Quantum Academy begins operations on September 15, 2026. Enrollment opens soon.
Skip to content

Geopolitics and Supply Chains

The Four Capabilities an Alliance Cannot Give You

Marin Ivezic13 min read

A superconducting quantum computer installed in Europe this year is a multinational object before anyone powers it on. The dilution refrigerator that holds the processor near 10 millikelvin was probably built by Bluefors in Finland. The processor may have been fabricated in the Netherlands. The control electronics generating the microwave pulses likely came from Zurich Instruments in Switzerland or Qblox in Delft, and the software stack was assembled from open-source projects with contributors on three continents. The machine stands on one country’s laboratory floor, and in engineering terms it belongs to a coalition.

That fact rules out one definition of quantum sovereignty, the one that means building everything yourself. Nobody does. The United States does not, and the governments that talk hardest about self-reliance still buy cryostats, lasers, and photonic components from abroad like everyone else.

So national strategies have settled on a second definition, and it is the one we find useful: sovereignty as the ability to specify, verify, and substitute, which is control over outcomes rather than control over every input. Almost all of those strategies then reach the same conclusion about how to get there. Work with allies. NATO adopted its first Quantum Technologies Strategy in 2023 and published a public summary of it, Summary of NATO’s Quantum Technologies Strategy, on November 28, 2023. The European Union built its quantum communications program, EuroQCI, as a joint undertaking across all 27 member states. AUKUS placed quantum positioning and navigation in its second pillar. The United Kingdom, Canada, Japan, and the Netherlands have layered bilateral quantum agreements on top of all of it.

Multiplier is the right word for what these arrangements do, and it brings its arithmetic with it. Multiplying by zero returns zero. A country that enters a coalition holding no capability of its own receives access to other people’s capability, which is worth having and is not the same thing as sovereignty.

This piece sets out the four capabilities an alliance multiplies rather than supplies, and why each one is a workforce problem before it is an industrial one.

What a Coalition Actually Supplies

Start with what does transfer, because it is substantial and much of it is free.

Coalitions supply direction. NATO’s quantum strategy commits allies to a shared set of priority defense applications and a common transition to quantum-safe cryptography. That spares every member the work of guessing what the others intend to do.

They supply standards. When the US National Institute of Standards and Technology published FIPS 203, FIPS 204, and FIPS 205 on August 13, 2024, it handed every allied government the same three algorithms to build against: ML-KEM for key establishment, which is the business of two parties agreeing a shared secret across an untrusted network, plus ML-DSA and SLH-DSA for digital signatures, which prove that a message came from who it claims. A fourth signature scheme, FN-DSA, was still working through the standardization process. Before August 2024, procurement offices in a dozen countries were writing requirements against candidate algorithms that might not survive selection.

They supply money and facilities. The NATO Innovation Fund committed roughly a billion euros of allied capital to deep-tech startups. DIANA, the alliance’s Defence Innovation Accelerator for the North Atlantic, runs a distributed network of test centers and accelerator sites across member states rather than concentrating them in one country, with its European headquarters in London, a regional office in Tallinn, and a North American regional office in Halifax. The EU sited its first tranche of EuroHPC quantum computers across six member states.

They supply a perimeter. In September 2024 the US Bureau of Industry and Security issued export controls on quantum computing items, deliberately aligned with rules that partner governments introduced in the same window. The measure appeared in the Federal Register on September 6, 2024 as an interim final rule covering advanced computing, quantum computing, and additive manufacturing items. Coordinated controls close the arbitrage in which a restricted buyer simply shops in whichever allied jurisdiction has the loosest regime.

Direction, standards, funding, facilities, a perimeter. That is a great deal of supply, and none of it is judgment.

The Part That Doesn’t Transfer

You can read a target date off a shared roadmap, and whether your own systems will meet it depends on an audit that nobody outside your organization has done. You can read the algorithm off a published standard, and whether the product in front of you implemented it correctly still takes your own test. You can book time on a shared testbed, and interpreting what comes back still takes your own engineers.

Each of those is the same gap. Coalitions distribute artifacts, and an artifact needs someone competent at the receiving end. We teach that competence as four distinct capabilities, and they are the same four whether the subject is a quantum computer, a sensing program, or a cryptographic migration.

Specification. Writing a requirement that describes what you need rather than what a supplier happens to sell.

Verification. Establishing independently that a delivered system does what the specification said it would.

Integration. Assembling components from several suppliers into a working system and owning the interfaces between them.

Substitution. Replacing any single supplier without rebuilding the whole.

An alliance multiplies whichever of these a member already holds, and supplies none of them.

Writing Requirements You Can Defend

Specification is the least visible of the four and the one that decides most public procurements.

Consider a ministry buying quantum-safe network equipment. A weak tender says the product must support post-quantum cryptography. A defensible one names ML-KEM at a stated parameter set, requires a hybrid mode running the post-quantum key exchange alongside a classical one so that a flaw in either still leaves the session protected, specifies how certificates and keys are generated, stored, and rotated, obliges the supplier to document every cryptographic dependency inside the product, and includes a clause requiring support for an algorithm change within a defined period. The first tender will be answered by whatever the market is already selling. The second will be answered by products that fit the buyer’s threat model, and where no such product exists, the buyer learns that before signing.

When a technical annex can only be satisfied by one product, the supplier of that product wrote the annex.

The same capability decides whether a mid-sized country has any influence in standards work. ETSI, the European Telecommunications Standards Institute, along with ISO/IEC committees and the International Telecommunication Union, sets the interfaces that everyone will later have to build against. Delegates arrive with drafted text, or they arrive as observers. Two or three trained specialists in a national standards body buy a country more influence than a much larger research grant.

Testing What an Ally Hands You

Verification is what makes the other three trustworthy, and it is the one most often skipped, because independent testing looks like duplicated effort when a partner has already tested.

The clearest live example is the disagreement among European agencies over quantum key distribution. QKD uses the physics of single photons to distribute encryption keys, so that an eavesdropper’s interference disturbs the transmission and becomes detectable in principle. In 2024 several European cybersecurity agencies, France’s ANSSI and Germany’s BSI among them, published a joint Position Paper on Quantum Key Distribution, discouraging QKD for most operational use in the near term and citing cost, limited range, and the difficulty of certifying real hardware against an idealized protocol. Other governments, including several building national segments of EuroQCI, are funding QKD deployment anyway.

Both positions are arguable. A country without its own evaluation capability has to pick a side on trust rather than on evidence. With even a modest national test laboratory, the same country can read both papers, apply its own threat model, and reach a decision it can explain to its own legislature.

Implementation is where verification earns its cost. The mathematics behind ML-KEM and ML-DSA has been examined by the international cryptographic community for years. The code implementing them has not. Timing side channels, weak random number generation, careless key handling, and wrong parameter choices have broken far more deployed cryptography than broken mathematics ever has. A supplier’s compliance claim describes a validated module, not an audit of the build running in your data centre.

Owning the Interfaces

Return to the machine from the opening. The sovereignty question it poses concerns the interfaces rather than the parts.

A national laboratory that buys a complete quantum computer from a single supplier has acquired a working machine and one supplier relationship. A national laboratory that assembles a machine from a Finnish refrigerator, a Dutch processor, and Swiss control electronics has acquired a working machine and the ability to change any one of those three next year. The second laboratory needed an integration team to get there, meaning cryogenic engineers, microwave engineers, firmware developers, and someone who understands the control stack end to end. That team is the asset, and the machine is what the team produced.

Open interface standards are what make the second route available. OpenQASM gives quantum programs a common textual representation across different hardware. QIR, the Quantum Intermediate Representation maintained by the QIR Alliance, does similar work one layer down, at the format a compiler uses between source code and machine instructions. Where these are adopted, a country can change hardware supplier without rewriting its application software. Where they are not, the software binds the country to the hardware.

The identical structure appears in cryptographic migration, which is why we treat the two subjects as one in our teaching. Compare two organizations facing the same deadline. The one that produced its own cryptographic inventory, covering every algorithm, key, certificate, and protocol in use and every system depending on them, can change algorithms. The one that outsourced discovery and received a report can change consultancies. Crypto-agility is an engineering property of your own estate, and no supplier installs it for you.

Keeping a Second Source

Substitution turns the other three into insurance, and it runs into a structural constraint. The coordination that makes allied supply predictable is the same coordination that makes non-allied supply unavailable.

Dilution refrigerators are the standard illustration. A handful of manufacturers supply most of the world’s superconducting and spin-qubit research, and most of them are European – Bluefors in Finland, Oxford Instruments in the United Kingdom, Leiden Cryogenics in the Netherlands, and CryoConcept in France. They depend in turn on helium-3, which is produced almost entirely as a decay product of tritium held in national nuclear stockpiles, so the supply of a basic laboratory input is governed by the security policy of two or three governments. Ultra-stable lasers, specialist optical materials, and several classes of photonic component show similar concentration.

None of that is fixable by a mid-sized country acting alone, and none of it needs to be. Substitution asks for something narrower: documented interfaces so a replacement part can be qualified, second-source terms written into contracts before anyone needs them, escrow of design documentation, and enough retained skill to keep older equipment running through a gap. A laboratory that kept its previous-generation cryostat working, and kept someone able to run it, has months in which to qualify an alternative. Scrapping the old unit converts the same gap into a lead time and a purchase order.

Where Alliance Frictions Come From

Coalitions generate three predictable arguments, and each is a capability asymmetry wearing the clothes of a political disagreement.

Uneven contribution

Larger members suspect free-riding. Smaller ones suspect they will end up as customers with a flag on the letterhead. Specialization is the standard answer, and it works when the specializing country can hold its niche in practice. Finland in cryogenics, the Netherlands in quantum networking and chip fabrication, Austria in trapped ions and quantum communications: each of those is a real position, defended by research groups and companies that other countries depend on. A niche declared in a strategy document and never staffed is a label.

The practical test is whether the contribution would be missed if it stopped.

Competing security doctrines

Allies diverge on how fast to move and what to move to. Some governments treat harvest-now-decrypt-later, where an adversary records encrypted traffic today in order to decrypt it once a capable quantum computer exists, as an immediate operational problem for any data with a long confidentiality life. Others weigh implementation risk and wait for more mature products. Some fund QKD, and most do not.

Alliances manage this by moving at the pace of the more cautious member on shared systems, and by letting the more forward members run pilots that everyone else can watch. For an individual country, the doctrine question resolves back into the verification question. With an evaluation capability you contribute evidence to the argument. Without one you wait for somebody else’s conclusion and adopt it.

Hosting decisions

Every member would like the flagship facility on its own territory, and most will not get it. Alliances handle this by splitting and spreading: DIANA’s network of accelerator sites and regional offices, EuroHPC’s six quantum computing sites, NATO’s long practice of placing Centres of Excellence in smaller member states.

Geography decides where the building goes. Access decides who can use it, and access follows staffing. A country with three engineers embedded in a multinational operating team can run experiments on a facility two borders away. Hosting the building without supplying staff produces the reverse case, a national asset that national researchers queue for.

A Capability Ledger

For a program that has signed the agreements and now has to make them pay, the four capabilities give a review structure that doesn’t depend on budget size.

CapabilityThe question to answerEvidence that you have it
SpecificationCould we write the technical annex for our next quantum or post-quantum procurement without a supplier’s help?A tender issued in the last two years, written in-house, that at least two suppliers could bid on
VerificationCan we test a delivered system against our own threat model?A named laboratory, named staff, and a test report that changed a purchasing decision
IntegrationCan we combine components from three suppliers and own the interfaces between them?A working system assembled in country, with the team that built it still employed
SubstitutionIf our principal supplier stopped shipping tomorrow, what happens over the following twelve months?A written second-source plan naming the alternative and the qualification steps

Every program believes it can specify. Few can point to a tender written without a supplier’s help.

The ledger is deliberately silent on funding, because at the scale most countries operate, none of the four is primarily a money problem. Specification capability costs a handful of trained people in a procurement office. Verification costs a laboratory that a mid-sized university could house. What all four cost is time, because they live in individuals and individuals take years to train.

You can also read the ledger backwards, to work out what to offer a coalition rather than what to ask of it. The capability you are strongest in is the one to specialize in and defend. The ones you are weakest in belong in partnership agreements as training and technology-transfer conditions, not as procurement line items.

The Workforce the Alliance Assumes You Have

Every mechanism described here assumes a person at the receiving end. The shared roadmap assumes someone who can turn it into a national plan. The common standard assumes engineers who can implement and test against it. The joint testbed assumes researchers who can use the time productively. Exchanges, fellowships, and fast-track visas for specialists move people between allied countries, and a country with nobody to send gets nothing from a reciprocal exchange.

Quantum physicists are the visible shortage. The larger gap sits in roles that rarely appear in a strategy document: procurement officers who can read a cryptographic specification, security architects who can plan a migration across a bank’s estate, program managers who can run a multinational integration, engineers who can qualify a component from a new supplier. Those roles are not filled by doctorates in quantum information. They are filled by working professionals who acquire a specific, teachable body of knowledge, and the professionals who reach us are usually already in post and already responsible for the decision.

That is the work Quantum Academy exists to do. Our certification programs are built for the people who sit between a signed alliance agreement and a working system, and the curriculum is organized around the same four capabilities, because those are what national programs and employers are short of.

You can review the current programs at quantumacademy.com/. For migration methodology in depth, see pqcframework.org. For deeper technical background on the standards, hardware, and supply chains referenced here, see PostQuantum.com. For how these roles map onto career paths, see QuantumCareers.com.