The Q-Risk Score is a 0–100 quantum risk metric scored across five weighted pillars, constrained by hard ceilings that prevent inflated posture claims. The methodology is published, auditable, and aligned to QCI-QS1.
Q-Risk Score = min( HardCeiling(controls), 0.25 × CryptographicExposure + 0.20 × GovernanceReadiness + 0.20 × TechnicalPreparedness + 0.20 × StrategicAlignment + 0.15 × OperationalResilience ) Each pillar is scored 0–100 from evidenced controls. HardCeiling enforces caps when foundational controls are absent.
The hard-ceiling operator is what separates Q-Risk from posture-only scoring models. A weighted sum alone allows organizations to compensate for missing foundations with cosmetic controls. The Q-Risk methodology refuses that trade.
Current cryptographic infrastructure vulnerability — share of RSA, ECC, and DH dependencies across identity, payments, and data systems.
Board oversight, accountable executive, documented quantum risk appetite, and integration into enterprise risk management.
Infrastructure and talent readiness to execute migration — crypto agility, CA/PKI modernization, and engineering capacity.
Integration of quantum risk into enterprise risk, vendor management, M&A diligence, and capital planning.
Incident response, crypto-failure playbooks, and continuity testing for cryptographic outages or forced algorithm migration.
Hard ceilings are non-negotiable caps that prevent inflated scores when foundational controls are absent. They are how Q-Risk stays defensible to auditors, boards, and regulators.
Without a cryptographic inventory, no other control can be reliably evidenced.
Governance accountability is a precondition for sustained program execution.
Third-party dependencies materially constrain enterprise migration timelines.
Inability to swap algorithms creates an unrecoverable operational risk.
The Q-Risk Score assessment takes about 15 minutes and produces a board-ready report with pillar breakdowns, applicable hard ceilings, and a prioritized remediation path.