Cookie Preferences

    We use cookies to ensure our website functions properly and to improve your experience. Essential cookies are always active. You can choose to enable other categories below. Review our cookie policy

    Definitional Guide

    Think Earlier.

    The quantum problem starts before the quantum computer arrives.

    What is Q-Risk Score?

    Q-Risk Score is a measurable, auditable metric ranging from 0-100 that quantifies an organization's quantum vulnerability and readiness posture. It provides boards, investors, and regulators with a standardized way to assess and communicate quantum preparedness.

    The Short Answer

    Q-Risk Score is to quantum risk what a credit score is to financial risk, a single, understandable number that summarizes complex risk factors into actionable intelligence for decision-makers.

    Why Does Q-Risk Score Exist?

    As quantum computing advances toward practical cryptographic capabilities, organizations face a new category of risk: the potential for quantum computers to break the encryption protecting their most sensitive data and systems. But how do you measure preparation for a threat that hasn't fully materialized?

    Q-Risk Score was developed to solve this problem. It provides a standardized framework for assessing, communicating, and improving quantum readiness, designed specifically for governance audiences who need clear metrics, not technical jargon.

    The Five Dimensions of Q-Risk

    QCI-QS1 v2.3 defines five weighted pillars:

    Governance and accountability
    20 points

    Ownership, decisions and oversight

    Crypto visibility and QASI completeness
    20 points

    Validated critical-system and critical-flow inventory

    Data longevity and exposure management
    20 points

    Long-lived data and trust exposure

    PQC migration readiness and crypto agility
    25 points

    Migration evidence and tested algorithm replacement

    Third-party readiness
    15 points

    Critical supplier responses and attestations

    How is Q-Risk Score Calculated?

    Each pillar receives an evidenced integer level from 0 to 5. The raw score is 4×P1 + 4×P2 + 4×P3 + 5×P4 + 3×P5. The final score is capped by any failed G60 inventory, G70 supplier, or G80 agility gate. The free questionnaire does not verify these requirements or produce a formal QCI-QS1 score.

    Score Interpretation

    • 0–19 Exposed: Limited evidence of an established readiness program.
    • 20–39 Behind: Initial awareness or defined elements with substantial gaps.
    • 40–59 Mobilizing: Evidence of coordinated preparation and early execution.
    • 60–80 Advancing: Progress with remaining gate, coverage, or execution limitations.
    • 81–100 Defensible readiness: Higher evidence-supported maturity with all score gates passed; not a security or compliance guarantee.

    Bands apply only to evidenced final scores, not to the self-reported screening estimate.

    Who Uses Q-Risk Score?

    Organizations

    Quantify baseline risk, prioritize investments, demonstrate preparedness to stakeholders

    Boards & Investors

    Governance reporting, due diligence, portfolio risk assessment

    Regulators

    Compliance verification, industry benchmarking, standards alignment

    Screen Your Quantum Risk Posture

    Use the free self-reported tool to identify areas for evidence review. Request a posture review for an independent assessment.