Setting direction for the UK's migration to post-quantum cryptography
Why the key milestones for PQC migration are part of building and maintaining good cyber security practice.
Our advice & guidance covers a broad range of topics
Resources for individuals and organisations in the UK who have experienced an online scam or cyber attack.
Find a range of products & services from NCSC and certified 3rd party suppliers
Working with industry, government and academia to support the next generation of researchers, students and cyber security professionals
All the latest information to help you keep track of what's happening

In our 2023 white paper, the NCSC outlined the need to prepare for migration to post-quantum cryptography (PQC) due to the threat to cryptography posed by future developments in quantum computing.
Along with the technical messages in that paper, we also described our responsibilities to supporting UK government and our regulated CNI sectors, and to grow the UK skills base in PQC.
We know that PQC migration can feel like a daunting challenge for many organisations. It is a multi-year effort that will span more than one investment cycle, and needs careful planning. So, we are introducing new guidance, ‘Timelines for migration to post-quantum cryptography’, that sets out some of the key milestones in planning and delivering your migration.
Migration to PQC can be viewed as any large technology transition. In the guidance, we describe the key steps in such a transition, and illustrate some of the cryptography and PQC-specific elements required at each stage of the programme. We also discuss how the challenge will vary between different sectors, and how the PQC ecosystem is likely to evolve following the work of industry developers and international standards bodies.
The guidance defines three phases for migration.
The first of those involves carrying out a full discovery exercise to understand your estate, and identify services that are dependent on cryptography that will need to be upgraded to PQC. This then enables you to build an initial migration plan, identifying priority services for migration. 2028 is the target date for completing all of this.
The second phase is carrying out the highest priority migration activities that you have identified, and refining your plan as the PQC ecosystem develops so that you have a thorough roadmap for completing migration. You should aim to complete this phase in 2031.
The third phase is to complete migration to PQC of all your systems, services and products, with 2035 as your target.
For many SMEs, migration will be routine; your service providers will deliver PQC as part of their normal upgrades. However, for some large organisations, PQC migration will require significant investment. Other companies will have a mixed estate, with most of their migration managed relatively easily, but with some systems needing particular attention. We hope that setting these dates helps with the planning and the investment cases.
For everyone, though, the activities that underpin migration (careful management of technology assets, building a good understanding of your systems and services, and understanding your suppliers and their plans) are part of building and maintaining good cyber security practice. So although our guidance is primarily for risk owners of large organisations, CNI operators and companies that have bespoke IT, the key messages and the critical timelines in it are relevant to all organisations.


