The UK’s National Cyber Security Centre (NCSC) has issued new guidance to help organizations prepare for and protect against threats posed by future developments in quantum computing.
The guidance, ‘Timelines for migration to post-quantum cryptography’, emphasises the importance of using post-quantum cryptography (PQC) to help safeguard sensitive information from the future risks posed by quantum computers.
Three phases for migration to PQC are outlined in the guidance:
- To 2028 – identify cryptographic services needing upgrades and build a migration plan.
- From 2028 to 2031 – execute high-priority upgrades and refine plans as PQC evolves.
- From 2031 to 2035 – complete migration to PQC for all systems, services and products.
NCSC Chief Technical Officer Ollie Whitehouse said:
“Quantum computing is set to revolutionise technology, but it also poses significant risks to current encryption methods.
“Our new guidance on post-quantum cryptography provides a clear roadmap for organizations to safeguard their data against these future threats, helping to ensure that today’s confidential information remains secure in years to come.
“As quantum technology advances, upgrading our collective security is not just important – it’s essential.”






