Post-quantum migration could become Britain’s next Y2K-scale IT programme

Post-quantum migration could become a vast, largely invisible IT programme. British businesses should fund discovery and supplier coordination now, while separating routine upgrades from systems that genuinely need replacement.

7 min read
Read with AI

Open in

ChatGPT Claude Perplexity

This page

Copied to clipboard
A realistic editorial photograph inside a Midlands engineering workshop during an early morning maintenance window. An engineer seen from behind inspects an ageing industrial control cabinet beside a

America’s accelerated post-quantum migration programme strengthens the case for treating cryptographic replacement as a board-level investment programme in Britain. My position is that its reach could justify the Y2K comparison, but blanket replacement would waste money. UK leaders should fund discovery and supplier coordination now, then separate routine upgrades from systems needing substantial intervention. The immediate decision is who owns that work, not when quantum computers will arrive.

America has turned a future threat into scheduled work

The significant detail in the US announcement is the assignment of responsibility. Agencies are directed to appoint migration leads, while the Department of Commerce must initiate the pilot. The announcement also calls for work to identify cost savings across the migration programme. The White House fact sheet describes an implementation programme with owners and milestones.

British boards should take that organisational signal seriously. My expectation is that overseas procurement programmes will increase pressure on international suppliers to explain their migration plans. A UK buyer should ask how those plans cover its particular services, versions and contracts.

Britain already has its own planning framework. The NCSC describes migration as a mass technology change spanning years and, in large organisations, multiple leadership cycles. Its targets provide a basis for investment decisions without pretending to predict the arrival of a threatening quantum computer. NCSC migration timelines

That distinction matters for the headline. “Y2K-scale” is an editorial comparison about reach, coordination and work that customers may never see. The available evidence does not establish that PQC will exceed other programmes in expenditure or equipment replaced.

Map services before funding PQC changes
UK leaders map important services and supplier responsibilities, then choose routine upgrades, targeted integration work or replacement based on assessed need.

The British problem is finding what needs to change

Post-quantum cryptography, or PQC, uses mathematical approaches intended to resist attacks from both conventional and quantum computers. The relevant migration concerns vulnerable public-key cryptography, which supports functions including protected communications and digital signatures. NIST explains the underlying purpose.

For a business owner, the useful question is which services depend on that cryptography and who can change them.

The NCSC recommends identifying important services, the data they process, its expected lifetime and its protection in transit and storage. It also explicitly includes networking equipment, virtual private networks, user tokens, mobile devices and industrial systems within discovery. NCSC discovery and assessment guidance

I would turn that guidance into a service map before commissioning an exhaustive component inventory. The NCSC itself says initial discovery is not intended to be a formal asset register. Its purpose is to understand systems well enough to plan their migration.

An illustrative British manufacturer might therefore examine remote maintenance access, factory equipment and its customer portal as separate services. Each would need an owner, a supplier response and an assessment of what could interrupt production. This is a proposed planning example, not a customer case study.

For certificates, identity systems and encrypted archives, ask where vulnerable public-key mechanisms actually sit. The presence of encryption alone is not a sufficient reason to replace a system.

Put responsibility at the connections between services

A supplier’s migration plan is only useful when it explains the customer’s part of the change. The NCSC’s July 2026 workshop report identifies supplier readiness, early engagement and alignment with normal refresh cycles as central issues.

The following responsibility model is an editorial recommendation.

| Workstream | Proposed accountable owner | Evidence to request before approval |

| --- | --- | --- |

| Data and service priorities | Business service owner | Data lifetime, operational importance and consequences of interruption |

| Product upgrade route | Product supplier, coordinated by internal IT | Supported versions, dependencies, upgrade path and exclusions |

| Connections between systems | Internal engineering team or systems integrator | Compatibility test results and a documented rollback procedure |

| Managed services | Customer service owner and managed provider | Written division of discovery, deployment, testing and support duties |

| Investment decisions | Executive sponsor and procurement | Phased costs, unresolved dependencies and acceptance conditions |

This model connects business priorities to technical work. It also makes a useful procurement test possible. If nobody accepts responsibility for checking the complete service after its components change, the proposal is incomplete.

Budget for discovery and testing before replacement

The NCSC warns that migration costs could be significant and says budgets should cover preparation as well as implementation. Its guidance also expects many commodity platforms to receive PQC through supplier upgrades and normal hardware refresh. NCSC migration planning

Those two statements should govern spending. Neither “everything must be replaced” nor “the supplier will handle everything” is a credible starting assumption.

There is no defensible standard GBP price for the work in the available evidence. Buyers should compare quotations against the same service boundary, including discovery, engineering, testing, staff time, support and any eventual replacement.

Three delivery approaches deserve consideration.

| Approach | Where I would consider it | Costs and responsibilities to clarify |

| --- | --- | --- |

| Existing supplier upgrades | Supported, standard technology with a documented migration route | Included updates, customer testing, support and any required refresh |

| Targeted integration work | Bespoke applications or connections that standard upgrades do not resolve | Engineering, specialist advice, test environments and ongoing maintenance |

| Re-platforming or replacement | Systems without a credible supported upgrade path | Procurement, data migration, retraining, disruption and retirement of the old system |

This compares delivery choices rather than ranking named suppliers. Product-level recommendations require verified evidence about particular editions, implementations and support terms, which is not established here.

My buying rule would be simple. Fund enough discovery to distinguish these approaches, then approve implementation against demonstrated need. Require each quotation to identify work already covered by existing subscriptions or support contracts.

The strongest objection is that suppliers will do most of it

For many smaller businesses, that objection is correct.

The NCSC explicitly expects migration to be straightforward for SMEs relying mainly on standard browsers, operating systems and mobile devices, with changes arriving through vendor updates. Its explanation of the UK migration direction also distinguishes routine migration from the significant investment some larger organisations will face.

That is a strong argument against selling every small company a large consultancy programme. It is not a reason to leave ownership undefined.

A small firm should establish whether its technology fits that routine category and identify exceptions. A supported office application and a bespoke operational system should not receive the same treatment merely because both belong to the same small business.

The uncertainty over quantum computing strengthens the case for proportionate preparation. NIST acknowledges that the arrival date is unknown. Discovery, supplier questions and sensible refresh planning remain useful without committing to an early wholesale replacement.

Editorial analysis

Britain’s commercial opportunity lies in resolving the difficult exceptions. The NCSC’s 2025 annual review calls for more UK consultancies with suitable expertise and records the start of its assurance pilot. That supports the existence of an emerging market, but not a forecast of its eventual value.

My judgement is that buyers should reward firms that can explain a dependency, demonstrate a migration and leave the customer with maintainable documentation. A discovery report has limited value if it cannot guide procurement or engineering decisions.

The first board request should therefore be a named sponsor, a map of important services and a list of supplier questions with unresolved answers. For a small business, that may be manageable within its existing IT relationship. For a complex organisation, it becomes the foundation of a funded programme.

Post-quantum migration earns the Y2K comparison through the breadth of coordination it may demand. British leaders should respond by organising that work early, while preserving the option to update, retain or replace each system on evidence.

FAQ

Does every UK business need a major replacement programme?

No. The NCSC expects many SMEs using commodity technology to receive PQC through normal supplier updates. Bespoke or specialised systems need separate assessment, so business size alone does not determine the workload.

Is 2035 a universal legal deadline?

The cited NCSC guidance presents 2035 as a migration target, not a universal statutory deadline for every British business. Sector rules and contractual obligations require separate assessment. This is not legal advice; consult your legal counsel.

Why prepare before powerful quantum computers exist?

NIST describes the risk of capturing encrypted data now for later decryption, particularly where secrets retain their value. The NCSC also prioritises systems that are difficult or infrequent to change. Preparation addresses those long lead times without assuming a specific breakthrough date.

What should we ask our IT provider first?

Ask which services it has assessed, which upgrades it expects to deliver and which tasks remain your responsibility. Request a written response covering dependencies, testing, support and charges. This follows the emphasis on early supplier engagement in the NCSC migration workshop report.

Sources

UK post-quantum migration target years. Source: NCSC, Timelines for migration to post-quantum cryptography
NCSC target years for initial planning, highest-priority migration activities and completion, shown as calendar milestones rather than forecasts of quantum computing capability.