Quantum Commercialization

Clients Kept Asking Us to Train Their Teams, So I Started Quantum Academy

In 2000, a European government asked CyberAgency, the offensive security agency I was running at the time, what quantum computers would mean for its national cryptography. What it actually wanted was a quantum computer of its own.

We didn’t build one, of course. The largest quantum computer anywhere that year had seven qubits, the atomic nuclei of a small organic molecule in a test tube. But we spent nine months talking to the scientists who were trying to build something bigger. I came out of those conversations convinced of two things I still believe: the machines would work one day, and the physics behind them would have uses beyond the threat to cryptography.

Most of my career has been in cybersecurity, but I trained in applied physics first, and I kept working on the technology side too. I tried to start a company, Boston Photonics. I’ve stepped in as interim Chief Quantum Officer at companies that were early to want one, and I’ve worked on quantum sensing projects, including one on spotting nano-drones with quantum sensors.

A year and a half ago I gave up a comfortable partnership at a Big Four firm to work on quantum and nothing else, and started Applied Quantum. Since then the firm has worked across the whole field, from PQC migrations and quantum computing integration to quantum networks and sensors, which is why Quantum Academy teaches six domains rather than one.

On October 2, 2026, I opened Quantum Academy, which trains and certifies professionals in post-quantum cryptography (PQC) and quantum technologies. I’d wanted to build it for years. If you’re after the courses, credentials, prices and dates, they’re all in the launch report.

The push came from Applied Quantum’s clients. They kept asking us to train their people. Private quantum training turned into one of our most requested services, hundreds of hours of it, from board briefings to hands-on technical sessions. I understand why. Organizations now need people who can judge where quantum technology will pay off and people who can run a post-quantum migration, and there are too few of both.

Most of our clients are dealing with both at once. Jonathan Dowling and Gerard Milburn called this the second quantum revolution back in 2003, the point where the rules of quantum mechanics turn into working technology, and it has reached the boardroom. A bank that has to replace the cryptography in its payment systems by a deadline someone else set is, in the same year, being pitched quantum optimization for its trading desk. It needs people who can tell a demonstrated result from a roadmap on both counts.

Post-quantum migration now comes with deadlines and budgets. In the US, Executive Order 14412 gives federal agencies until December 31, 2030 to move their high-value assets and high-impact systems, other than national security systems, to post-quantum key establishment. And when ISACA polled more than 2,600 digital trust professionals in 2025, only 7% said they had a strong understanding of the new NIST standards, and 44% said they had never heard of them.

Why Training Needed Its Own Company

I could have kept training inside Applied Quantum. Three things made me set it up separately.

The first is independence. A client can fairly wonder whether training from its consultants is really a pitch for the next engagement, and I want the answer to be no without anyone having to take my word for it. That’s easier to show when the training runs as its own company, with its own faculty and its own rules.

The second is the faculty. Some of the best people to teach this run consulting practices of their own, and three of the instructors you’ll meet below do. As a separate company, Quantum Academy can bring experts like them in as collaborators to train our clients’ teams, and neither side has to worry about competing for the consulting work.

The third is reach. Large organizations are still our main audience, and teams can book private training for any course. But individuals can now register for an instructor-led online session on their own, so a security architect who wants to learn this before their employer starts a program can do it.

Quantum Academy runs under Post-Quantum Institute, a Delaware corporation that’s separate from Applied Quantum and, despite the similar name, from this blog. The Institute also runs QuantumCareers.com, a job board for quantum technology and quantum security roles, and is preparing to launch QuantumExperts.com. We want to support people’s careers in other ways once they finish our training.

Teaching, Books and Free Frameworks

I love teaching, and I always have. Teaching has been part of my IT career since it started in 1992. I taught SANS courses and have given many guest lectures at universities over the years. I also mentor people who are moving into quantum security. These days most of the people I teach come from cybersecurity rather than physics. I’ve always wanted to help the security community through this transition, and teaching is the most direct way I know of doing it.

I think of the books the same way. Quantum Ready is a practitioner’s guide to PQC migration, built on the Applied Quantum PQC Migration Framework. Quantum Systems Integration explains how quantum computing, networking and sensing systems get built and integrated. Quantum Sovereignty, which I wrote with Luka Ivezic, covers the geopolitics and the supply chains. Every paid Quantum Academy course comes with a PDF of its companion book at no extra cost.

The frameworks are where I’ve given away the most. The PQC Migration Framework has been downloaded more than 20,000 times, and version 3.0 came out in September with six sector extensions. With Steve Vaile I also wrote the Cryptographic Concentration Framework, which measures how far one shared cryptographic defect can spread across an institution’s supposedly independent vendors, and the Applied Quantum CBOM Profile, an open CycloneDX property taxonomy for cryptographic bills of materials (CBOMs). Both are release candidates. The CCF is due to reach version 1.0 in November, and the CBOM Profile is open for comment until October 31. All three are published under CC BY 4.0, so anyone can use, adapt and share them, commercially too, as long as they credit the authors. I did that because I think PQC migration is too important to put behind a paywall.

When I wrote the framework’s skills section, I tried to describe the team a migration really needs: people with deep cryptographic knowledge, people who can run a large enterprise program, and people who know the networks, applications, cloud and operational technology the migration touches. Those skills rarely come together in one team, so the framework calls for training at four levels: executive education for the board and the steering committee, PQC foundations for everyone working on the program, lab-based training for the engineers who deploy the new algorithms, and a crypto champion program in every platform team.

The courses draw on the same material. Of the 68 courses in the launch catalog, 28 use the PQC Migration Framework as one of their sources, and anyone can download it for free. What you get from a course is an instructor who has done the work in the field, realistic exercises, and an assessment that checks whether you can apply what you learned.

The intensives are built around a decision the participants have to take back to work, with everyone who must act on it in the room. The Government and Defense Intensive is the clearest case. In eight hours, agency architects, defense industrial base security leads, system owners and contracting officers turn their CNSA 2.0 and NSM-10 obligations into a dated, sequenced migration plan. The contracting officers are there because much of what the workshop produces is procurement language, the requirements that will end up in contracts.

Payments, for example, gets its own intensive because no single party controls its migration. When my team mapped a cross-border mobile banking payment, it crossed nine independent parties and more than 30,000 unique cryptographic functions, and the phone made about 320 cryptographic function calls before the customer even typed an amount. The Quantum-Safe Payments Intensive brings payment security architects, HSM engineers, terminal and card product managers, scheme compliance leads and the risk staff who will sign the plan together for a day on card rails, HSM estates, key ceremonies and terminal fleets replaced every 7 to 15 years.

On the technology side, Quantum Technology for Investors gives venture, private equity and institutional investors three hours on reading quantum technology claims, separating demonstrated capability from announcements and pricing the risk. It’s the judgment I’d want from anyone signing off on a quantum budget.

We write every course text-first, with diagrams, scenario exercises and short videos, and you keep the course handbook, a PDF of all the material. In my experience security professionals scan, search and come back to a specific section months later, so we write for that.

What Quantum Academy Teaches

Quantum Academy covers post-quantum security and quantum technologies, and nothing else. We launched with 68 courses across six domains: quantum security and PQC, quantum computing, communications and networking, sensing and metrology, leadership and strategy, and quantum AI and machine learning. We add new ones every day. There are 11 credentials in four tracks, Post-Quantum, Quantum Technology, Quantum Computing Security and Quantum Leadership.

Every sector migrates on its own terms, so we cut the catalog by industry too. A power utility keeps control equipment in service for 15 to 25 years. A payment processor can set its own date for its gateways and signing services, but for everything else it depends on the card schemes and terminal fleets. Each of the 13 industries we cover gets its own half-day overview, its own full-day intensive, and a page listing the computing, networking and sensing courses that apply to it.

The Chief Quantum Officer Program

Our flagship is the program for Chief Quantum Officers. It’s a new role. Applied Quantum has filled it for clients on an interim and fractional basis, and I’ve written more about what the job involves at ChiefQuantumOfficer.com. A few organizations have started hiring for it, and more are thinking about it. In the model I recommend, the person in that seat owns the organization’s whole quantum portfolio and works alongside the CIO, the CISO and the business owners rather than replacing them.

It’s a hard seat to fill. In my experience a quantum physicist usually doesn’t know how a large enterprise works. They may never have seen what it takes to deploy a quantum sensor in the field, let alone run a PQC migration. A Chief Quantum Officer in my model doesn’t own that migration, but has to understand it well enough to fund it and hold the program to account. People who combine all of that are rare, and I haven’t found a single provider that teaches the whole combination.

Quantum Academy can teach it, because we cover all six domains and our instructors include people who’ve run large enterprise departments with budgets in the hundreds of millions of dollars. The six-week Certified Chief Quantum Officer (CCQO) Program is built for experienced leaders. It adds quantum breadth and judgment to the experience they already have, and it brings the technical, commercial and PQC sides together in one program and one credential. Executives work through computing, networking and sensing as opportunities and the PQC migration as a risk. Each study week has an instructor-led Saturday session, with reading and capstone work in between. The capstone is a quantum strategy and three-year roadmap for a simulated multinational, and two assessors who didn’t teach the cohort mark it independently.

Credentials Earned by Proctored Exam

Nine of the 11 credentials require a proctored exam. The exams are closed book, multiple choice and scenario-based, and a Quantum Academy proctor who never taught the candidate watches every sitting in real time over video. Subject-matter experts set the passing standard with the modified Angoff method, estimating how a minimally competent candidate would answer each question, and results are reported on a scale of 100 to 900, with 700 as a pass. The CCQO is assessed by its capstone instead, and the eleventh credential, the Post-Quantum Certified Expert (PQCX), is awarded automatically to anyone who holds active Post-Quantum Certified Manager, Architect and Validator credentials. All the rules on eligibility, scoring, retakes and appeals are public in the Candidate Guide.

We proctor every exam because a professional credential should mean more than attendance, and I hope that helps enterprises recognize these credentials and adopt them. Supervised assessment is only one part of earning an employer’s confidence, though. These are new credentials, and they’ll earn their reputation through the quality of the assessments and through what the people who hold them go on to do. Until then I’ll describe them as exactly what they are: private professional credentials from Post-Quantum Institute, not government licenses or accredited degrees, and no promise of a job or a promotion.

Who Teaches at Quantum Academy

We have one staffing rule: everyone who teaches has done the work first. Between them, our instructors have led cryptographic migrations, assembled quantum computers from modular components, deployed quantum key distribution (QKD) systems and quantum networks, and briefed boards. It’s the standard we’ve always held at Applied Quantum, and I’ve carried it over. I want people who’ve pushed a program through approvals, budget cycles and internal politics, not only people who can explain the technology.

A CV alone won’t get anyone onto the faculty. Applicants go through a technical interview with instructors in their field and a recorded twenty-minute teaching audition, scored against a rubric they see in advance. We assess subject knowledge and teaching ability separately. New instructors co-teach a real-time session before they teach alone. Promotion through the four ranks, from Instructor to Fellow, weighs sessions taught, learner evaluations, contributions to curriculum and exams, and peer review, and quality counts for more than volume. Our rules put it bluntly: an instructor who teaches brilliantly twice a year outranks one who teaches adequately every month.

Louise Davey came to PQC governance by an unusual route. She started out as an experimental nuclear physicist, then spent more than 30 years leading transformations in large organizations, rising to partner, CTO and COO in financial services and IT consulting firms. She now advises boards, regulators and executives through her firm, LDIQ. On PQShield’s podcast this spring she argued that quantum breaks three things in a standard risk model: risk ownership, remediation, and the assumptions underneath digital trust. Ownership is the one she and I have argued about most. We’ve spent hours, some of them heated, on what the CISO, the CIO and the board should each own in a PQC migration, with Louise holding that IT enables the transition and business leadership has to drive it. I haven’t enjoyed an argument that much in a long time. If you’re on a board, start with her free guide, Quantum How.

Many readers will know Joe Spencer from his market analysis at Global Quantum Intelligence. Fewer know how hands-on his career has been. For his PhD at the University of Southampton he built cryogenic optical setups to study nanowires one or two atoms wide. He went on to Dstl, the UK’s Defence Science and Technology Laboratory, and to QinetiQ, where he led a laser physics team. He has worked on systems integration for large defense programs such as the UK’s DragonFire laser and has advised the UK Ministry of Defence and the UK Space Agency. His 2026 market outlook argued that quantum sensing is much closer to practical deployment than large-scale quantum computing. He’s also a born teacher. As a PhD student he ran Southampton’s “Accelerate!” science show, and in 2016 he won the Institute of Physics’ Three Minute Wonder contest for explaining his research to a public audience. He founded his firm, IoniQ Consulting, partly to develop early-career scientists and engineers, giving them the commercial and delivery skills that turn good science into working capability.

Steve Vaile has the least conventional career on the faculty. He joined the UK Armed Forces at 16 and trained as an electrical engineer on defense systems. He then spent more than a decade in causal-analysis software for telecom and defense networks, in senior roles at companies that IBM and EMC later bought, and founded a data communications analytics firm in the Gulf that was later acquired. Then he changed course completely. He co-founded Mad Monkey, a hostel group in Southeast Asia, ran it as CEO and chairman for more than a decade, and helped set up Cambodia’s first credit bureau along the way. He came back to deep tech as a co-founder of Quantum Security Defence, a community of quantum security professionals with more than 1,200 members in over 40 countries. He and I wrote the Cryptographic Concentration Framework and the CBOM Profile together, and he works with me at Applied Quantum.

Obada Alia may be the least familiar name here outside quantum networking, and he’s the person I’d want in the room for any QKD decision. He did his PhD in optical and quantum communications at the University of Bristol, working on the UK’s Quantum Communications Hub, and much of his research there was about getting QKD to share fiber with ordinary network traffic. At JPMorgan Chase, where he rose to vice president and technical lead in the Global Technology Applied Research division, he was first author of a 2024 study that carried about 100 Gbps of IPsec traffic between two of the bank’s data centers in Singapore, over 46 km of deployed fiber, secured with keys from QKD. He now runs his own firm, Qantaris Consulting. If you’re deciding where QKD fits alongside PQC, he has seen it work between a bank’s data centers.

And many other instructors with similar qualifications and experiences.

Some of our instructors, me included, work at Applied Quantum, and more from other firms are joining as we open. I’m on the faculty as a Fellow and course author. If you’ve done this work and want to teach it, the selection process is public, and applications go to [email protected].

Three Rules I’ll Hold Myself To

I’m writing these down so you can hold me to them.

  1. Evidence over hype, in both directions. I’ve spent years on this blog arguing against the quantum panic industry and against quantum denialism, and the Academy works to the same standard. Instructors teach what each technology does today, what it will plausibly do next and what that means for your work. They state the uncertainty of every timeline they give.
  2. Open material stays open. The PQC Migration Framework, the CBOM Profile and the Cryptographic Concentration Framework stay under CC BY 4.0. The courses draw on them, so the free versions remain a reference anyone can check a course against.
  3. No sales pitch in the classroom. Some instructors work at Applied Quantum, me included, and we’ll always say so. A course exists to teach its subject. It isn’t a sales channel for Applied Quantum or for any of my other properties, and no course is built around a vendor’s product. When I write about training or credentials on this blog, I’ll disclose my interest in the Academy. The same expectations apply to all instructors whichever firm thay are coming from.

The Next Sessions, From October 19

Our first sessions sold out, including the in-person classes in Amsterdam on October 1 and 2. They started life as Applied Quantum courses and were almost full when we converted them into public Quantum Academy courses. The earliest sessions with places available begin on October 19, and the first CCQO cohort starts on November 7. Everything else is on the schedule, and if you’d like private training for your team, write to [email protected].

I’ve been explaining quantum technology, its opportunities and its risks, since that request in 2000. My hope is that people who’ve followed that work here now have somewhere to practice it, argue with it and build the skills their organizations need, with instructors who’ve done it themselves.

Marin Ivezic

I am the Founder of Applied Quantum (AppliedQuantum.com), a research-driven consulting firm empowering organizations to seize quantum opportunities and proactively defend against quantum threats. A former quantum entrepreneur, I’ve previously served as a Fortune Global 500 CISO, CTO, Big 4 partner, and leader at Accenture and IBM. Throughout my career, I’ve specialized in managing emerging tech risks, building and leading innovation labs focused on quantum security, AI security, and cyber-kinetic risks for global corporations, governments, and defense agencies. I regularly share insights on quantum technologies and emerging-tech cybersecurity at PostQuantum.com.