The post-quantum deadline that applies to you is 2028, and it only asks you to make a list

· Carl Heaton · Security

If your business holds data that still matters in 2035, the encryption protecting it today is a live question, not a future one. Customer records, financial files, contracts, medical or legal material: anything with a long confidentiality tail. We covered why in an earlier filing on harvest-now-decrypt-later, where an attacker records encrypted data now and waits for the technology to read it.

What has changed since is a useful piece of evidence about where everyone actually is. A DigiCert survey reported by ITPro found that 85% of IT and security leaders expect quantum computing to break current encryption standards within a decade, while only 7% have deployed quantum-safe certificates. That gap has been widely read as an awareness problem. Look at the rest of the numbers and it plainly is not.

The awareness gap is not the problem

The same survey found nearly nine in 10 organisations are planning, testing, or implementing post-quantum work. Half have done a quantum risk assessment. 45% have a transition plan. 44% have built a cryptographic inventory. UK organisations reported the highest share describing themselves as leading edge, at 18%, ahead of the US at 17% and Australia at 10%.

So people know. They are working on it. They are simply not finishing, and the reason is not motivation. Simon Pamplin, CTO of Certes, put the blocker at the "absolute complexity" of making cryptographic changes across legacy applications, hybrid environments, and edge infrastructure, systems he says were "never designed with crypto agility in mind".

That is a much more useful diagnosis than "not moving fast enough". It means the work is not blocked on a decision or a budget line. It is blocked on the fact that most organisations cannot see where their encryption lives, and you cannot replace what you cannot find.

The UK date is 2028, not 2035

Most coverage quotes 2035 as the deadline, which makes this sound like someone else's decade. The NCSC's migration timeline sets three UK milestones, and the first one is much closer:

  • By 2028: define your migration goals, carry out a full discovery exercise to understand which services and infrastructure depend on cryptography, and build an initial migration plan.
  • By 2031: complete your highest-priority migration work and turn the initial plan into a thorough roadmap.
  • By 2035: complete migration across all systems, services, and products.

Read the 2028 milestone again, because it is the whole point of this filing. It does not ask you to replace a single algorithm. It asks you to know what you have and to have a plan. That is roughly 18 months away, and it is the milestone the survey data says organisations are stuck on.

The NCSC's dates are guidance rather than law for most businesses. But they set the expectation that regulators, insurers, and large customers will work from, and they are the closest thing to a UK schedule you will get.

Why the discovery is the hard bit

Cryptography accumulates quietly. It is in applications, in the libraries those applications depend on, in hardware, in protocols, in certificates, and in systems bought a decade ago that nobody has opened since. Nothing announces itself. There is rarely a person whose job it is to track it.

That is why 44% have an inventory while only 7% have deployed anything. The inventory is the expensive part. The swap, once you know where to swap, is comparatively mechanical.

For a smaller business this is less daunting than it sounds, because your estate is smaller. You are not mapping a bank. You are answering a narrow question: where does this business rely on encryption to protect data that will still be sensitive in 2035, and what protects it.

What to do before 2028

Scope it to long-lived data first. Do not try to inventory everything. Start with the data that is still sensitive in 10 years, then list the systems that hold it and how it is protected in transit and at rest. A spreadsheet is a perfectly good first version.

Write down what you find, including the gaps. "We do not know what this system uses" is a legitimate inventory entry and often the most valuable one. It is the thing you take to your supplier.

Treat it as a legacy audit, because it is one. The systems that will be hardest to migrate are the ones that are already hardest to patch, hardest to support, and most likely to be the source of your next incident. Post-quantum is the reason you finally look. Most of what you find is ordinary technical debt worth clearing anyway.

If you have an IT provider, make the inventory their deliverable. This is a reasonable thing to ask for, and their answer tells you a lot. A provider who can produce a rough map of where your cryptography lives is doing their job. One who cannot has just shown you a gap that is not really about quantum computing at all.

The temptation with anything labelled quantum is to file it under "not yet". The honest reading of the survey is that most organisations already resisted that temptation and started, then hit the part nobody budgets for. The 2028 milestone exists precisely because that part takes years, and it is the only one of the three dates that asks nothing more of you than knowing what you own.

How Steelwise can help

Working out where your business relies on encryption, and which of it protects data with a long enough shelf life to matter, is a scoping exercise rather than a quantum project. It is the kind of review we do. Get in touch.

Further reading

← All filings