NCSC workshop highlights the need for coordinated post-quantum cryptography migration
The UK National Cyber Security Centre (NCSC), Vodafone and the National Cyber Advisory Board have called for closer cooperation between government, industry and academia as organisations prepare to ad...
The UK National Cyber Security Centre (NCSC), Vodafone and the National Cyber Advisory Board have called for closer cooperation between government, industry and academia as organisations prepare to adopt post-quantum cryptography (PQC).
The message followed a migration workshop held in December 2025, attended by security leaders and specialists responsible for cryptography and technology resilience. The event focused on sharing practical challenges and approaches, with participants stressing that no organisation can manage the transition in isolation.
Why preparation needs to start now
Future quantum computers could undermine many of the public-key cryptographic systems currently used to protect networks, applications and data. PQC algorithms are intended to provide protection against both quantum and conventional computing attacks.
The NCSC has published migration milestones, including targets for 2028 and 2031. Although those dates may seem distant, the workshop highlighted that complex technology estates, long-lived hardware and supplier dependencies mean that discovery and planning should begin immediately.
Building support at board level
Participants said migration is more likely to succeed when it is presented as a business resilience and risk-management issue rather than solely as a technical upgrade. Organisations were encouraged to appoint a senior sponsor, explain the cost and consequences of delay, and connect PQC work with existing priorities such as legacy-system replacement, compliance and wider cyber resilience.
Early preparation can strengthen the business case. This may include identifying critical systems and sensitive data, assessing supply-chain dependencies and determining which assets will take longest to update. A phased roadmap, with clear milestones, funding requirements and skills needs, can then give senior decision-makers a practical view of the programme.
Supply chains are part of the migration
The workshop also identified supplier readiness as a central dependency. Organisations should raise PQC with vendors early, understand their migration plans and make requirements clear during procurement and security assessments.
Where possible, PQC capabilities should be incorporated into normal technology refresh cycles. Products that support the relevant algorithms—or can be upgraded to do so—may help reduce disruption and avoid an expensive, compressed transition later.
The NCSC said continued collaboration and the exchange of real-world experience will be essential as organisations turn guidance into coordinated migration plans.
