What NISQ Hardware Tells Us About Quantum Risk
- Brian Couzens
- 2 minutes ago
- 6 min read
Why today's limitations in noisy quantum machines still matter for assurance, PQC planning and governance
By Dr Clauden Higgsbottom
Published August 2026

Executive Summary
NISQ algorithms such as QAOA, VQE and other variational circuits have not yet demonstrated practical advantage on real-world workloads. Their strategic value is different: they provide measured evidence about noise, circuit depth, sampling cost, hybrid workflows and operational reliability.
That evidence helps organisations calibrate quantum-risk assumptions, prioritise PQC migration and design assurance controls without relying solely on vendor roadmaps.
Evidentiary, not computational
Measured hardware evidence
Evidence-based PQC scenarios
Engineering, not cryptanalysis
Assurance controls you can audit
A more realistic cost model
This article explains why NISQ-era experiments matter for CISOs, risk officers, regulators and board-level stakeholders, even though today's quantum devices cannot break deployed cryptography.
What This Does Not Mean
Before explaining what NISQ evidence does tell us, it is important to state clearly what it does not.
NISQ devices do not have the capability to break deployed public-key cryptography. Current machines lack the qubit counts, error rates and logical-qubit overhead required for cryptographically relevant algorithms such as Shor's algorithm.
NISQ performance does not provide a precise countdown to a cryptographically relevant quantum computer. Hardware benchmarks inform engineering assumptions; they do not produce a calendar date for fault-tolerant quantum computing.
Current limitations do not justify delaying PQC migration. The urgency of post-quantum cryptography is driven by asset lifetimes, data sensitivity and cryptographic dependency, not by whether today's devices can run a specific attack.
Vendor roadmaps should be treated as scenarios, not evidence of guaranteed timelines. Commercial projections are useful for planning, but they are not independent evidence of when cryptanalytic capability will arrive.
The correct use of NISQ evidence is to improve assumptions, stress-test scenarios and strengthen governance decisions.
NISQ Separates Measurement from Projection
Most quantum-risk narratives ultimately depend on the future availability of fault-tolerant machines. Today's hardware is noisy, shallow, unstable and hybrid, and it is where measurement rather than projection is possible.
Benchmarks show variational methods often struggle to scale beyond small or carefully selected problems. Gradients can become harder to resolve as circuit size and depth grow, and noise plus sampling overhead erode accuracy gains before useful depth is reached.
What hardware experiments reveal
How real qubits behave under load
How noise accumulates and destroys structure
How circuit depth limits useful computation
How hybrid optimisation loops degrade or stall
How measurement overhead dominates runtime
NISQ experiments are not a forecast of when fault-tolerant quantum computing arrives. They are measured evidence of the engineering constraints any future system must overcome.
For assurance and risk modelling, that distinction is critical. It separates what has been demonstrated from what is assumed.
NISQ Evidence Calibrates PQC Scenarios
PQC urgency is driven primarily by the future possibility of fault-tolerant quantum attacks, not by the current ability of NISQ devices to break cryptography.
Organisations must migrate because:
Some data has confidentiality lifetimes of decades.
Cryptographic dependencies are embedded in long-lived infrastructure.
Migration is slow, complex and risk-laden.
Regulatory expectations are increasing.
NISQ evidence does not change those fundamentals. It does, however, constrain the assumptions used to model quantum risk.
What NISQ evidence constrains
Assumptions about noise and control
Scaling and error-correction overhead
Logical-qubit resource requirements
Operational cost of running quantum workloads
The gap between demonstration and deployment
What should drive migration planning
Asset lifetime and data sensitivity
Cryptographic dependency mapping
Regulatory expectations
Credible quantum-computing scenarios
Urgency is justified. Panic is not. NISQ results give a reason to reject both complacency and unsupported countdowns.
Testbeds, Not Cryptanalytic Prototypes
A common misconception is that NISQ experiments are early prototypes of quantum cryptanalytic attacks. They are not.
NISQ systems cannot, by themselves, establish whether a cryptanalytic attack is feasible. They are early engineering testbeds whose observations feed into, rather than replace, fault-tolerant resource estimates.
What NISQ research does show
How noise and approximation error affect algebraic subroutines
How optimisation landscapes deform under scale
How circuit outputs drift under repeated measurement
How compilation and hardware constraints shape execution
What it still requires
Fault-tolerant resource estimates
A complete attack model
Target-specific cryptanalytic analysis
Validation of attack assumptions
This is engineering and benchmarking intelligence for crypto governance, not a demonstration of cryptanalytic capability.
For CISOs and risk officers, the implication is straightforward: NISQ results inform the plausibility of future attack models, but they do not determine them.
A Practical Quantum Assurance Control Model
NISQ workloads are among the first quantum workloads where operational assurance can be built and tested. Existing control principles still apply; what changes is the evidence an auditor inspects.
Existing control principles
Access control
Change management
Evidence retention
Risk acceptance
Third-party assurance
Quantum-specific evidence
Circuit and algorithm version
Backend, compiler and transpiler configuration
Calibration, error and shot-count data
Noise-mitigation method and comparators
Failure classification and reproducibility record
Provider and hardware provenance
These map to NIST CSF, ISO/IEC 27005 and QCaaS change governance, and give organisations a practical foundation for quantum assurance.
In practice, this means:
Every quantum experiment should be versioned and logged.
Hardware, backend and compilation settings should be recorded.
Calibration and error metrics should be retained as evidence.
Results should be accompanied by reproducibility records and failure classifications.
Provider and hardware provenance should be documented for third-party assurance.
This is not speculative governance. It is the kind of control framework that regulators and auditors already expect for emerging technologies.
A More Realistic Cost Model
Real organisations need realistic cost-risk models rather than vendor-roadmap assumptions.
NISQ workloads expose several cost drivers that are often omitted from high-level quantum-business cases.
What NISQ workloads expose
How sampling cost scales with target precision
How noise forces repeated runs
How hybrid loops multiply compute cost
How circuit depth limits capability
For many sampling-based estimators, achieving additive precision requires a sampling cost that scales approximately as O(1 over epsilon squared), before accounting for circuit depth, compilation, observable count, queue time and classical optimisation.
Actual cost also depends on the estimator, observable, circuit structure, shot allocation, error-mitigation method and hardware execution time.
This does not mean quantum computing will never be cost-effective. It does mean that early business cases must be stress-tested against measured sampling overhead, noise-induced repetition, hybrid-loop cost and depth limitations.
For CFOs and risk committees, the message is clear: treat early quantum cost models as scenarios, not forecasts.
The Baseline for Future Quantum Governance
Future assurance frameworks for quantum workloads, PQC migration and quantum risk will need to account for four things:
NISQ hardware behaviour
Measured limitations
Documented failure modes
Hybrid quantum-classical workflows
This is the world we are in right now. NISQ is the first rung of the quantum maturity ladder. Organisations should not skip it, and they can already build assurance, governance and PQC migration plans on top of it.
Organisations should not skip the first rung of the ladder.
From a governance perspective, this means:
Quantum-risk assumptions should be explicitly tied to measured hardware behaviour.
Limitations and failure modes should be documented and reviewed.
Hybrid workflows should be treated as the default operating model for the foreseeable future.
Assurance controls should be designed around observable, auditable evidence.
This is how quantum governance becomes operational rather than theoretical.
Blunt Summary
NISQ does not tell us exactly when quantum computers will threaten cryptography. It tells us which assumptions are already testable, and which governance decisions cannot responsibly wait.
Calibrated PQC scenarios
Grounded in measured hardware behaviour, not vendor roadmaps.
A defensible risk profile
Which attack assumptions hold, and which still require validation.
Auditable assurance
Controls and evidence that can be built and tested today.
NISQ systems are strategically valuable even though they are computationally limited. This is why governance and assurance work in this domain must run on evidence rather than hype.
Next Step: The Discovery Sprint
NISQ evidence does not reveal an organisation's cryptographic exposure by itself. That requires an inventory of cryptographic assets, data lifetimes, trust dependencies, supplier exposure and migration constraints.
The Discovery Sprint is a 20 to 30 day time-bounded diagnostic that converts those questions into an evidence-based migration pathway.
Questions it answers
Where is cryptography used?
Which data has the longest confidentiality lifetime?
What should be migrated first?
How is progress reported to the board?
Deliverables
Cryptographic asset and dependency map
Quantum-exposure risk assessment
Prioritised PQC migration roadmap
Built for
Critical infrastructure
Financial institutions
Government vendors and regulated suppliers
If your organisation cannot yet answer where its cryptography lives, the first step is visibility, not speculation.
Dr Clauden Higgsbottom is a Senior engineer with SITG-Consulting and post-quantum cryptography and technology governance. This article is based on the SITG briefing "What NISQ Hardware Tells Us About Quantum Risk." https://www.linkedin.com/posts/bcouzens_what-nisq-hardware-tells-us-about-quantum-ugcPost-7496038205981483008-lnFE/?utm_source=share&utm_medium=member_desktop&rcm=ACoAAABeKQsBN9AnJvvQ3fQ4HlWJFqy-p-elxdM




Comments