric in Clause 6.6. In the score formula it is L1, weighted 4. Level 5 needs an independent review of the pillar within the previous 12 months and after any invalidating change.
| Requirement | Clause | Relationship | Pillar | Gate |
|---|---|---|---|---|
| QCI-6.6-01 | 6.6 | explicit requirement | P1 | — |
| QCI-6.1-01 | 6.1 | explicit requirement | — | — |
| QCI-6.1-02 | 6.1 | explicit requirement | — | — |
| QCI-4.8-02 | 4.8 | supporting evidence | P1 | — |
| QCI-4.8-01 | 4.8 | supporting evidence | — | — |
Common mistakes
- Treating an approved policy as level 3. Level 3 needs a completed quarterly cycle with recorded outcomes.
- Running cycles late. Level 4 needs two consecutive quarterly cycles completed on time.
- Claiming level 5 without an independent review of the pillar in the past 12 months (QCI-4.8-02).
Questions for the board
- Who is our named Quantum Risk Owner, and when did we last receive their report?
- Have the last two quarterly cycles been completed on time?
Questions
How many points can Pillar 1 contribute?
Up to 20. Each level adds 4 points in the formula R = 4×L1 + 4×L2 + 4×L3 + 5×L4 + 3×L5 (QCI-6.1-02).
Can a pillar be marked not applicable?
Only where its entire subject population is demonstrably absent and that absence is independently checked. Weight is not redistributed, and no 0–100 total or band is published while a pillar is not applicable (QCI-6.1-03).
Can a strong policy alone reach level 3?
No. Level 3 needs at least one completed quarterly inventory–assessment–action–report cycle, recorded roadmap outcomes and incident procedures covering the applicable Clause 4.4 scenarios (QCI-6.6-01).
Sources
- QCI-QS1 Quantum Readiness and Post-Quantum Cryptography Governance Standard, Quantum Core Institute, Version 2.3, September 23, 2026, Clause 6.6. Supports: P1 level criteria.
- QCI-QS1 Quantum Readiness and Post-Quantum Cryptography Governance Standard, Quantum Core Institute, Version 2.3, September 23, 2026, Clause 6.1. Supports: Levels and score formula.
- QCI-QS1 Quantum Readiness and Post-Quantum Cryptography Governance Standard, Quantum Core Institute, Version 2.3, September 23, 2026, Clause 4.8. Supports: Evidence and independent review.
Related learning
Before this
Back to QCI-QS1 scoring: pillars and gates · All Knowledge Center topics
Page history
- Published
- Not yet recorded
- Standard edition
- QCI-QS1 v2.3 (September 23, 2026)
Cite this page
Quantum Core Institute. (n.d.). Pillar 1: Governance and accountability. https://quantumcoreinstitute.com/learn/qci-qs1/governance-accountability-pillar
Link: https://quantumcoreinstitute.com/learn/qci-qs1/governance-accountability-pillar