Skip to content

National Cyber Security Centre (UK)

The UK's cyber security authority, and its dated timeline for completing post-quantum migration.

United Kingdommigration timeline

Why this is listed

The 2028, 2031 and 2035 dates are the authority's own migration guidance, published in its own name rather than assembled from what other bodies have said.

The NCSC describes itself as part of GCHQ, helping businesses, the public sector and individuals protect the online services and devices everyone depends on. Its post-quantum migration guidance puts three dates on the work: by 2028, define migration goals, carry out a full discovery exercise and build an initial plan; by 2031, carry out the earliest and highest-priority migration activities and refine that plan into a thorough roadmap; by 2035, complete migration of all systems, services and products.

It states the reasoning behind the end date: that ten years is a sufficient period for a rich set of post-quantum standards to appear, for an ecosystem of products using them to be developed, and for uptake to become widespread. The guidance is addressed primarily at large organisations, operators of critical infrastructure and anyone running bespoke IT, and says smaller organisations on commodity software should still follow a similar schedule where custom components exist.

Sources

Checked against these sources on Sep 4, 2026. Listing is not endorsement, and nothing here is ranked or scored.