Step 1: define the assessment perimeter
Decide whether the assessment covers a single business unit, a regulated entity, or the whole group. Define which classes of data, systems and supplier relationships are in scope. Without a clear perimeter, the output collapses into a generic awareness deck.
Step 2: inventory cryptographic dependencies
Catalogue every place classical asymmetric cryptography is used: TLS termination points, VPN gateways, code signing chains, document signing, HSMs, KMS, IoT firmware update keys and long term archive encryption. Map each entry to data lifetime and regulatory exposure.
Step 3: assess opportunity, not just threat
Quantum risk assessment is wasted if it only counts threats. The same exercise should identify two or three workloads where quantum or quantum inspired computation could deliver measurable commercial value over the next three years: optimisation, simulation, sampling or graph problems.
Step 4: rate maturity across five dimensions
Score your organisation 1 to 5 on each of:
- Cryptographic agility (can you change algorithms quickly).
- Vendor and supply chain readiness.
- Talent and internal capability.
- Data lifetime and regulatory exposure.
- Strategic positioning vs sector peers.
Step 5: produce a board ready output
The deliverable is a short, defensible pack: a one page heatmap, a 12 to 36 month roadmap, a named accountable owner, and a budget envelope. Anything longer than 20 slides usually means the assessment did not finish.
Frequently asked questions
How long does a quantum risk assessment take?
A focused engagement runs six to ten weeks for a mid sized UK enterprise, longer for a group with multiple regulated entities.
Who should sponsor it?
Joint sponsorship by the CISO and CIO works best. CISO owns the cryptography risk, CIO owns the opportunity and capability build.
Want a tailored view for your organisation?
Get in touch and qubion will match you with marketplace vendors who can map your quantum exposure, opportunities and a 12 to 36 month plan.
Find a vendor