Quantum Academy begins operations on September 15, 2026. Enrollment opens soon.
Skip to content

Leadership and Governance

Before You Create a Chief Quantum Officer Role

Marin Ivezic13 min read

In 2023, the State of Illinois appointed a Chief Quantum Officer. The appointment was not a branding exercise. The state had capital committed, partners waiting, and a short list of decisions that no existing role was making. The title came second.

Most organizations reading about appointments like that one reverse the order. They ask whether they need a Chief Quantum Officer, which sounds like a staffing question, and the cheaper question underneath it is about accountability: which quantum-related decisions is this organization already facing, who owns each one today, and which of them are drifting because the owner is ambiguous?

That inventory takes an afternoon. It usually produces two or three orphaned decisions rather than a new seat at the executive table. This piece walks through the inventory, then through the three staffing patterns that follow from it, then through the knowledge floor for whoever ends up holding the file.

The decisions that are already on the table

Quantum reaches an enterprise in two waves, and the waves arrive on very different schedules. The security wave has already landed and has published deadlines attached to it. The computing wave is still in pilot territory for almost everyone outside quantum vendors and a handful of research-heavy firms. An honest inventory separates the two, and most of the urgency sits on the security side.

Six decisions come up in nearly every organization we work with. Read each one and name the person who owns it today. If you can’t name one in five seconds, the decision is drifting.

One. Which cryptography gets replaced, and in what order. NIST published the first three post-quantum cryptography (PQC) standards on August 13, 2024. Its draft transition guidance, NIST IR 8547, proposes deprecating RSA and elliptic-curve cryptography after 2030 and disallowing them after 2035, and it is an initial public draft rather than binding federal policy. NSA’s CNSA 2.0 sets separate transition milestones that bind U.S. national security systems. Dates from both tracks propagate into supply chains, product certifications, and procurement language well before they bind anyone directly. Migration is not optional; the open question is sequencing, and sequencing needs an inventory first: a cryptographic bill of materials, or CBOM, which is simply a list of every place your organization uses cryptography, what algorithm it uses, and what would break if that algorithm were swapped. Building one crosses application teams, network infrastructure, operational technology, embedded product firmware, and third-party integrations. The CISO usually owns the decision on paper. The CISO rarely has authority over half the places the inventory has to reach.

Sequencing also depends on how long your data stays sensitive. An adversary who copies encrypted traffic today can store it and decrypt it whenever a capable quantum computer exists. Security teams call this harvest now, decrypt later, and it moves the deadline forward for anyone holding data with a long confidentiality tail. Medical records, life insurance files, sealed legal agreements, and state secrets all fall into that category. Payment authorizations from last Tuesday do not.

Two. What the organization says publicly about its timeline. Customer security questionnaires now ask about post-quantum readiness. So do a growing number of contract renewals in financial services and defense supply chains. Regulators ask in some jurisdictions and will ask in more. This is a communications decision with legal exposure attached, and it is very often unowned, so three different functions give three different answers to the same question in the same quarter.

Three. Which vendor claims to believe. Quantum hardware roadmaps are written to be read charitably. A slide promising ten thousand qubits by a given year means one thing if those are physical qubits and something entirely different if they are logical ones. A physical qubit is the actual piece of hardware, and it’s noisy: it holds its state for a short time and then errors creep in. A logical qubit is an error-corrected unit built from many physical qubits working together, and it’s the thing an algorithm actually runs on. The ratio between them is the whole game. In December 2024, Google reported an error-corrected system operating below the threshold where adding more physical qubits starts to reduce errors rather than add them, using roughly a hundred physical qubits for a single logical one. That was a genuine scientific result and it is not a product. Meanwhile, resource estimates for breaking RSA-2048 have moved sharply: a 2025 paper from Craig Gidney at Google put the figure under one million noisy qubits, down from around twenty million in the 2019 estimate by the same author with Martin Ekerå. Someone in your organization needs to be able to read those two facts side by side and explain what they do and do not imply for your migration schedule.

Four. Whether to run a computing pilot, and what would end it. Optimization and simulation pilots on cloud quantum services are inexpensive and instructive. They are also easy to keep alive indefinitely on enthusiasm. The question worth answering isn’t whether to pilot but what result would make you stop, written down before the first sprint. Most enterprise quantum pilots today are learning exercises rather than performance projects, and that’s a legitimate purpose as long as it’s the stated one.

Five. Who gets trained, and to what depth. This decision gets deferred more than any other on the list, and deferring it is what turns the other five into consulting engagements. There are three distinct depths involved, and conflating them wastes budget: general awareness across the leadership team, working knowledge for the people who will run the migration, and specialist depth for anyone evaluating hardware or writing quantum code.

Six. What suppliers have to commit to. Migration clauses, algorithm-agility requirements, and disclosure obligations in vendor contracts. Procurement owns the paper. Procurement cannot write the clause without someone who understands what a reasonable commitment looks like.

Look at the six together. Decisions one and six have natural homes in most organizations, even if the homes are under-resourced. Two, three, four and five typically have no home at all. That’s the finding the inventory produces, and it’s a more tractable problem than a new executive role.

A worked map

Take a regional life and annuity insurer as a working example. Around two thousand staff, three hundred in technology, a mainframe policy administration platform written across three decades, a cloud-hosted claims portal, and roughly eighty third-party integrations for reinsurance, actuarial services, and distribution. Policies written this year carry confidentiality obligations for forty years or more. On the harvest-now-decrypt-later logic, that firm has one of the longest exposure windows of any commercial sector, longer than most banks.

Run the six decisions against the existing org chart.

Decision one goes to the CISO, and it immediately runs into two limits. The mainframe cryptography is embedded in code nobody currently maintains, which makes it an engineering budget question rather than a security question. And roughly a third of the cryptographic surface belongs to third parties, which makes it a vendor management question. The CISO owns the decision and controls maybe half of what it touches.

Decision six goes to procurement, and procurement asks the CISO’s team for language. That works.

Decision two has no owner. Legal, marketing, and the security team have each answered a customer questionnaire about quantum readiness in the past year, and they didn’t answer the same way.

Decision three has no owner either. The firm has been offered a quantum optimization proof of concept by two vendors, and nobody in the building can independently assess the claims in either proposal.

Decision four is currently a slide in an innovation team deck with no budget and no exit criteria.

Decision five is unassigned, which is why decisions two and three are unassigned.

What this insurer needs is not a Chief Quantum Officer. It needs a named accountable executive, and the CTO is the obvious candidate given that the hardest constraint is mainframe engineering rather than security policy. It needs a chartered working group with the CISO, procurement, the actuarial data owner, and one senior engineer from the platform team. It needs eight to twelve people trained to working depth, and the leadership team trained to awareness depth so the working group’s recommendations get read rather than nodded at. And it needs a standing quarterly item on the board technology agenda with a defined red condition, something like: any system holding policy data with no migration owner assigned by the end of the following quarter.

Total incremental headcount: zero. Total incremental cost: training, some consulting on the initial inventory, and roughly a day a week of the CTO’s attention for two years.

Three ways to staff it

The inventory points to one of three patterns. Each has a real cost and a characteristic failure.

The chartered owner. An existing executive takes named accountability, with a written charter, a budget line, and a cross-functional group reporting into it. This fits most organizations, and it’s what the insurer above should do. The cost is attention: a senior person gives up something else, and if nothing is taken off their plate, the charter becomes a slide. The characteristic failure is a charter with no budget and no board reporting line, which produces activity without decisions.

The rotating committee. A steering group with no permanent chair, meeting monthly, minutes circulated. This is the most common arrangement and the weakest one. Committees are good at reviewing decisions and poor at making them, and the four orphaned decisions on the list all require someone to be wrong in public occasionally. A committee will produce a readiness assessment. It will not produce a migration sequence with dates.

The dedicated executive. A genuine Chief Quantum Officer, or a VP of Quantum reporting to the CTO or CEO. Three conditions justify this, and one of them has to be true rather than aspirational. First, quantum sits in the revenue line: you sell quantum hardware, software, security products, or services, and technical direction is a commercial decision. Second, you are the surrounding environment rather than a participant in it: a state, a region, a national laboratory, or an innovation hub, where the job is partnership formation and inward investment. The Illinois appointment mentioned at the top of this piece falls squarely into that second category, which is why the title made sense there and travels badly to a manufacturer or an insurer. Third, a regulator has given your sector dated obligations and your board wants a single accountable name against them.

If none of the three is true, a dedicated role is difficult to justify and difficult to fill. The person you want has deep quantum literacy plus enough organizational weight to move an engineering budget, and that combination is genuinely scarce in the current market. Appointing someone who has one half and not the other tends to produce either a research function with no authority or an authority with no technical judgment, and both get quietly folded back into the CTO’s organization within two years.

There’s also a hybrid worth naming: a quantum lead hired at director or VP level, reporting into an accountable executive, with a small budget and a two-year mandate. It buys the expertise without the org-chart argument, and it’s reversible.

What the owner has to know

Whatever the title, the person holding this file needs a specific and bounded body of knowledge. Bounded matters here. The requirement is not a physics education, and treating it as one is how organizations conclude that they can’t staff this internally.

The floor has six parts.

The two threat mechanics, stated precisely. Confidentiality breaks retroactively through harvest now, decrypt later. Authenticity breaks prospectively: once signatures can be forged, anything relying on a signature made with vulnerable cryptography becomes untrustworthy from that point forward. The second mechanic drives firmware, code signing, and root-of-trust decisions with lead times measured in product generations, and it is the half that gets missed.

The standards vocabulary. ML-KEM (formerly Kyber) for establishing shared keys, ML-DSA (formerly Dilithium) and SLH-DSA (formerly SPHINCS+) for digital signatures, with a fourth signature scheme, FN-DSA (formerly Falcon), standardized separately. The owner should know which of these applies to which problem, what a hybrid mode is (running a classical and a post-quantum algorithm together so that the connection stays secure if either one holds), and why hybrid is the default posture during transition rather than a hedge for the indecisive.

Migration mechanics. Inventory, then crypto-agility, then sequenced replacement. Crypto-agility means building systems so that an algorithm can be swapped without rebuilding the system around it, and it’s the property that determines whether the next migration takes two years or two months. Certificate lifetimes, key management, and hardware security module refresh cycles all set the pace.

Hardware literacy. Physical versus logical qubits, error rates and what they mean for circuit depth, and the difference between an announced roadmap and a demonstrated result. This is what makes decision three answerable in-house.

Algorithmic honesty. Shor’s algorithm gives an exponential speedup for factoring and discrete logarithms, which is why public-key cryptography is the problem. Grover’s algorithm gives a quadratic speedup for unstructured search, and the practical overhead eats most of it, which is why symmetric cryptography needs a key-size adjustment rather than a replacement. Variational and heuristic methods for optimization and chemistry have no proven advantage over classical alternatives today. An owner who can state those three facts in a vendor meeting will save more money than one who can derive any of them.

Procurement language. What a defensible quantum-readiness clause looks like, and what a supplier can reasonably commit to in 2026.

What the owner does not need: the ability to derive amplitude amplification, write production Qiskit, or hold an opinion on trapped ions versus superconducting circuits. Those belong to specialists, and specialists can be contracted.

This is a curriculum rather than a career. It’s the reason we build executive and program-leadership tracks separately from technical ones, and it’s why the training decision, number five on the inventory, is the one that unblocks the rest.

Plan for the role to expire

The comparison people reach for is the Chief Electricity Officer. Early electrified factories did appoint executives to manage in-house generation and the conversion from steam, and the role disappeared once the grid standardized and every engineer understood electricity. It’s a decent parallel, and it’s incomplete, because the more instructive arc is recent: the Chief Digital Officer. That title spread through large enterprises between roughly 2010 and 2018, then began folding back into the CIO and CMO functions once digital ceased to be a separate thing anyone could own. The roles that ended cleanly had one feature in common. They were chartered with an expiry condition from the start.

Write the same condition into whatever you charter. Something concrete: this accountability returns to the CISO and CTO permanently once the cryptographic inventory is complete and maintained as a standing process, once migration is funded through the normal capital cycle rather than a special allocation, and once quantum questions in vendor evaluations are answered by the evaluating team without escalation. Those are observable conditions with dates attached. They also happen to be a reasonable definition of what success looks like, which is convenient, since the alternative definition tends to be the number of conference panels the role appears on.

Where to start this quarter

Four steps, in order, none of which requires a hiring decision.

Run the six-decision inventory with your CIO, CISO, CTO, and head of procurement in one room. Ninety minutes. Write the owner’s name next to each decision or write “none,” and resist the urge to fill in a name that isn’t real.

For every decision marked “none,” assign a provisional owner and a date for their first written recommendation. Provisional is fine. Unowned is not.

Decide the training depth for each group before commissioning any external assessment. An inventory delivered to an audience who can’t evaluate it becomes a filing exercise.

Put the whole thing on the board agenda once, with the deadline dates and your current exposure window, and agree what a red status means. That single item does more for the program than the title debate ever will.

Where the title has made sense, it arrived after the four steps rather than instead of them. The Chief Quantum Officer was the last decision those organizations made, not the first.


Quantum Academy builds programs for the people who end up owning these decisions: executive-level literacy for boards and leadership teams, and deeper program-leadership tracks for whoever runs the migration itself. Our certifications are private credentials, designed to establish a defensible working knowledge rather than an academic qualification. You can see the current programs and access options at quantumacademy.com/.

For the migration methodology behind decision one, the PQC Framework sets out the inventory and sequencing approach in detail. For deeper technical background on the hardware and cryptographic claims discussed here, PostQuantum.com covers both in long form.