Summary
- The NCSC’s first PQC migration workshop highlights executive sponsorship, business case development, supplier readiness, and transparency.
- The agency says migration is not only a technical challenge but a strategic resilience issue across industry and government.
- UK organisations face long planning cycles because cryptography is embedded in products, suppliers, certificates, protocols, and legacy systems.
The National Cyber Security Centre has urged organisations to treat post-quantum cryptography migration as a long-range resilience programme that needs executive sponsorship, supplier engagement, and practical delivery planning.
The NCSC’s workshop report, published on 22 July, draws on a December 2025 event hosted with Vodafone and the National Cyber Advisory Board. The workshop brought together people responsible for post-quantum cryptography migration across industry, academia, and government.
The agency has already set migration milestones intended to drive immediate action. Its latest report focuses on the work needed to reach them: engaging boards, building a business case, identifying senior sponsorship, linking migration to wider resilience activity, prioritising high-impact systems, and creating phased roadmaps.
Post-quantum cryptography is often discussed through the mathematics of future algorithms. The delivery problem is more operational. Public key cryptography is embedded in certificates, virtual private networks, identity systems, industrial equipment, payment flows, cloud services, messaging systems, software updates, hardware appliances, and supplier-managed platforms. Replacing or upgrading those protections requires inventory, testing, vendor coordination, change planning, and sequencing.
Supplier readiness is central. Organisations cannot migrate faster than the products and services they rely on. Critical vendors will need credible roadmaps, upgrade paths, testing evidence, support windows, and compatibility plans. Procurement teams will need to ask whether new products can support quantum-safe algorithms, whether existing systems can be upgraded, and whether replacement cycles align with the NCSC’s milestones.
Early planning can reduce cost and disruption by aligning cryptographic changes with normal technology refreshes, certificate renewals, network upgrades, and contract negotiations. Delayed action risks compressing complex changes into shorter windows, with a higher chance of outages, insecure workarounds, and expensive emergency programmes.
The board role is not to approve algorithms. It is to ensure that cryptographic risk is visible, owned, funded, and linked to wider resilience planning. That means asking which systems are most exposed, which data must remain protected over long periods, which suppliers hold dependencies, and whether replacement plans are realistic.
The UK exposure cuts across government, telecoms, finance, healthcare, defence suppliers, manufacturers, and operators of essential services. Large organisations may be able to build specialist migration programmes, while smaller entities will rely heavily on vendors, managed service providers, regulators, and sector bodies.
The NCSC is inviting continued collaboration and knowledge-sharing across organisations responsible for migration. The report’s practical value lies in moving the subject away from abstract quantum timelines and towards the work now needed inside estates, contracts, and infrastructure plans. The organisations that know where cryptography sits will be better placed to change it without disrupting the services it protects.




