← Back to Halochrome
Whitepapers & Resources

The NCSC Post Quantum Cryptography Timeline, Explained: What UK Organisations Must Do by 2028, 2031 and 2035

Post Quantum Cryptography · NCSC Guidance

In March 2025, the National Cyber Security Centre published specific target dates for the UK's move to quantum resistant encryption. Its guidance, Timelines for migration to post quantum cryptography, sets 2035 as the year organisations should have completed the transition, with two earlier checkpoints in 2028 and 2031.

This is a plain English guide to what the timeline requires, which organisations it applies to, and what starting now involves in practice.

Why there's a deadline at all

The encryption that protects almost everything today, including banking, secure messaging, VPNs, digital signatures and the padlock in a web browser, relies on mathematical problems that classical computers cannot solve in any useful timeframe. A sufficiently powerful, fault tolerant quantum computer would change that. The problems that keep today's encryption safe become solvable.

Risk of data and IP loss exists now. The reason is a technique known as "harvest now, decrypt later." An attacker can copy encrypted traffic now and store it until a quantum computer can open it later. Any data with a long confidentiality life, such as health records, state secrets, intellectual property and financial information, is therefore exposed the moment it crosses a network today. The NCSC states plainly that organisations should assume sensitive encrypted data is already being collected.

This is why the timeline exists. Migrating to post quantum cryptography (PQC) is not a patch applied in the week the threat lands. It is a multi year programme that touches every system using cryptography, and the NCSC's view is that ten years is roughly what a careful transition takes.

The three phases

The NCSC divides the work into three phases, each with a target date.

By 2028: Discovery and planning

The first phase is not about deploying anything. It is about establishing what exists. Cryptography that cannot be seen cannot be migrated, and in most organisations cryptography is spread more widely than teams expect: TLS certificates, VPNs, code signing, document signing, database encryption, hardware security modules, embedded devices, third party services, and dependencies inside third party software.

Phase one is a full cryptographic discovery and inventory. It means identifying every place cryptography is used, understanding how and where each system is managed, assessing which assets are most at risk, and building a prioritised migration plan from that picture. Where a managed service provider runs systems on an organisation's behalf, this phase includes confirming that the provider is doing the same.

By 2031: High priority migration

Phase two is where migration begins in earnest, starting with the systems that matter most: the highest risk and highest value assets first. This is usually where hybrid approaches are deployed, running classical and post quantum algorithms together during the transition, and where customer facing and critical systems are upgraded. Plans are refined through this phase as the surrounding standards and products mature.

By the 2031 checkpoint, critical and high priority systems should be quantum safe.

By 2035: Full migration

The final phase completes the transition across all remaining systems, services and products, and retires the quantum vulnerable algorithms still in use. The NCSC accepts there will be a tail of technologies where migration is harder, but it expects all organisations to work toward the 2035 target rather than treat it as optional.

The end state is not only new algorithms in place. It is crypto agility: the ability to change cryptographic algorithms in future without another decade long programme. The organisations that come through this well will be the ones that reach a point where changing cryptography has become routine.

Who this applies to

The guidance is aimed mainly at technical decision makers and risk owners in larger organisations, operators of critical national infrastructure including industrial control systems, and organisations running bespoke IT.

For many small and medium sized organisations, migration will arrive quietly, delivered by vendors as part of normal product updates. For those organisations, the work is mostly vendor management: identifying which suppliers have credible PQC roadmaps and holding them to those roadmaps.

For organisations that build their own systems, operate infrastructure others depend on, handle data with a long secrecy life, or work in a regulated sector such as finance, defence, healthcare or telecoms, the timeline applies directly, and the 2028 discovery deadline is the one to plan against now.

The standards underneath it

The migration has a defined destination. In 2024, the US National Institute of Standards and Technology (NIST) finalised the first post quantum standards, and the NCSC's guidance aligns with them. Three matter most in practice:

What starting now involves

The NCSC's central message is to start now, and for most organisations that means beginning the discovery phase. Everything else depends on it, and it usually takes longer than teams budget for.

The first step is establishing who owns cryptographic risk within the organisation. A cryptographic discovery exercise then builds the inventory, which identifies the highest risk data and systems. That inventory becomes a prioritised roadmap mapped to the 2028, 2031 and 2035 checkpoints. The roadmap then supports budget decisions, sequences the work, and demonstrates to regulators and customers that the organisation is on track.

Where this sits for UK organisations

Post quantum migration is unusual among security programmes because the deadline, the standards and the phasing are already defined by the UK's own national technical authority. That removes much of the ambiguity and raises the expectation on execution. By 2031, being able to show progress against the plan will matter.

Halochrome works with UK organisations across the full encryption lifecycle, from the cryptographic discovery and readiness assessment that phase one calls for, through to migration and operational integration, aligned to NCSC direction and the underlying international standards. As a UK based capability, Halochrome is set up for organisations for whom the location of their cryptographic expertise and supply chain is itself part of the risk picture.

For organisations mapping themselves against the 2028 checkpoint, a readiness assessment is a natural first step. It produces the cryptographic inventory and prioritised roadmap that the NCSC's first phase asks for. Halochrome provides these assessments and is happy to discuss how the timeline applies to a specific estate.

Speak to an expert →