Post-Quantum Cryptography: A UK CIO Migration Checklist
UK CIOs should begin post-quantum cryptography discovery now: the National Cyber Security Centre (NCSC) requires full system discovery by 2028 and complete migration by 2035.
Quantum computers capable of breaking today’s public-key encryption (RSA, ECC) do not yet exist, but the NCSC’s 2025 migration roadmap treats the threat as a planning certainty, not a possibility. Adversaries are already harvesting encrypted data now to decrypt later once quantum capability matures — a tactic known as “harvest now, decrypt later.” For any UK organisation holding data with a shelf life beyond 2035 — financial records, health data, IP, national security material — that clock is already running.
What is the NCSC’s timeline for post-quantum cryptography migration?
The NCSC’s roadmap sets three phases. By 2028, organisations should complete full cryptographic discovery — identifying every system, service and product that relies on vulnerable encryption — and have a migration plan drafted. By 2031, the highest-priority systems should be migrated and infrastructure prepared for full transition. Between 2031 and 2035, migration should be complete across all systems, services and products.
According to the NCSC, this guidance is aimed primarily at technical decision-makers and risk owners in large organisations, operators of critical national infrastructure, and companies running bespoke IT estates — precisely the profile of most INFORMD readers. The dates are not statutory deadlines for most commercial organisations, but regulators in financial services and critical infrastructure are expected to reference them as the baseline for “reasonable” cryptographic risk management.
Executive Action:
- Confirm ownership of the 2028 discovery deadline with the CISO and enterprise architecture lead this quarter.
- Map the roadmap’s three phases against existing technology strategy and budget cycles, not as a standalone project.
- Use INFORMD’s technology strategy review template (/templates/) to fold PQC milestones into the next strategy refresh.
Why should UK CIOs act now, not closer to 2031?
Migration timelines look distant until the discovery phase is scoped properly. Most large organisations have no accurate inventory of where encryption is embedded — in code libraries, hardware security modules, VPNs, firmware, third-party APIs and legacy systems nobody has touched in a decade. According to DigiCert’s 2026 global survey of enterprise security leaders, 87% of organisations are planning, testing or implementing quantum-safe encryption, yet only 7% have broadly deployed it, and 81% say their cryptographic libraries and hardware security modules are not yet prepared for post-quantum integration.
The UK actually leads globally on quantum-readiness awareness — 18% of UK organisations describe themselves as leading edge, ahead of the US and Australia. Awareness is not the constraint. Execution capacity is. Discovery alone can take 18–24 months in a complex estate, which means an organisation starting scoping in 2027 is already behind the NCSC’s 2028 checkpoint.
Executive Action:
- Treat 2028 as a working deadline, not a distant one — back-plan from it in this year’s budget round.
- Ask the CISO directly: “where is our cryptography inventory today, and who owns it?”
- Flag third-party and vendor cryptographic dependencies as a distinct workstream — they are the most commonly missed.
What should a CIO’s cryptographic discovery phase cover?
A credible discovery phase goes beyond scanning for TLS certificates. It should produce a full inventory of cryptographic assets across infrastructure, applications and third-party services; a risk-tiering model that prioritises systems by data sensitivity and shelf life; a dependency map showing which vendors, APIs and legacy platforms control cryptographic implementation outside the organisation’s direct control; and a migration sequencing plan aligned to the NCSC’s 2028 and 2031 checkpoints, not a single “big bang” cutover.
Crypto-agility — the ability to swap cryptographic algorithms without re-architecting systems — should become a standing design principle for any new procurement or build from this point forward, not a retrofit exercise in 2033.
Executive Action:
- Mandate crypto-agility as a non-negotiable requirement in all new technology procurement from now on.
- Commission a cryptographic asset inventory as a standalone, funded workstream — not a line item buried in a wider security budget.
- Run INFORMD’s project review checklist (/tools-assessments/) against the discovery plan before it goes to the board.
How should CIOs brief the board on quantum risk?
Boards do not need a physics lesson on quantum computing; they need a risk-and-investment case. Frame post-quantum migration the way any other multi-year infrastructure risk is framed: what is exposed, what it costs to fix on a sensible timeline versus a rushed one, and what the NCSC’s phased dates mean for capital planning. Anchoring the briefing to a named regulator timeline — rather than a hypothetical quantum breakthrough — gives the board a concrete decision point rather than a speculative one.
This is also a Companies Act 2006 governance consideration where cryptographic failure could plausibly affect long-term value or data integrity disclosures — worth a line in the annual risk register review, even before it becomes a line item in the audit committee’s agenda.
Executive Action:
- Add PQC migration as a standing item on the technology risk register reviewed with the board this year.
- Present the NCSC’s 2028/2031/2035 phases as the board’s reference timeline, not an internal IT estimate.
- Request multi-year budget sign-off in phases, matched to NCSC checkpoints, rather than a single large ask.
Want a second opinion on your organisation’s quantum-readiness posture before it reaches the board? Contact INFORMD (/contact/) to discuss a tailored briefing.
INFORMD provides intelligence briefings, tools and frameworks for senior business leaders across technology, finance, strategy and compliance. Based in Milton Keynes, UK, we help executives stay informed and act with confidence. Explore our full briefing library (/resources/) or access our free assessment tools (/tools-assessments/).
It is the process of replacing current encryption methods (RSA, ECC) with quantum-resistant algorithms before sufficiently powerful quantum computers can break them. The NCSC has set a UK roadmap running from discovery in 2028 to full migration by 2035.
Not currently for most commercial organisations — the NCSC’s dates are guidance, not statutory deadlines. However, regulators in financial services and critical infrastructure are expected to treat the roadmap as the baseline for reasonable cryptographic risk management.
The CIO typically owns the migration programme, working with the CISO on risk tiering and discovery, and enterprise architecture on implementation. The board’s role is oversight and capital allocation, not technical delivery.
Now. The NCSC’s first checkpoint, full cryptographic discovery, falls in 2028, and discovery alone can take 18-24 months in a complex estate. Starting after 2026 risks missing that checkpoint.
Stay ahead. Subscribe to INFORMD’s weekly executive briefing at informd.co.uk (/resources/).
