
The UK now has published dates for post-quantum migration. The National Cyber Security Centre’s guidance on PQC migration timelines sets out three milestones, in 2028, 2031 and 2035, and each one is written as an outcome rather than an intention.
That matters, because most post-quantum planning still runs on open-ended horizons. “Before a cryptographically relevant quantum computer exists” is not a date anyone can build a budget or a programme around. 2028 is.
The three milestones
NCSC breaks migration into three phases:
- By 2028Define your migration goals, carry out a full discovery exercise across the estate, and build an initial plan for migration.
- By 2031Carry out your early, highest-priority migration activities, and refine that initial plan into a thorough roadmap for completing the work.
- By 2035Complete migration to post-quantum cryptography across all your systems, services and products.
Source: NCSC guidance on PQC migration timelines.
This is guidance rather than law. It carries no statutory force and it does not require any organisation to deploy a specific algorithm by a specific date. What it does provide is a published reference point, with dates attached, that boards, auditors, insurers and enterprise customers can all now ask questions against.
Not every organisation faces the same task
NCSC is candid that the burden is uneven, and it splits organisations into two groups.
Smaller organisations that consume IT as a service largely inherit the transition. In NCSC’s words, for such organisations “PQC migration will be more straightforward and should happen seamlessly, as services are updated by their vendors.” If you buy your systems and someone else runs them, most of this arrives as a supplier upgrade.
Large organisations, and anyone running their own IT infrastructure, are in a different position entirely. For them, NCSC expects the preparatory work alone to take two to three years, covering discovery and assessment exercises, defining a migration strategy, and building an initial migration plan. It then expects a further two to three years to carry out early migration activities and refine the plan.
Why 2028 is closer than it reads
Work the arithmetic backwards. If the preparatory phase takes two to three years, and it has to be finished by 2028, the start line sits in 2025 or 2026. NCSC says as much directly: organisations “should be beginning or continuing their preparation for migration to PQC now.”
2028 is not when discovery starts. It is when discovery, assessment, strategy and an initial plan are all expected to be finished.
Read that way, the timeline is less generous than it first appears. An organisation that opens the question in 2027 has compressed a two-to-three-year exercise into a single year, and will be building its migration strategy on an incomplete picture of its own estate.
The first milestone is an inventory milestone
It is worth being precise about what the 2028 phase actually asks for, because it is not a cryptography task in the first instance.
NCSC describes the discovery exercise as “assessing your estate to understand which services and infrastructure that depend on cryptography need to be upgraded to PQC”. In practice that means building a clear understanding of the current estate: identifying key services, documenting data holdings and their lifetimes, and mapping how data protection actually works across systems.
That is an asset problem before it is an algorithm problem. You cannot sequence a migration across systems you have not found, and you cannot defend a prioritisation decision to a board without knowing what the estate contains, where the exposure sits, and which data has to stay confidential well beyond 2035.
The instruction to document data lifetimes is the one most directly tied to harvest now, decrypt later. Data captured in transit today and stored by an adversary stays exposed for as long as it needs to remain confidential, which is why retention periods, not just system criticality, belong in the prioritisation.
Where the roadmap maps onto ECEM
NCSC’s three phases describe a sequence that Enterprise Cryptographic Exposure Management (ECEM) already formalises as six continuous stages:
- Discover cryptographic assets across endpoints, servers, applications, databases, PKI, HSMs, cloud environments and source code repositories.
- Inventory what you find as a living Enterprise CBOM (Cryptography Bill of Materials) rather than a point-in-time spreadsheet.
- Assess cryptographic exposure and business impact, using business context alongside recognised industry guidance.
- Prioritise remediation where it delivers the greatest reduction in cryptographic exposure.
- Transition to post-quantum cryptography through a practical, phased roadmap.
- Monitor and improve cryptographic posture continuously as the environment changes.
The first two stages carry almost the whole weight of the 2028 milestone. Assess and Prioritise are what turn that inventory into the “thorough roadmap” the 2031 milestone expects. Transition is the execution window between 2031 and 2035. Monitor is what stops the picture going stale in the years in between, which matters both because estates change constantly and because parts of the standards landscape are still evolving.
What to do with the date
Three practical takeaways from the guidance:
- Treat 2028 as a delivery date for a completed discovery exercise, not as a start date.
- Establish which side of NCSC’s split you genuinely sit on. Organisations that run their own infrastructure, carry legacy or custom systems, or hold long-lived sensitive data should assume the two-to-three-year preparatory estimate applies to them.
- Start with the estate rather than the algorithms. The standards question is largely settled; the question of what cryptography you are actually running, and where it is exposed, is the one that takes years to answer.
A published timeline is genuinely useful. It converts an open-ended risk into a planning problem with dates, phases and a defined end state. The organisations that will meet it comfortably are the ones treating the first milestone as the discovery and inventory exercise it plainly is, and starting it now.
Further reading: PQC migration planning, building an Enterprise CBOM, and our whitepaper on Understanding Enterprise Cryptographic Exposure Management.