A future threat creates work today

A sufficiently capable quantum computer could break public-key algorithms used to protect identities, software updates and confidential communications. Nobody can give a reliable arrival date, but large migrations take years and some encrypted information remains sensitive for a long time. That creates a harvest-now, decrypt-later risk. Organisations with long-lived secrets cannot wait for a dramatic hardware announcement before finding out where vulnerable cryptography lives.

The British milestones

The NCSC asks organisations to complete discovery and planning by 2028, migrate the highest-priority systems by 2031 and complete migration by 2035. These are planning targets, not a prediction that current encryption fails on one date. The first deadline is the most revealing. Before buying products, an organisation must find certificates, VPNs, identity systems, embedded devices, code signing, archives and supplier services, then rank them by sensitivity and replacement difficulty.

Prepare for another change

A public website certificate replaced frequently is different from a root of trust embedded in equipment expected to last fifteen years. Suppliers should explain which post-quantum standards their products will support and whether algorithms can be changed without replacing hardware. Implementations will mature, so cryptographic agility is more valuable than a one-off swap. Britain’s roadmap turns an abstract quantum debate into ordinary programme management: inventory, prioritise, test and migrate.

UK TECH TRENDIndependent analysis for the British technology market.

Continue to all articles