A realistic editorial photograph inside a small British precision engineering workshop in late afternoon. Two staff members, seen from behind with no identifiable faces, review a laptop beside a conne

When UK businesses should prepare for post-quantum cryptography

7 min read

UK small and mid-sized businesses should begin proportionate preparation for post-quantum cryptography, using the NCSC’s migration milestones to organise the work. Supplier evidence, system ownership and the lifetime of sensitive information should guide priorities and spending.

Daniel Thomas
Written by Daniel Thomas

UK companies should start preparing now, with the work scaled to the systems they control. A small business using hosted services should establish what suppliers will update and what remains its responsibility. A company running bespoke applications or infrastructure needs a migration plan. The NCSC’s roadmap sets targets for discovery and planning by 2028, high-priority migrations by 2031 and completion by 2035. Those dates guide preparation, not predictions of when quantum attacks will become possible.

What post-quantum cryptography means for a smaller business

Post-quantum cryptography, or PQC, uses mathematical techniques designed to resist attacks from quantum computers. The NCSC identifies it as the primary mitigation for the future threat to asymmetric, or public-key, cryptography.

For a buyer, the distinction matters because “we already encrypt our data” does not settle the question. The assessment must identify which cryptographic mechanisms a system uses and which need upgrading. The NCSC’s discovery milestone specifically asks organisations to find services and infrastructure that depend on cryptography.

There is also a reason to consider information that must remain confidential for years. Ampcus Cyber describes the “harvest now, decrypt later” threat, in which an attacker stores encrypted information for possible decryption once sufficiently capable quantum computers exist. This is a risk mechanism, not proof that a particular company’s data has been collected.

Consider a hypothetical British engineering business sharing valuable designs with manufacturing partners. Its planning question is how long those designs need protection, which systems transmit them and who can upgrade those systems. Headcount alone is a poor basis for deciding how much preparation it needs.

A business PQC migration path
UK businesses can match PQC preparation to the systems they control, then work towards the NCSC’s 2028, 2031 and 2035 targets.

Use the UK milestones to schedule decisions

The NCSC describes its dates as indicative timelines and key targets. Its guidance is primarily aimed at larger organisations, critical infrastructure operators and companies with bespoke IT, although the core dates are relevant more widely.

Target yearNCSC milestonePractical interpretation for a smaller business
2028Define goals, complete discovery and create an initial migration planIdentify affected services, record supplier responsibilities and assign an owner to unresolved systems
2031Carry out early, highest-priority migrations and refine the roadmapComplete priority changes and have a credible route for the remaining estate
2035Complete migration across systems, services and productsVerify completion against the inventory and record any unresolved exceptions

The milestone descriptions come from the NCSC roadmap. The smaller-business interpretations are CTC’s suggested way to turn them into manageable work. TechUK’s account of the migration timeline also sets out the NCSC’s key dates.

Do not read 2028 as permission to postpone discovery until that year. Discovery and an initial plan are the intended outcomes by then. Nor should 2035 become a forecast for the arrival of an encryption-breaking quantum computer. The roadmap supplies migration targets, not that prediction.

Start with the systems you control

The most useful first distinction is between systems a supplier operates and systems your business must change itself. The NCSC expects many smaller organisations to migrate through normal supplier upgrades, while more complex estates may require substantial planning and investment.

A business using hosted accounting, email and document services should begin by requesting written migration information from those suppliers. A business maintaining its own application, remote-access infrastructure or connected product should also establish who can assess and change the underlying technology.

Use the following responsibility map as a proposed starting point. It is an operating model, not a description of any supplier’s contract.

AreaSuggested leadEvidence to collect
Hosted business applicationsBusiness owner or IT managerSupplier roadmap, affected services and any customer actions
Staff devices and locally managed softwareInternal IT team or support providerSupported versions, update ownership and unresolved dependencies
Bespoke applications and integrationsDevelopment lead or contracted developerRelevant components, upgrade requirements and compatibility test results
Network equipment and remote accessInfrastructure owner or managed service providerProduct-specific migration information and replacement requirements
Sensitive informationInformation ownerRequired confidentiality period and consequences of disclosure
Overall migrationNamed business sponsorPriorities, budget, accountable owners and acceptance evidence

An external provider can perform discovery or testing, but the business should retain the decision about priorities. Ask for an inventory and findings that another competent provider could use if the relationship ends.

What preparation should cost

There is no defensible universal price for preparing a UK small business for PQC in the supplied evidence. The NCSC warns that migration costs can be significant and says organisations should budget for preparation as well as implementation.

Build a budget around work packages rather than a single “quantum-safe” purchase. For supplier-operated services, establish whether updates are included in the existing agreement and whether customer configuration or testing will cost extra. For systems you operate, request separate estimates for discovery, dependency analysis, upgrades, compatibility testing and ongoing support.

Replacement hardware, application changes, staff training and migration assistance should appear where required. They should not be assumed necessary across the whole estate, or assumed to cost nothing because a software update is available.

For an assessment quotation, specify the systems in scope, required deliverables, exclusions, access arrangements and handover format. Require GBP pricing, VAT treatment and a clear distinction between the assessment fee and subsequent remediation. A low assessment price is not a complete migration budget.

Compare supplier evidence on the same terms

The available evidence does not support a current readiness ranking of Google Cloud, AWS, Microsoft, open-source projects or UK managed service providers. It contains no comparable set of their product-specific implementation documents. A ranking would therefore imply verification that has not happened.

Instead, compare the suppliers already responsible for your estate against identical questions. Request the exact service or product version covered, the protection being changed, the supported upgrade route, customer actions, exclusions and evidence of successful deployment. Separate an announced roadmap from functionality available in the product you actually use.

The delivery options also deserve different scrutiny.

ApproachWhen to consider itWhat to establish before relying on it
Existing supplier delivers the upgradeHosted services and supported commercial productsWhether your specific service is covered and what you must configure or test
Internal team implements changesBespoke applications or infrastructure under your controlSkills, dependencies, maintenance responsibility and acceptance criteria
Existing UK support provider coordinates migrationAn estate already covered by an outsourced support agreementWhether discovery, testing and application work fall within its contracted scope
Specialist adviser assesses difficult systemsUnclear dependencies or a migration beyond the team’s experienceDeliverables, implementation boundaries, evidence quality and handover arrangements

These are procurement criteria, not ratings of particular providers. Keeping an existing service can be a sound choice when its supplier can demonstrate a suitable upgrade path. Switching supplier should follow an identified gap, rather than an unsupported claim of market leadership.

Editorial analysis

CTC’s view is that the first useful deliverable is a short, owned list of affected systems, supplier commitments and unresolved questions. That makes the NCSC’s discovery target actionable without assuming every small business needs a separate cryptography programme.

Prioritise investigation where valuable information needs lasting confidentiality, systems are difficult to replace or responsibility is unclear. Use normal renewals and replacement decisions to secure better answers from suppliers.

The distinction between preparation and deployment should remain explicit. Starting preparation now does not mean changing production cryptography without supported implementation guidance, compatibility testing and a recovery plan. The business needs evidence that a change protects the intended service and still lets people do their work.

Sources

Data & Insights

NCSC post-quantum migration target years

Calendar-year targets for discovery and planning, high-priority migration and completion, rather than forecasts of quantum computing capability.

NCSC post-quantum migration target yearsCalendar-year targets for discovery and planning, high-priority migration and completion, rather than forecasts of quantum computing capability.05001,0001,5002,0002,500Discovery and initial planDiscovery and i…High-priority migrationHigh-priority m…Migration completeMigration compl…Discovery and initial plan, Target year: 2,028High-priority migration, Target year: 2,031Migration complete, Target year: 2,035
View the data
NCSC post-quantum migration target years
CategoryTarget year
Discovery and initial plan2,028
High-priority migration2,031
Migration complete2,035
Source: National Cyber Security Centre

Frequently Asked Questions

Should a small UK business start now?

Yes, but scale the task to the systems you control. The NCSC encourages preparation now and expects many smaller businesses to receive migration through normal supplier upgrades. Begin by identifying those suppliers and asking what remains your responsibility.

Does the 2028 target mean every system must already use PQC?

No. The 2028 milestone covers migration goals, discovery and an initial plan. The later targets address high-priority migration by 2031 and completion by 2035.

Will cloud and software suppliers handle everything?

The NCSC says many smaller organisations will migrate through provider updates, but that does not establish coverage for your particular estate. Request confirmation for each relevant service and identify locally managed components or integrations that need separate attention.

Should we replace our current software immediately?

The evidence does not justify blanket replacement. The NCSC recommends preparation as part of broader security improvements and system replacement. Ask for the supported migration route before deciding whether to retain, upgrade or replace a product.

How should we choose which systems to investigate first?

CTC recommends starting with information that needs lasting confidentiality and systems with difficult upgrade paths or unclear ownership. That creates a practical investigation order before technical migration decisions are made. The NCSC roadmap calls for early, highest-priority migrations rather than simultaneous replacement of everything.

What should we ask an IT support provider to deliver?

Ask for an agreed inventory, supplier dependencies, unresolved gaps, priorities and a costed next stage. Specify who will implement changes and how successful operation will be tested. These deliverables turn the NCSC’s discovery and planning objectives into work you can review and accept.