United Kingdom

Executing
National Cyber Security Centre (GCHQ)

NCSC's 'Timelines for migration to post-quantum cryptography' guidance sets three dated phases: by 2028 complete discovery and assessment and build an initial migration plan; by 2031 complete migration of the highest-priority systems and refine the plan; by 2035 complete migration across all systems and services.

Guidance, not statute — but it is the reference schedule UK regulators and CNI operators are being measured against, and NCSC's 2025 Annual Review tracks it as a live national programme.

Scope

UK organisations generally, with government, critical national infrastructure, telecoms and finance treated as priority sectors

Band rationale

Final published guidance with the clearest whole-economy phasing, but no statutory instrument behind it.

Readiness dimensions
Policy
Deadline maturity
Technical standards
Execution evidence
Supply-chain enablement
Evidence confidence
Milestones
  1. 2028

    Discovery and initial plan

    Cryptographic discovery and assessment complete; migration objectives and a costed initial plan in place.

    Bindingness · guidance
  2. 2031

    Highest-priority migration complete

    Highest-priority, highest-risk systems migrated; plan refined for the remainder.

    Bindingness · guidance
  3. 2035

    Migration complete

    Migration completed across all systems, services and products.

    Bindingness · guidance
Why it matters

The UK model makes discovery a dated deliverable in its own right, which is the step most organisations actually fail first.

Migration implications
  • ·Build the cryptographic inventory before choosing algorithms — 2028 is a discovery deadline, not a deployment one
  • ·Tie priority tiers to data lifetime, not system age
  • ·Bespoke and legacy estates need their own programme and budget line
Evidence
Compare with United StatesCompare with European UnionCompare with FranceCompare with NetherlandsCompare with Canada