Quantum computing still sounds like a distant concern. For UK businesses, it isn't something we can leave until 2034.
The National Cyber Security Centre (NCSC) has set clear milestones for moving to post-quantum cryptography (PQC):
- By 2028: complete discovery and create an initial migration plan.
- By 2031: migrate the highest-priority systems.
- By 2035: complete migration across systems, services and products.
The NCSC says this work should start now. The reason is simple: much of the public-key encryption used today is expected to be vulnerable to sufficiently powerful quantum computers.
The often-cited 95% figure describes the estimated share of current encryption that depends on quantum-vulnerable public-key methods. It isn't an official NCSC statistic, and it doesn't mean every password hash or piece of symmetric encryption will suddenly fail. However, it highlights the scale of the change ahead.
For many small and mid-sized businesses, the first challenge is more basic: we don't yet have a clear record of where encryption is being used.
What is post-quantum cryptography?
Encryption turns readable information into a protected form. Only someone with the right key can read it.
Most modern businesses use encryption for:
- Websites and customer portals
- Email and file transfers
- Virtual private networks
- Cloud applications
- Remote access
- Digital certificates
- Software updates
- Secure connections between servers
- Data stored on laptops, servers and backup systems
Some of this protection relies on mathematical problems that are difficult for today's computers to solve. A sufficiently advanced quantum computer could solve some of those problems much faster.
Post-quantum cryptography uses different mathematical methods designed to remain secure against both traditional and quantum computers.
In practical terms, PQC isn't a new app that we download. It will become part of operating systems, browsers, cloud platforms, firewalls, VPNs, certificates, applications and hardware.
The transition will take years because these systems need to work together. Some will be updated by suppliers. Others, especially custom applications and older infrastructure, may need direct planning and replacement.
The risk has already started: “harvest now, decrypt later”
Quantum computers capable of breaking current public-key encryption aren't available today. That doesn't mean the risk begins in the future.
An attacker can collect encrypted information now and store it. If the information is still valuable in ten or twenty years, it may be decrypted when quantum technology becomes powerful enough.
This is known as “harvest now, decrypt later.”

This matters most when data needs to remain private for a long time, such as:
- Intellectual property
- Product designs and research
- Financial information
- Personal and medical records
- Legal documents
- Long-term business agreements
- Customer and supplier data
- Sensitive communications
A business might complete its migration in 2035 but still face a problem if an attacker has already copied sensitive encrypted data.
That is why the NCSC's first milestone is discovery and planning, rather than waiting until new quantum-safe systems are widely available.
The NCSC timeline in practical terms
The NCSC's guidance on timelines for migration to post-quantum cryptography is mainly aimed at larger organisations, critical national infrastructure and businesses with bespoke IT.
However, the direction is relevant to organisations of every size.
By 2028: understand what we have
The first milestone is not to replace every firewall, laptop or application.
It is to:
- Define our migration goals.
- Identify where cryptography is used.
- Record which systems depend on it.
- Identify long-lived or sensitive data.
- Understand supplier dependencies.
- Create an initial migration plan.
For a smaller business, this may be a focused review rather than a large transformation programme. Many standard systems will eventually be updated by their suppliers.
Custom software, older servers, specialist equipment and privately managed networks may need more attention.
By 2031: protect the most important systems
The second milestone is to migrate the highest-priority services.
This means focusing first on systems that:
- Protect valuable or long-lived information
- Support essential business operations
- Connect directly to customers or suppliers
- Depend on older hardware or software
- Use custom encryption or certificates
- Would be difficult to replace quickly
By this point, businesses should also have a more detailed route to full migration by 2035.
By 2035: complete the migration
The final milestone is to complete migration across all in-scope systems, services and products.
There may be difficult exceptions, particularly for older equipment or specialist operational technology. Even so, the NCSC expects organisations to work towards the 2035 target.
This is a long-term technology change. It should be planned alongside normal hardware replacements, software upgrades, cloud projects and security improvements.
The simple first step: create a cryptographic inventory
Most businesses have an asset list. Fewer have a clear record of how those assets use encryption.
A cryptographic inventory is a practical map of the technology that protects business information.
It doesn't need to begin as a complex technical document. We can start with a spreadsheet that records:
- System or application name
- Supplier and product version
- Where it is hosted
- What data it protects
- Whether it connects to external services
- Certificates and renewal dates
- VPN and remote access dependencies
- Hardware or software replacement cycle
- Supplier plans for PQC support
- Business importance
- Recommended next action
We should look at more than laptops and servers. The NCSC recommends considering:
- Cloud services
- Firewalls and VPNs
- Routers and switches
- Websites and customer portals
- Mobile devices
- Backup platforms
- Virtual machines
- Custom applications
- Software libraries
- Digital certificates
- Hardware security devices
- Internet-connected equipment
- Remote access tools

The goal isn't to document every technical detail on day one. The goal is to understand where the important systems are and which ones need deeper investigation.
This inventory also supports better everyday security. It can reveal unsupported software, expired certificates, unknown suppliers and systems that no one is actively managing.
What UK SMEs should do now
A sensible starting plan can be straightforward.
1. Identify long-lived data
Ask which information would still be sensitive in ten or twenty years.
This data should receive early attention, even if it isn't the easiest system to change.
2. Ask suppliers about their plans
Cloud providers, software suppliers, firewall vendors and application developers should have a roadmap for quantum-safe updates.
We should ask:
- Will the product support PQC?
- When will updates be available?
- Will existing hardware support them?
- Will licences or configuration changes be needed?
- What happens to older versions?
- Will the change affect performance or compatibility?
3. Record custom and older systems
Standard cloud platforms may be updated by their suppliers. Custom applications and older systems are less predictable.
These should be marked clearly in the inventory, along with their replacement or upgrade options.
4. Build flexibility into new projects
New systems should avoid designs that make future encryption changes difficult.
Where possible, we should choose platforms that support cryptographic agility. In plain English, this means we can change the encryption method without rebuilding the entire system.
5. Align upgrades with normal business planning
We don't need to replace working systems unnecessarily. Instead, we can consider PQC readiness when:
- Renewing a firewall
- Replacing servers
- Selecting a new cloud application
- Developing custom software
- Refreshing network equipment
- Updating remote access
- Reviewing backup systems

Where IT support fits
Post-quantum preparation sits within wider security and IT planning. It shouldn't be treated as a separate product sale.
At Your IT Specialist, we can help businesses build a clearer view of their systems and risks through:
- IT infrastructure reviews
- Firewall and network support
- Patching and update management
- Vulnerability assessments
- Logs and security monitoring
- Hardware and software lifecycle planning
- Cloud application support
- Custom application advice
- Remote support for servers, desktops and networks
- Out-of-hours upgrades and emergency work
Our approach is provider-agnostic. We don't recommend a particular vendor simply because it is familiar or commercially convenient. We look at the current environment, business priorities, supplier support and long-term cost.
That matters with PQC because no single product will solve the whole problem. Different systems will move at different speeds. Some may be updated by suppliers. Others may need re-platforming, replacement or retirement.
Our provider-agnostic IT support guide explains how impartial advice can help businesses make technology decisions without unnecessary sales pressure.
The main takeaway
The NCSC's 2035 target may feel distant, but the planning deadline is much closer.
By 2028, UK businesses should understand where encryption is used, which systems matter most and what suppliers plan to do.
For many SMEs, the right first step isn't buying new quantum-safe technology. It is creating a useful inventory and identifying the information that must remain protected for the longest time.
From there, we can plan upgrades alongside normal IT maintenance and security work.
A clear inventory today gives us better choices tomorrow. It also reduces the risk of rushing into expensive changes when suppliers, customers or regulators start asking difficult questions.
For an impartial review of your IT environment, contact Your IT Specialist. We can help identify practical next steps without pushing unnecessary replacements.
