Cookie Preferences

    We use cookies to ensure our website functions properly and to improve your experience. Essential cookies are always active. You can choose to enable other categories below. Review our cookie policy

    Press and Media

    Think Earlier.

    The quantum problem starts before the quantum computer arrives.

    For reporters covering the quantum transition

    The Quantum Core Institute is a quantum risk governance standards body. We publish QCI-QS1, the free standard that lets a board score its quantum exposure 0 to 100.

    On deadline? Email press@quantumcoreinstitute.com. We respond the same day.

    Story angles

    What we can speak to

    Pre-packaged angles, each with a spokesperson ready and a source you can cite.

    01

    The identity inversionLead

    The quantum conversation prices one exposure: data getting read. The systemic exposure is the other one. Quantum capability breaks asymmetric cryptography, which is the layer that proves who did what. Certificate chains, signing keys, customer authentication, and the machine credentials nobody has counted. A decrypted archive has a damage estimate. A forged signature inside a settlement system does not. Confidentiality failures are recoverable. Authentication failures are systemic, because a forged past cannot be un-signed. Institutions pricing quantum as an encryption problem are budgeting the cheapest third of it.

    QCI-QS1 v2.3 identity workstream
    02

    Three exposures, not one

    Quantum risk is three problems with three different clocks. Data risk runs on data lifetime and started when the collection did. Identity risk runs on re-issuance lead time, and certificate migration takes years. Payment risk runs on settlement infrastructure upgrade cycles, the slowest in the building. They carry different owners, different budget lines, and different failure costs. Institutions that budget them as one encryption problem reliably fund the most discussable exposure instead of the most expensive one. The useful question is not how exposed are we. It is which surface is late here.

    The Q-Risk model
    03

    The standard is free

    QCI-QS1 is published in full at no cost, with no form wall. That is a methodology decision rather than a marketing one. A readiness score means something only if institutions can be compared against the same rubric, and comparability requires adoption. A standard behind a paywall does not get adopted, it gets cited in sales decks. The standard is free. The judgment about a specific institution is the engagement. That separation is also why QCI has no incentive to inflate the threat, which is the first question a reporter should put to any source in this sector.

    Mapped to DORA, NIS2, NCUA, HIPAA, FFIEC
    04

    The calendar got real

    Quantum readiness acquired a regulatory skeleton in under two years. NIST finalized FIPS 203, 204, and 205 on August 13, 2024. The EU's first coordinated milestone lands December 31, 2026. CNSA 2.0 binds new national security system acquisitions from January 1, 2027. The UK NCSC published a ladder of 2028, 2031, and 2035. Governments on three continents converged on the same decade without coordinating with anyone's budget cycle. Every regime that prescribes a first step prescribes the same one, a cryptographic inventory. QCI tracks 31 references on the Regulatory Radar, each labeled with its actual legal force and reviewed quarterly.

    The Regulatory Radar, 31 tracked references
    05

    Harvest now, decrypt later

    Adversaries collect encrypted data today to decrypt it once capability arrives. Any data that must stay confidential longer than a migration takes is already exposed, regardless of when that capability lands. The planning arithmetic needs no Q-Day prediction. It is data lifetime plus migration time, measured against time to capability, and for long-lived records that inequality can already fail. The Federal Reserve put the irreversibility of this exposure on its research record in September 2025, concluding that previously recorded distributed-ledger data can remain vulnerable even after future post-quantum upgrades. This is the exposure that gets headlines. It is also the bounded one.

    Federal Reserve FEDS 2025-093
    06

    The machine identity blind spot

    Service accounts, API keys, signing keys, certificates, and now AI agents are the fastest growing identity population in any institution and the least counted. Discovery tooling finds algorithms in code. It does not find credentials in operations, which is where the exposure concentrates. Most cryptographic inventories in circulation today are, in operational terms, theater. They were built by scanners that cannot see the certificate estate or the vendor-held keys. One question separates a real inventory from a reported one: did it count algorithms in code, or credentials in operations.

    The QASI inventory
    07

    The double migration

    Organizations rolling out passkeys, replacing IAM platforms, or running credential re-issuance programs are on track to issue the same credentials twice. The identity program ships on its own schedule with its own inventory. The PQC program arrives later and re-issues the same estate. Neither team reconciles the two, and the second bill is avoidable in full. The fix costs nothing and has to happen early: one shared inventory, one re-issuance plan, and one named owner for the seam, decided before the identity program ships.

    QCI-QS1 v2.3 coordination clause
    08

    Community institutions have a one-quarter version

    NCUA's 2026 supervisory priorities never say quantum. They emphasize operational resilience, payment systems, cybersecurity, and vendor oversight, which is everything quantum readiness depends on. The examiner questions are already legible, and they are inventory, ownership, and timeline. Community banks and credit unions do not need an enterprise program to answer them. They need a named owner, an inventory of critical systems, a data-lifetime map, and roadmap requests to the core processor. That is one quarter of work. It is the version of this story that reaches the most institutions and gets covered the least.

    NCUA 2026 supervisory priorities
    For accurate coverage

    Key messages and boilerplate

    Approved copy for citation and the correct way to refer to us on first reference.

    Approved boilerplate

    The Quantum Core Institute (QCI) is a quantum risk governance standards body and advisory practice based in Washington, DC. It publishes QCI-QS1, the free, citeable standard for measuring and scoring an organization's quantum exposure, and runs assessments that apply it. QCI works on the demand side of quantum readiness: governance, measurement, and board-level evidence.

    How to refer to us
    • First reference
      Quantum Core Institute in full, not to be confused with unrelated firms using the name QuantumCore.
    • The standard
      QCI-QS1
    • The score
      Q-Risk Score
    Spokesperson

    On the record

    Available for interviews, background briefings, and expert comment on quantum risk, cryptographic migration, and board-level governance.

    Founder and Chief Executive Officer

    Bryant Nielson

    He founded the Quantum Core Institute to operationalize federal and international post-quantum standards for regulated institutions.

    He authored Q-Day Clock: The Quantum Threat Hiding in Plain Sight, a plain language account of the cryptographic transition and its board-level implications.

    He briefs boards, risk committees, and the supervisory community on quantum exposure, governance, and defensible migration planning.

    Credentials and recent platforms
    • Keynote, EIC Berlin: Identity Inversion.
    • Established publishing relationship with KuppingerCole.
    • Author, Q-Day Clock.
    Available for
    Written commentaryLive and recorded interviewsBackground briefingsPanels and keynotes
    Press releases

    Official announcements

    Statements issued by the Quantum Core Institute. Each release is quotable in full and dated at publication.

    No press releases yet. Announcements will be posted here as they are issued. Ask to be added to the distribution list.

    Press kit

    Everything you need to file

    Reports, standards, logos, and headshots. Please style the brand as QCI² in body copy.

    State of Quantum Readiness 2026

    Our annual report, 23 pages, fully sourced.

    PDF · 4.8 MB Download
    Regulatory Radar 2026

    31 tracked references by legal force, reviewed quarterly.

    PDF · 2.1 MB Download
    QCI-QS1 v2.3

    The free governance standard.

    PDF · 1.6 MB Download
    Logo pack

    Navy, white knockout, and mono.

    ZIP · 3.2 MB Download
    Spokesperson headshots

    High resolution.

    ZIP · 12.4 MB Download
    Fact sheet

    One page: who we are, what we measure, the key numbers.

    PDF · 480 KB Download
    Facts, with sources

    Cite with confidence

    Every figure below traces to a primary source, labeled with its real status. Final means final. Proposed means proposed.

    • FIPS 203, 204, and 205 were finalized August 13, 2024.

      Source: NIST.

      Final
    • EU coordinated PQC roadmap, Milestone 1: December 31, 2026.

      Source: European Commission and NIS Cooperation Group.

      Final
    • CNSA 2.0 binds new national security acquisitions from January 1, 2027.

      Source: NSA.

      Final
    • BIS Project Leap ran post-quantum signatures on live-like settlement transfers, December 2025.

      Source: Bank for International Settlements.

      Reported
    • Cryptographically relevant quantum computer probability, 19 to 34 percent by 2034. Expert survey estimate, not a forecast.

      Source: Global Risk Institute, via Citi Institute, January 2026.

      Estimate
    • NIST IR 8547 points to 2030 deprecation and 2035 disallowance.

      Source: NIST.

      Draft
    Coverage

    Recent and upcoming coverage

    Selected articles, interviews, and analyst mentions that reference QCI-QS1 and the Quantum Core Institute.

    Coverage links posted here as they publish.

    Upcoming

    On the calendar

    Dates reporters can plan around. Confirmed events and regulatory milestones.

    December 9, 2026

    State of Quantum Readiness Summit

    Rosslyn, Virginia

    Press passes available.

    December 31, 2026

    EU PQC roadmap, Milestone 1

    European Union

    First coordinated deadline under the EU post-quantum roadmap.

    January 1, 2027

    CNSA 2.0 acquisition requirement in force

    United States

    Binds new national security systems acquisitions.

    Contact

    Media inquiries

    For interviews, expert comment, briefings, and press kit access. We reply the same day on weekdays.