Jessica Entwistle
July 23 2026
The National Cyber Security Centre has published a detailed report following its first post-quantum cryptography migration workshop, which brought together UK organisations to discuss the practical challenges of preparing for quantum-resistant encryption. The NCSC reports that no organisation can navigate this transition alone, and the workshop identified common obstacles including asset discovery, cryptographic inventory management, dependency mapping, and the need for coordinated industry action. The findings emphasise that migration planning must begin now, even though large-scale quantum computing threats remain years away, because the complexity of replacing cryptographic systems across enterprise environments requires sustained effort and cross-sector collaboration.
Post-quantum cryptography represents a long-term infrastructure challenge that sits alongside immediate operational security priorities. It is not an urgent patch cycle, but it does require organisations to understand where cryptographic systems are deployed, how they are managed, and what dependencies exist across supply chains, cloud services, identity platforms and legacy systems. The NCSC's emphasis on collaboration reflects the reality that many organisations lack complete visibility of their cryptographic estate, and that vendors, standards bodies and industry groups will need to coordinate migration timelines to avoid creating gaps in interoperability or security. For UK businesses, this is a strategic planning issue that requires early engagement with vendors, clear ownership within IT and security teams, and a realistic understanding of the scale and complexity of the work involved. The organisations that begin this process now will have more time to test, validate and phase the transition, rather than being forced into reactive migration when quantum threats become more imminent.
Organisations should begin building an inventory of where cryptographic systems are deployed across infrastructure, applications, third-party services and supply chains, and identify which algorithms are in use. This includes reviewing encryption in transit and at rest, digital signatures, certificate authorities, VPNs, identity systems, cloud services and any custom or legacy applications that rely on cryptographic libraries. It is also worth engaging with key vendors and service providers to understand their post-quantum migration roadmaps and timelines. The NCSC workshop findings provide a useful reference for understanding the common challenges other UK organisations are facing, and the report includes practical guidance on how to approach discovery, planning and coordination. This is not a project that can be completed quickly, but starting the groundwork now will make the eventual transition more manageable and less disruptive.
Source: NCSC UK