top of page

What NISQ Hardware Tells Us About Quantum Risk

  • Writer: Brian Couzens
    Brian Couzens
  • 2 minutes ago
  • 6 min read

Why today's limitations in noisy quantum machines still matter for assurance, PQC planning and governance


By Dr Clauden Higgsbottom

Published August 2026


NISQ Hardware

Executive Summary


NISQ algorithms such as QAOA, VQE and other variational circuits have not yet demonstrated practical advantage on real-world workloads. Their strategic value is different: they provide measured evidence about noise, circuit depth, sampling cost, hybrid workflows and operational reliability.

That evidence helps organisations calibrate quantum-risk assumptions, prioritise PQC migration and design assurance controls without relying solely on vendor roadmaps.

Evidentiary, not computational

  • Measured hardware evidence

  • Evidence-based PQC scenarios

  • Engineering, not cryptanalysis

  • Assurance controls you can audit

  • A more realistic cost model

This article explains why NISQ-era experiments matter for CISOs, risk officers, regulators and board-level stakeholders, even though today's quantum devices cannot break deployed cryptography.


  1. What This Does Not Mean

Before explaining what NISQ evidence does tell us, it is important to state clearly what it does not.

NISQ devices do not have the capability to break deployed public-key cryptography. Current machines lack the qubit counts, error rates and logical-qubit overhead required for cryptographically relevant algorithms such as Shor's algorithm.

NISQ performance does not provide a precise countdown to a cryptographically relevant quantum computer. Hardware benchmarks inform engineering assumptions; they do not produce a calendar date for fault-tolerant quantum computing.

Current limitations do not justify delaying PQC migration. The urgency of post-quantum cryptography is driven by asset lifetimes, data sensitivity and cryptographic dependency, not by whether today's devices can run a specific attack.

Vendor roadmaps should be treated as scenarios, not evidence of guaranteed timelines. Commercial projections are useful for planning, but they are not independent evidence of when cryptanalytic capability will arrive.

The correct use of NISQ evidence is to improve assumptions, stress-test scenarios and strengthen governance decisions.


  1. NISQ Separates Measurement from Projection

Most quantum-risk narratives ultimately depend on the future availability of fault-tolerant machines. Today's hardware is noisy, shallow, unstable and hybrid, and it is where measurement rather than projection is possible.

Benchmarks show variational methods often struggle to scale beyond small or carefully selected problems. Gradients can become harder to resolve as circuit size and depth grow, and noise plus sampling overhead erode accuracy gains before useful depth is reached.

What hardware experiments reveal

  • How real qubits behave under load

  • How noise accumulates and destroys structure

  • How circuit depth limits useful computation

  • How hybrid optimisation loops degrade or stall

  • How measurement overhead dominates runtime

NISQ experiments are not a forecast of when fault-tolerant quantum computing arrives. They are measured evidence of the engineering constraints any future system must overcome.

For assurance and risk modelling, that distinction is critical. It separates what has been demonstrated from what is assumed.


  1. NISQ Evidence Calibrates PQC Scenarios

PQC urgency is driven primarily by the future possibility of fault-tolerant quantum attacks, not by the current ability of NISQ devices to break cryptography.

Organisations must migrate because:

  • Some data has confidentiality lifetimes of decades.

  • Cryptographic dependencies are embedded in long-lived infrastructure.

  • Migration is slow, complex and risk-laden.

  • Regulatory expectations are increasing.

NISQ evidence does not change those fundamentals. It does, however, constrain the assumptions used to model quantum risk.

What NISQ evidence constrains

  • Assumptions about noise and control

  • Scaling and error-correction overhead

  • Logical-qubit resource requirements

  • Operational cost of running quantum workloads

  • The gap between demonstration and deployment

What should drive migration planning

  • Asset lifetime and data sensitivity

  • Cryptographic dependency mapping

  • Regulatory expectations

  • Credible quantum-computing scenarios

Urgency is justified. Panic is not. NISQ results give a reason to reject both complacency and unsupported countdowns.


  1. Testbeds, Not Cryptanalytic Prototypes

A common misconception is that NISQ experiments are early prototypes of quantum cryptanalytic attacks. They are not.

NISQ systems cannot, by themselves, establish whether a cryptanalytic attack is feasible. They are early engineering testbeds whose observations feed into, rather than replace, fault-tolerant resource estimates.

What NISQ research does show

  • How noise and approximation error affect algebraic subroutines

  • How optimisation landscapes deform under scale

  • How circuit outputs drift under repeated measurement

  • How compilation and hardware constraints shape execution

What it still requires

  • Fault-tolerant resource estimates

  • A complete attack model

  • Target-specific cryptanalytic analysis

  • Validation of attack assumptions

This is engineering and benchmarking intelligence for crypto governance, not a demonstration of cryptanalytic capability.

For CISOs and risk officers, the implication is straightforward: NISQ results inform the plausibility of future attack models, but they do not determine them.


  1. A Practical Quantum Assurance Control Model

NISQ workloads are among the first quantum workloads where operational assurance can be built and tested. Existing control principles still apply; what changes is the evidence an auditor inspects.

Existing control principles

  • Access control

  • Change management

  • Evidence retention

  • Risk acceptance

  • Third-party assurance

Quantum-specific evidence

  • Circuit and algorithm version

  • Backend, compiler and transpiler configuration

  • Calibration, error and shot-count data

  • Noise-mitigation method and comparators

  • Failure classification and reproducibility record

  • Provider and hardware provenance

These map to NIST CSF, ISO/IEC 27005 and QCaaS change governance, and give organisations a practical foundation for quantum assurance.

In practice, this means:

  • Every quantum experiment should be versioned and logged.

  • Hardware, backend and compilation settings should be recorded.

  • Calibration and error metrics should be retained as evidence.

  • Results should be accompanied by reproducibility records and failure classifications.

  • Provider and hardware provenance should be documented for third-party assurance.

This is not speculative governance. It is the kind of control framework that regulators and auditors already expect for emerging technologies.


  1. A More Realistic Cost Model

Real organisations need realistic cost-risk models rather than vendor-roadmap assumptions.

NISQ workloads expose several cost drivers that are often omitted from high-level quantum-business cases.

What NISQ workloads expose

  • How sampling cost scales with target precision

  • How noise forces repeated runs

  • How hybrid loops multiply compute cost

  • How circuit depth limits capability

For many sampling-based estimators, achieving additive precision requires a sampling cost that scales approximately as O(1 over epsilon squared), before accounting for circuit depth, compilation, observable count, queue time and classical optimisation.

Actual cost also depends on the estimator, observable, circuit structure, shot allocation, error-mitigation method and hardware execution time.

This does not mean quantum computing will never be cost-effective. It does mean that early business cases must be stress-tested against measured sampling overhead, noise-induced repetition, hybrid-loop cost and depth limitations.

For CFOs and risk committees, the message is clear: treat early quantum cost models as scenarios, not forecasts.


  1. The Baseline for Future Quantum Governance

Future assurance frameworks for quantum workloads, PQC migration and quantum risk will need to account for four things:

  • NISQ hardware behaviour

  • Measured limitations

  • Documented failure modes

  • Hybrid quantum-classical workflows

This is the world we are in right now. NISQ is the first rung of the quantum maturity ladder. Organisations should not skip it, and they can already build assurance, governance and PQC migration plans on top of it.

Organisations should not skip the first rung of the ladder.

From a governance perspective, this means:

  • Quantum-risk assumptions should be explicitly tied to measured hardware behaviour.

  • Limitations and failure modes should be documented and reviewed.

  • Hybrid workflows should be treated as the default operating model for the foreseeable future.

  • Assurance controls should be designed around observable, auditable evidence.

This is how quantum governance becomes operational rather than theoretical.


  1. Blunt Summary

NISQ does not tell us exactly when quantum computers will threaten cryptography. It tells us which assumptions are already testable, and which governance decisions cannot responsibly wait.

Calibrated PQC scenarios

Grounded in measured hardware behaviour, not vendor roadmaps.

A defensible risk profile

Which attack assumptions hold, and which still require validation.

Auditable assurance

Controls and evidence that can be built and tested today.


NISQ systems are strategically valuable even though they are computationally limited. This is why governance and assurance work in this domain must run on evidence rather than hype.

  1. Next Step: The Discovery Sprint

NISQ evidence does not reveal an organisation's cryptographic exposure by itself. That requires an inventory of cryptographic assets, data lifetimes, trust dependencies, supplier exposure and migration constraints.

The Discovery Sprint is a 20 to 30 day time-bounded diagnostic that converts those questions into an evidence-based migration pathway.

Questions it answers

  • Where is cryptography used?

  • Which data has the longest confidentiality lifetime?

  • What should be migrated first?

  • How is progress reported to the board?

Deliverables

  • Cryptographic asset and dependency map

  • Quantum-exposure risk assessment

  • Prioritised PQC migration roadmap

Built for

  • Critical infrastructure

  • Financial institutions

  • Government vendors and regulated suppliers


If your organisation cannot yet answer where its cryptography lives, the first step is visibility, not speculation.


Dr Clauden Higgsbottom is a Senior engineer with SITG-Consulting and post-quantum cryptography and technology governance. This article is based on the SITG briefing "What NISQ Hardware Tells Us About Quantum Risk." https://www.linkedin.com/posts/bcouzens_what-nisq-hardware-tells-us-about-quantum-ugcPost-7496038205981483008-lnFE/?utm_source=share&utm_medium=member_desktop&rcm=ACoAAABeKQsBN9AnJvvQ3fQ4HlWJFqy-p-elxdM




 
 
 

Comments


bottom of page