All articles
    Strategy· 16 May 2026· 7 min read

    Quantum risk assessment: a five step framework for UK enterprises

    Quantum risk is not just a cryptography problem. It is a strategic risk that touches data, supply chain, regulatory exposure, talent and compute strategy. A good quantum risk assessment gives the board a single defensible view of where the organisation stands today and what action is required in the next 12 to 36 months.

    Step 1: define the assessment perimeter

    Decide whether the assessment covers a single business unit, a regulated entity, or the whole group. Define which classes of data, systems and supplier relationships are in scope. Without a clear perimeter, the output collapses into a generic awareness deck.

    Step 2: inventory cryptographic dependencies

    Catalogue every place classical asymmetric cryptography is used: TLS termination points, VPN gateways, code signing chains, document signing, HSMs, KMS, IoT firmware update keys and long term archive encryption. Map each entry to data lifetime and regulatory exposure.

    Step 3: assess opportunity, not just threat

    Quantum risk assessment is wasted if it only counts threats. The same exercise should identify two or three workloads where quantum or quantum inspired computation could deliver measurable commercial value over the next three years: optimisation, simulation, sampling or graph problems.

    Step 4: rate maturity across five dimensions

    Score your organisation 1 to 5 on each of:

    • Cryptographic agility (can you change algorithms quickly).
    • Vendor and supply chain readiness.
    • Talent and internal capability.
    • Data lifetime and regulatory exposure.
    • Strategic positioning vs sector peers.

    Step 5: produce a board ready output

    The deliverable is a short, defensible pack: a one page heatmap, a 12 to 36 month roadmap, a named accountable owner, and a budget envelope. Anything longer than 20 slides usually means the assessment did not finish.

    Frequently asked questions

    How long does a quantum risk assessment take?

    A focused engagement runs six to ten weeks for a mid sized UK enterprise, longer for a group with multiple regulated entities.

    Who should sponsor it?

    Joint sponsorship by the CISO and CIO works best. CISO owns the cryptography risk, CIO owns the opportunity and capability build.

    Want a tailored view for your organisation?

    Get in touch and qubion will match you with marketplace vendors who can map your quantum exposure, opportunities and a 12 to 36 month plan.

    Find a vendor