Boards tend to hear about quantum computing from two directions at once. A security report says it will break encryption. A vendor says it will transform optimization. Both are partly true, on very different timelines, and a company needs a single plan that treats them separately. That plan is what we build with you: a quantum computing strategy short enough for a board meeting and specific enough that the teams below can act on it.
Why does a quantum computing strategy need two timelines?
A quantum computing strategy needs two timelines because risk and opportunity move at different speeds. The cryptographic risk already has dates from NIST and data stolen today can be decrypted later, while the business opportunity depends on fault-tolerant hardware that vendors only target for the end of the decade.
The security clock has dates. NIST published its first post-quantum standards (FIPS 203, 204 and 205) on August 13, 2024, and its draft IR 8547, released in November 2024, proposes deprecating RSA and elliptic-curve cryptography by 2030 and disallowing it by 2035. Because attackers can store encrypted traffic now and decrypt it later, any data that must stay secret past the arrival of a large quantum computer is already exposed. This part of the strategy is about migration budgets and sequencing, and it usually leads into a post-quantum cryptography migration.
The opportunity clock depends on hardware that isn’t here yet. Here the strategy is about positioning: knowing which of your problems could benefit, keeping enough skill in-house to judge vendor claims, and being ready to move when the milestones arrive.
What do quantum vendor roadmaps promise, and can you trust them?
Quantum vendor roadmaps converge on the end of the decade: IBM targets its fault-tolerant Starling system for 2029, Quantinuum aims for a universal fault-tolerant machine by 2030, and IonQ publishes a target of 80,000 logical qubits by 2030. Treat these as targets rather than delivery dates, since vendor dates have slipped before.
IBM’s roadmap plans Kookaburra for 2026, the first processor module that stores information in qLDPC memory and processes it with an attached logic unit, then Starling in 2029: a fault-tolerant system running 100 million gates on 200 logical qubits. Quantinuum launched Helios in November 2025 and says Apollo, its fifth generation, will be a fully fault-tolerant, universal machine. Google’s Willow chip showed in December 2024 that errors fell as the error-correcting code grew, a step toward error-corrected machines. IonQ publishes the most aggressive targets, 80,000 logical qubits and 2 million physical qubits by 2030. Microsoft announced its Majorana 1 topological chip in February 2025, and physicists are still debating how far that result goes.
Any of these dates can slip, which is why we don’t build your plan on a year. We build it on milestones that you can check when they happen.
Signals that should move you to the next stage
Each stage of your roadmap opens with an outside event, not by the calendar. Typical signals include:
- a vendor publishes logical qubit counts and logical error rates that an independent group reproduces
- a quantum advantage claim on a problem close to yours survives scrutiny from classical algorithm researchers
- your main cloud provider, bank or HSM vendor turns on post-quantum algorithms by default
- a regulator where you operate (a central bank, a financial superintendency, a data protection authority) publishes a post-quantum deadline
- a competitor or supplier moves a quantum pilot into production and says so publicly
When a signal fires, the roadmap already says what happens next, who owns it and which budget tier it opens.
How to size a quantum budget without invented numbers
We don’t quote industry spending averages, because the credible ones don’t exist for a company like yours. Instead, the budget follows three tiers.
The first tier is watch and learn: training, a small amount of cloud hardware time, and someone who owns the milestone tracker. The second is pilot: one or two hybrid proofs of concept with clear success criteria and a classical baseline to beat. The third is program: a dedicated team, vendor contracts and production integration, justified by pilot results.
The cryptographic migration sits outside these tiers. It is a security investment with regulatory deadlines, and it should be budgeted like one. We work out each amount with your finance and technology teams, based on your inventory and your problems.
Talent: build, borrow or buy
Most companies don’t need a quantum team yet. They need three or four people who understand enough to make good decisions.
We usually recommend building that core from engineers you already have, through focused training for your teams. Specialist work, such as algorithm research or error-mitigation experiments, is better borrowed from universities or consultancies for now. Hiring dedicated quantum staff makes sense when a use case enters the program tier, and the plan says which profiles to look for when that happens.
Partners, cloud providers and public programs
No company should pick a single hardware vendor today. The strategy includes a shortlist of cloud platforms (IBM Quantum Platform, Amazon Braket, Azure Quantum and others) chosen for the processors you would want to compare, plus research partners and public programs.
Public programs matter more than most boards expect. The US has funded quantum research through the National Quantum Initiative Act since 2018. In Latin America, Colombia’s Ministry of Science (MinCiencias) announced more than COP 63 billion for AI and quantum-science research in February 2025, funds quantum work through public calls such as ColombIA Inteligente 2026 and is backing a quantum processor project at Universidad del Valle. In Chile, an expert commission delivered 15 recommendations in September 2024, and the government launched a national quantum technologies strategy for 2025 to 2035 in December 2025. These programs fund joint projects, train graduates and open doors to university labs. We map the ones that apply to your countries of operation.
What does a quantum strategy engagement involve?
A quantum strategy engagement takes about six weeks: two weeks of interviews with the board, technology and security leaders, a positioning review of cryptographic exposure, business problems and skills, a drafted strategy reviewed with leadership, and a board session in week six, followed by a yearly review against what vendors and regulators actually did.
| Step | Timing | What happens | Output |
|---|---|---|---|
| Interviews | Weeks 1 and 2 | We meet board members, the CTO or CIO, the CISO and two or three business owners | Priorities and constraints on record |
| Position | Weeks 2 to 4 | High-level review of cryptographic exposure, business problems and skills, building on a readiness assessment if you have one | Your current position |
| Draft and review | Weeks 4 and 5 | Strategy, budget tiers, talent plan and milestone tracker, reviewed with your leadership team | Draft board paper |
| Board session | Week 6 | We present with your executives, in Spanish or English | Decisions for this year |
| Yearly review | Once a year | We check the roadmap against what vendors and regulators actually did | Updated roadmap |
Strategy work is open now as we start taking engagements in stages. If your board has asked for a quantum plan, tell us when it meets next.
Sources
- NIST CSRC, Post-quantum cryptography FIPS approved (FIPS 203, 204, 205), August 13, 2024
- NIST IR 8547 (initial public draft), Transition to Post-Quantum Cryptography Standards, November 2024
- IBM Quantum, How IBM will build the world's first large-scale, fault-tolerant quantum computer, June 10, 2025
- Quantinuum, Quantinuum unveils accelerated roadmap to achieve universal, fault-tolerant quantum computing by 2030
- IonQ, technology roadmap
- Minciencias, investment of more than COP 63 billion in AI and quantum science, 24 Feb 2025