Sovereignty in quantum computing gets discussed as a manufacturing question and decided as a contractual one. A system built entirely abroad can leave its buyer with real control over what happens next, and a system assembled at home can leave its buyer with almost none. The conditions around a quantum program – export licensing, ownership of suppliers, the security reviews attached to specific deployments – can all change inside a single five-year contract term, without a processor getting slower or a roadmap moving. What changes is who can ship which system to whom, and under whose licence.
For a buyer running a quantum program, a change of that kind arrives in one place: the contract signed eighteen months earlier. Strategy documents announce sovereignty. Contracts decide whether an organisation can change supplier, jurisdiction, or architecture without restarting the work.
Sovereign optionality describes what most buyers actually need. It means control over outcomes without ownership of every input, and the ability to change supplier, jurisdiction, or technical approach fast enough that a dependency never becomes a hostage. Almost every property that makes such a change cheap gets fixed at signature. The rest of this article is about the terms that fix it.
Sovereignty, Restated as a Procurement Problem
Technical sovereignty in quantum is usually defined as owning the whole stack, from isotopically pure materials and qubit fabrication through cryogenics, control electronics, firmware, and compilers to the applications running on top. Defined that way, almost nobody qualifies.
The pieces are distributed by accident of industrial history. Finland is home to the leading makers of dilution refrigerators, the cryostats that hold superconducting processors within a hundredth of a degree of absolute zero. Dutch and Japanese firms supply the lithography and precision components behind the classical control chips. French, German, and American companies build the processors, and the software talent is spread across all of them.
Japan comes closest to closing the loop, and the reason is industrial rather than quantum: decades of prior investment in precision electronics, semiconductor tooling, and materials science. That industrial base is what most countries don’t have, and it isn’t something a procurement timeline can assemble.
European Union policy is candid about the problem, because it commits to both halves at once. The stated goal is an autonomous and competitive European quantum industry, and the stated method includes diversified partnerships and reduced dependencies through cooperation with like-minded countries. Both are policy. A bloc of 27 member states with world-class research still expects to buy from outside its borders.
Building every layer at home is expensive, slow, and duplicative. It also creates a failure mode that rarely gets priced. When the single domestic supplier ships a flawed component, there is nowhere else to go. Diversity of supply is a security property before it is an economic one.
So the useful question for a buyer is not ownership but replacement speed. How long would it take, and what would it cost, to run this system on someone else’s hardware, software, or licence? Everything below is a way of answering that in writing, before the money moves.
Interfaces Before Implementations
The property that makes a swap cheap is a documented interface. When the control software talks to the processor through a published, versioned specification, and the applications talk to the control software through another, replacing the processor becomes an engineering task rather than a rebuild.
Europe has already demonstrated the mechanism outside quantum. Directive (EU) 2022/2380 took effect in December 2024 and requires most portable devices sold in the Union to use USB-C, and manufacturers who wanted market access complied. Brussels did not manufacture a single port. It specified the interface and let the market supply the implementations.
Quantum standards work is under way and unevenly mature. The European Telecommunications Standards Institute has published its GS QKD series of specifications for quantum key distribution (QKD), the technique of distributing encryption keys using the states of individual photons, and the International Telecommunication Union has issued its Y.3800-series recommendations for QKD networks. Quantum computing itself is further behind, and terminology, benchmarking, and control interfaces are still under discussion in joint committees of the International Organization for Standardization and the International Electrotechnical Commission (ISO/IEC), and in working groups at the Institute of Electrical and Electronics Engineers (IEEE). The European Committee for Standardization (CEN) and the European Committee for Electrotechnical Standardization (CENELEC) set up a joint technical committee for quantum technologies to give European standards a home. A buyer waiting for all of that to settle won’t be procuring anything for years.
So the requirement goes into the tender instead.
- Every interface between major subsystems is documented, versioned, and licensed to the buyer for the operational life of the system.
- The vendor states which parts of its software development kit (SDK) are proprietary and which follow a published specification.
- Applications developed under the contract are written against interfaces the buyer can reimplement, and the vendor supplies whatever specification makes that possible.
- Where a standard exists, the vendor either conforms to it or documents the deviation in a form the buyer’s engineers can act on.
Vendors price documented interfaces higher than closed ones, and they are right to. That premium is the cost of the option, and it belongs in the business case at the start rather than in the last hour of negotiation.
A Second Source, Named Before Signature
Diversification reads well in a strategy and rarely reaches the purchase order. The procurement version is narrower and testable. For each critical subsystem, the buyer records which other supplier could provide it, on what timeline, at what cost, and with how much interface work.
If no alternative can be named, that is the finding, and the purchase may still be the right one. It then gets approved as a single-source dependency with a named owner and a review date, rather than becoming one by default.
At national scale the same discipline appears as partnering by subsystem rather than by supplier. One partner covers photonics, another cryogenics, a third control electronics and software. Each relationship fills a specific gap, and no single one of them can stop the program if it ends.
Two conditions make this work. The alternative supplier has to be able to bid, which returns to the interface question. And the buyer needs somewhere to run a comparison, which is the argument for testbeds and small pilot procurements that otherwise look like duplicated spending. In our work with procurement teams, real dependencies tend to become visible during a pilot and stay invisible during a strategy workshop.
Exit Terms That Cost Less Than Lock-In
Every long-term contract has an exit price. In quantum procurement that price is usually unknown at signature and usually high, since the buyer’s staff have learned one toolchain, the applications are written against one SDK, and the calibration and benchmark data live in the vendor’s cloud. Five clauses set it.
Term and break points. A five-year commitment without a break point commits the organisation to a technology that will change substantially inside that window. Shorter base terms with priced extension options keep the decision live.
Escrow. Source code escrow places a copy of the software, its build instructions, and the design documentation with an independent third party, released to the buyer on defined triggers.
The trigger list. The escrow mechanism is standard. The trigger list is where quantum differs from a general IT template, and it needs entries those templates omit: a change in export licensing between the vendor’s jurisdiction and the buyer’s, a change of control that moves the vendor into a different jurisdiction, a national security review blocking a specific deployment, or the discontinuation of a hardware line.
Transition assistance. The vendor supports migration for a defined period at a defined day rate, and exports the buyer’s circuits, calibration records, and benchmark results in documented formats.
Intellectual property. Joint work has a named owner, and the buyer’s rights to use it after the relationship ends are written down rather than assumed.
We already know how to do most of this in cloud and defence categories. What tends to be missing in quantum is the trigger list, and it’s the cheapest part of the whole exercise to get right.
The Right to Verify
None of these clauses is worth more than the buyer’s ability to check compliance with them.
Acceptance testing is where the abstraction ends. A contract that accepts “a 200-qubit system” has accepted a number with no operational meaning attached to it, and vendors know it. Physical qubits are the devices on the chip. Logical qubits are error-corrected units assembled from many physical ones, and the ratio between the two is large, hardware-specific, and moving. A useful acceptance clause names the measurements rather than the headline. Two-qubit gate error, connectivity, coherence time, the circuit depth achievable at a stated fidelity, and the method used to measure each all appear in the schedule. The clause also separates announced specifications from demonstrated ones and pays against the demonstrated figures.
Security hardware raises the bar further. A quantum random number generator produces random numbers from a physical quantum process rather than an algorithm, and a QKD appliance distributes keys over fibre or free space. Both are trust anchors for everything above them. When either is imported, the right to open the device, test it independently, and share the results inside the buying organisation belongs in the contract. Certification against a published scheme helps, and it doesn’t replace the buyer’s own test.
Independent evaluation is the one item on this list that lawyers can’t enforce. Someone has to run the test.
Skills Transfer as a Deliverable
Knowledge transfer usually appears in contracts as an intention. Written as a deliverable it looks different. Named staff from the buyer’s side, a defined number of hours, a syllabus agreed before installation, and an assessment the vendor doesn’t grade.
Countries that import defence equipment have run this model for decades. The aircraft is foreign and the maintenance engineers are not, and the offset agreement says so in enough detail that the capability actually appears rather than being promised. Quantum procurement can borrow the structure directly.
The target capability is specific. The buyer’s engineers should be able to install and recalibrate the system, integrate it with existing high-performance computing infrastructure, read the vendor’s error and benchmark data critically, and write the next specification without the incumbent’s help. Each of those is a training objective before it becomes a contract clause, which is why the training plan and the procurement plan belong on the same timeline.
Buying Power Differs by Size
Large blocs specify the interface
The European Union’s advantage here runs through market access rather than manufacturing capacity. A supplier that wants to sell into the single market will meet the interface and certification requirements attached to it, as the charger rules showed. Applied to quantum, European specifications for control interfaces, for QKD device security evaluation, and for benchmark reporting could become the global default without a single additional fabrication plant being built in Europe.
Certification is the second instrument. Rather than requiring that critical components be made in Europe, the Union can require that they be evaluated against European criteria, whatever their origin. A buyer who has certified three suppliers has three options. A buyer who has nationalised one supplier has one, and finds out what that costs when a flaw turns up in it.
Smaller buyers sell access
A country outside the top tier has less purchasing volume, and it has two assets the large blocs lack – speed and neutrality.
Saudi Aramco and the French company Pasqal announced an agreement in 2024 to deploy a 200-qubit neutral-atom quantum computer in Saudi Arabia, a design that holds individual atoms in place with laser beams and uses them as qubits. The Kingdom did not attempt to build one first. It bought one with local involvement in deployment and applications, and compressed its learning curve by years. The same instinct shows up in regulatory sandboxes and shared testbeds, where a small country becomes an attractive place for several vendors to prove their systems and ends up with staff who have handled all of them.
Specialisation is the other half. A country with a strong telecommunications industry has a credible claim on quantum networking. A country with large mining or energy operations has a real application for quantum sensing. Becoming genuinely good at one or two of these turns a buyer into a supplier of something, and a supplier of something negotiates from a different position than a buyer with only a budget.
The Capability Behind the Clauses
Every term in this article assumes someone on the buyer’s side can do four things. Describe the technical requirement precisely enough that it can be tested. Judge whether a vendor’s answer to it is credible. Price the option that a swap clause buys. Run the acceptance test when the machine arrives.
None of those are legal skills and none are physics-research skills. They sit with procurement, architecture, and program management, and most organisations are building them from a standing start while the first contract is already in draft.
Security teams have the closest precedent in crypto-agility, the ability to change cryptographic algorithms without redesigning the system around them. Sovereign optionality is the same property extended to hardware, software, and jurisdiction, and it gets bought or lost in the same place, in the requirements document.
We build our programs around exactly this list. If your organisation is heading into a first quantum procurement, or reviewing a contract signed before jurisdiction became a live question, the programs at quantumacademy.com/ cover the technical judgment those clauses depend on. Teams whose immediate exposure is cryptographic rather than hardware will find the migration methodology at pqcframework.org more directly useful, and the longer strategic argument behind this article sits at PostQuantum.com.