Post-Quantum Cryptography: The UK Board Action Plan for 2026
The UK’s National Cyber Security Centre (NCSC) is now urging organisations to begin migrating to post-quantum cryptography before quantum computers render current encryption standards obsolete — and the threat is closer than most boards assume.
Why Should UK Boards Care About Quantum Computing Threats Right Now?
Quantum computing is often discussed as a technology of the future — a theoretical horizon rather than an imminent operational risk. This framing is increasingly dangerous. While large-scale, fault-tolerant quantum computers capable of breaking current encryption do not yet exist commercially, the trajectory of quantum development — backed by significant state investment from China, the US, and the EU — means that the window for cryptographic migration is measured in years, not decades.
The NCSC’s guidance on post-quantum cryptography, published and updated through 2024 and 2025, is explicit: large organisations should begin factoring the threat of quantum computer attacks into their long-term planning now. The NCSC identifies public key cryptography — which underpins virtually every secure digital transaction, from TLS-encrypted web traffic to VPN connections and digital signatures — as the primary vulnerability. Current asymmetric cryptographic algorithms, including RSA and elliptic curve cryptography, are vulnerable to quantum attacks using Shor’s algorithm, which could solve the mathematical problems these systems rely on in exponentially less time than classical computers.
According to a 2026 KPMG analysis of board quantum readiness, only a small minority of business leaders currently identify quantum computing as among the most impactful technologies over the next three years — despite the growing consensus among security researchers that cryptographically relevant quantum computers could be operational within a decade. This gap between expert concern and boardroom awareness is precisely where the risk lies.
Executive Action
- Instruct your CISO to assess which cryptographic systems your organisation currently relies on and which are vulnerable to quantum attack — beginning with public key infrastructure, digital certificates, and VPN encryption.
- Request a board briefing on the NCSC’s post-quantum migration timeline guidance and what it means for your sector’s critical data and systems.
- Include post-quantum cryptography in your organisation’s 3–5 year technology and security roadmap — not as a future consideration, but as an active programme.
What Is “Harvest Now, Decrypt Later” and Why Is It a Board-Level Risk Today?
“Harvest now, decrypt later” (HNDL) is one of the most significant and least understood threats in the current cyber risk landscape. The attack model is straightforward: adversaries — including nation-state actors — are intercepting and storing encrypted data today, in anticipation of using quantum computers to decrypt it in the future. The data collected now may include sensitive government communications, intellectual property, financial information, personal health records, and classified commercial contracts.
For UK boards, this means that data your organisation is transmitting and storing today may be at risk — not in 2035 when quantum computers become viable, but right now, because the collection is happening now. This is not a speculative risk. Security agencies including the NCSC, NSA, and CISA have all identified HNDL as an active threat vector. Data with long-term sensitivity — including trade secrets, merger and acquisition information, long-lived personal data, and strategic plans — is particularly exposed.
The implication is stark: waiting until quantum computers are available before beginning cryptographic migration is not a viable strategy. By the time a cryptographically relevant quantum computer exists, the adversary already holds the data. Migration to post-quantum cryptographic standards must begin now to protect data that is sensitive today and will remain sensitive when quantum decryption becomes possible.
Executive Action
- Identify which data your organisation holds or transmits that has long-term sensitivity — trade secrets, personal data, regulated financial information, strategic plans — and treat HNDL as a live risk for this data category.
- Review your organisation’s data retention and transmission security policies with HNDL in mind — consider whether sensitive data currently transmitted over public networks needs additional protection now.
- Brief your board’s Risk Committee on HNDL as a current threat, not a future scenario — and ensure it is captured in your organisation’s threat intelligence reporting.
What Does the NCSC’s Post-Quantum Guidance Require UK Organisations to Do?
The NCSC has published detailed guidance on post-quantum cryptography migration, including a white paper setting out its position on mitigating the quantum computing threat to cryptography, and updated timelines for migration to post-quantum cryptographic standards. The NCSC’s recommended approach follows a phased framework: discovery, prioritisation, migration, and validation.
In the discovery phase, organisations are expected to develop a comprehensive inventory of all cryptographic systems in use — including embedded cryptography in enterprise software, cloud platforms, IoT devices, and operational technology. This is more complex than it sounds: cryptography is pervasive in modern enterprise IT, and many organisations have limited visibility into where specific algorithms are deployed, particularly in vendor-supplied systems.
The US National Institute of Standards and Technology (NIST) finalised its first post-quantum cryptographic standards in July 2022 — including CRYSTALS-Kyber (for key encapsulation) and CRYSTALS-Dilithium (for digital signatures). These NIST standards form the basis for international migration, and the NCSC has endorsed this direction for UK organisations. According to NCSC guidance published in 2024, large organisations in high-risk categories should aim to complete migration of their highest-priority systems to post-quantum standards by 2035, with planning beginning now and early migration in highest-risk areas accelerated significantly ahead of this date.
Executive Action
- Commission a cryptographic inventory — a systematic audit of which cryptographic algorithms and protocols are in use across your organisation’s systems, applications, and supplier integrations.
- Prioritise migration planning for systems that protect the most sensitive long-term data or that underpin critical business processes — these should move first.
- Engage your technology vendors and cloud providers to understand their post-quantum migration roadmaps and timelines, particularly for systems where your organisation cannot control the underlying cryptographic implementation.
How Should UK Boards Structure a Post-Quantum Migration Programme?
Post-quantum cryptography migration is a multi-year programme that requires board-level sponsorship, dedicated resource, and coordination across technology, security, legal, and procurement functions. It is not a project that can be owned exclusively by the CISO — the scale of change required, and its intersection with vendor management, regulatory compliance, and strategic planning, makes it a board and executive committee issue.
Boards should ensure that a named executive owns the post-quantum migration programme and that progress is reported against defined milestones. The programme should include four workstreams: cryptographic discovery (inventory of current algorithms), risk prioritisation (identifying highest-risk systems), vendor engagement (understanding and managing third-party migration timelines), and governance (board reporting, risk register inclusion, and integration with the organisation’s broader cyber strategy).
Critically, the board should understand that post-quantum migration is not solely a technical undertaking. It intersects with regulatory compliance — the FCA’s operational resilience framework, the UK Cyber Security and Resilience Bill’s forthcoming requirements, and sector-specific regulators’ expectations around cryptographic adequacy will all evolve as quantum threats mature. Boards that begin now will be positioned to comply as requirements emerge, rather than facing costly emergency remediation.
The INFORMD cybersecurity and resilience assessment tools and executive briefing library include frameworks for board-level cyber risk oversight. The INFORMD team can support boards in understanding how post-quantum risk fits within their broader operational resilience and technology governance frameworks.
Executive Action
- Establish a post-quantum migration programme with named executive ownership, board-level sponsorship, and defined reporting milestones — beginning in 2026.
- Add post-quantum cryptography risk to your organisation’s risk register with an explicit risk appetite statement and a timeline for achieving defined migration milestones.
- Engage your board’s Risk or Audit Committee to ensure that post-quantum migration progress is reviewed at least annually — and that the board understands the HNDL threat is live, not future.
INFORMD provides intelligence briefings, tools and frameworks for senior business leaders across technology, finance, strategy and compliance. Based in Milton Keynes, UK, we help executives stay informed and act with confidence. Explore our full briefing library or access our free assessment tools.
