UK companies should start preparing now, with the work scaled to the systems they control. A small business using hosted services should establish what suppliers will update and what remains its responsibility. A company running bespoke applications or infrastructure needs a migration plan. The NCSC’s roadmap sets targets for discovery and planning by 2028, high-priority migrations by 2031 and completion by 2035. Those dates guide preparation, not predictions of when quantum attacks will become possible.
What post-quantum cryptography means for a smaller business
Post-quantum cryptography, or PQC, uses mathematical techniques designed to resist attacks from quantum computers. The NCSC identifies it as the primary mitigation for the future threat to asymmetric, or public-key, cryptography.
For a buyer, the distinction matters because “we already encrypt our data” does not settle the question. The assessment must identify which cryptographic mechanisms a system uses and which need upgrading. The NCSC’s discovery milestone specifically asks organisations to find services and infrastructure that depend on cryptography.
There is also a reason to consider information that must remain confidential for years. Ampcus Cyber describes the “harvest now, decrypt later” threat, in which an attacker stores encrypted information for possible decryption once sufficiently capable quantum computers exist. This is a risk mechanism, not proof that a particular company’s data has been collected.
Consider a hypothetical British engineering business sharing valuable designs with manufacturing partners. Its planning question is how long those designs need protection, which systems transmit them and who can upgrade those systems. Headcount alone is a poor basis for deciding how much preparation it needs.

Use the UK milestones to schedule decisions
The NCSC describes its dates as indicative timelines and key targets. Its guidance is primarily aimed at larger organisations, critical infrastructure operators and companies with bespoke IT, although the core dates are relevant more widely.
| Target year | NCSC milestone | Practical interpretation for a smaller business |
|---|---|---|
| 2028 | Define goals, complete discovery and create an initial migration plan | Identify affected services, record supplier responsibilities and assign an owner to unresolved systems |
| 2031 | Carry out early, highest-priority migrations and refine the roadmap | Complete priority changes and have a credible route for the remaining estate |
| 2035 | Complete migration across systems, services and products | Verify completion against the inventory and record any unresolved exceptions |
The milestone descriptions come from the NCSC roadmap. The smaller-business interpretations are CTC’s suggested way to turn them into manageable work. TechUK’s account of the migration timeline also sets out the NCSC’s key dates.
Do not read 2028 as permission to postpone discovery until that year. Discovery and an initial plan are the intended outcomes by then. Nor should 2035 become a forecast for the arrival of an encryption-breaking quantum computer. The roadmap supplies migration targets, not that prediction.
Start with the systems you control
The most useful first distinction is between systems a supplier operates and systems your business must change itself. The NCSC expects many smaller organisations to migrate through normal supplier upgrades, while more complex estates may require substantial planning and investment.
A business using hosted accounting, email and document services should begin by requesting written migration information from those suppliers. A business maintaining its own application, remote-access infrastructure or connected product should also establish who can assess and change the underlying technology.
Use the following responsibility map as a proposed starting point. It is an operating model, not a description of any supplier’s contract.
| Area | Suggested lead | Evidence to collect |
|---|---|---|
| Hosted business applications | Business owner or IT manager | Supplier roadmap, affected services and any customer actions |
| Staff devices and locally managed software | Internal IT team or support provider | Supported versions, update ownership and unresolved dependencies |
| Bespoke applications and integrations | Development lead or contracted developer | Relevant components, upgrade requirements and compatibility test results |
| Network equipment and remote access | Infrastructure owner or managed service provider | Product-specific migration information and replacement requirements |
| Sensitive information | Information owner | Required confidentiality period and consequences of disclosure |
| Overall migration | Named business sponsor | Priorities, budget, accountable owners and acceptance evidence |
An external provider can perform discovery or testing, but the business should retain the decision about priorities. Ask for an inventory and findings that another competent provider could use if the relationship ends.
What preparation should cost
There is no defensible universal price for preparing a UK small business for PQC in the supplied evidence. The NCSC warns that migration costs can be significant and says organisations should budget for preparation as well as implementation.
Build a budget around work packages rather than a single “quantum-safe” purchase. For supplier-operated services, establish whether updates are included in the existing agreement and whether customer configuration or testing will cost extra. For systems you operate, request separate estimates for discovery, dependency analysis, upgrades, compatibility testing and ongoing support.
Replacement hardware, application changes, staff training and migration assistance should appear where required. They should not be assumed necessary across the whole estate, or assumed to cost nothing because a software update is available.
For an assessment quotation, specify the systems in scope, required deliverables, exclusions, access arrangements and handover format. Require GBP pricing, VAT treatment and a clear distinction between the assessment fee and subsequent remediation. A low assessment price is not a complete migration budget.
Compare supplier evidence on the same terms
The available evidence does not support a current readiness ranking of Google Cloud, AWS, Microsoft, open-source projects or UK managed service providers. It contains no comparable set of their product-specific implementation documents. A ranking would therefore imply verification that has not happened.
Instead, compare the suppliers already responsible for your estate against identical questions. Request the exact service or product version covered, the protection being changed, the supported upgrade route, customer actions, exclusions and evidence of successful deployment. Separate an announced roadmap from functionality available in the product you actually use.
The delivery options also deserve different scrutiny.
| Approach | When to consider it | What to establish before relying on it |
|---|---|---|
| Existing supplier delivers the upgrade | Hosted services and supported commercial products | Whether your specific service is covered and what you must configure or test |
| Internal team implements changes | Bespoke applications or infrastructure under your control | Skills, dependencies, maintenance responsibility and acceptance criteria |
| Existing UK support provider coordinates migration | An estate already covered by an outsourced support agreement | Whether discovery, testing and application work fall within its contracted scope |
| Specialist adviser assesses difficult systems | Unclear dependencies or a migration beyond the team’s experience | Deliverables, implementation boundaries, evidence quality and handover arrangements |
These are procurement criteria, not ratings of particular providers. Keeping an existing service can be a sound choice when its supplier can demonstrate a suitable upgrade path. Switching supplier should follow an identified gap, rather than an unsupported claim of market leadership.
Editorial analysis
CTC’s view is that the first useful deliverable is a short, owned list of affected systems, supplier commitments and unresolved questions. That makes the NCSC’s discovery target actionable without assuming every small business needs a separate cryptography programme.
Prioritise investigation where valuable information needs lasting confidentiality, systems are difficult to replace or responsibility is unclear. Use normal renewals and replacement decisions to secure better answers from suppliers.
The distinction between preparation and deployment should remain explicit. Starting preparation now does not mean changing production cryptography without supported implementation guidance, compatibility testing and a recovery plan. The business needs evidence that a change protects the intended service and still lets people do their work.
Sources
- National Cyber Security Centre — Timelines for migration to post-quantum cryptography, 20 March 2025
- National Cyber Security Centre — Cyber chiefs unveil new roadmap for post-quantum cryptography migration, 20 March 2025
- Ampcus Cyber — What Are NIST’s Finalized Post-Quantum Cryptography Standards?, 16 July 2026
- TechUK — National Cyber Security Centre publishes timelines for migration to post-quantum cryptography