UK compliance guide

Cyber Essentials and Post-Quantum Cryptography

Cyber Essentials is not a post-quantum cryptography certification. It is a practical baseline for UK organisations that need to fix visible security weaknesses, define scope and prepare credible evidence before a broader PQC migration.

Updated: 19 June 2026|11 min read

Boundary and asset scope

Use the Cyber Essentials scoping exercise as the starting list for public websites, cloud services, remote access and supplier-hosted systems that may later need PQC review.

Secure configuration

Weak TLS versions, exposed services and unsafe defaults should be fixed before deeper post-quantum migration work.

Security update management

Post-quantum readiness depends on keeping browsers, servers, TLS libraries, CDNs and network appliances current enough to support new algorithms.

Access and supplier control

PQC migration requires supplier evidence. Track who operates certificates, gateways, VPNs, signing systems and cryptographic key stores.

How Cyber Essentials Fits With PQC

Cyber Essentials focuses on common cyber security controls. Post-quantum cryptography focuses on the future risk to public-key cryptography. They are different problems, but they meet in the same operational places: public endpoints, cloud platforms, managed suppliers, certificates, updates and documented scope.

A site with weak TLS, unmanaged assets or unclear suppliers is not ready for serious PQC work. Fixing those basics first creates a cleaner path for cryptographic inventory and migration planning.

For UK teams, the sensible order is baseline hygiene, public endpoint scanning, cryptographic inventory, supplier questions and then risk-based post-quantum pilots.

What the Free Scan Can Check

TLS posture

TLS 1.3 support, protocol downgrade exposure and certificate basics.

Security headers

HSTS, CSP, X-Frame-Options and X-Content-Type-Options signals.

PQC readiness signals

Whether the public endpoint shows observable hybrid post-quantum key exchange indicators.

Evidence starting point

A saved baseline that can be rerun after fixes and used in planning discussions.

Cyber Essentials to PQC Checklist

  1. 1. Confirm the website and API hostname are in scope for Cyber Essentials evidence.
  2. 2. Run an external scan for TLS 1.3, downgrade paths and observable hybrid key exchange signals.
  3. 3. Record which provider controls the TLS stack: hosting platform, CDN, WAF, load balancer or internal team.
  4. 4. Add cryptographic dependencies to the asset register, including certificates, key stores and signing workflows.
  5. 5. Ask suppliers for NIST FIPS 203, 204 and 205 roadmap evidence where they manage encryption or signatures.
  6. 6. Use the NCSC PQC timeline to turn the inventory into a migration plan.

Primary References

Cyber Essentials and PQC FAQ

Does Cyber Essentials require post-quantum cryptography?

Cyber Essentials is a baseline cyber security scheme. It does not by itself certify that an organisation has migrated to post-quantum cryptography, but the scoping, secure configuration and update-management work creates useful evidence for PQC planning.

Can a Cyber Essentials scan prove a website is quantum-safe?

No. A public scan can show TLS posture, downgrade risk and some post-quantum readiness signals, but a full PQC assessment also needs internal systems, signing workflows, suppliers and data-lifetime analysis.

Where should a UK SME start?

Start with Cyber Essentials basics, then run a public website readiness scan and build a small cryptographic inventory for the systems that protect long-lived sensitive data.

Get a Public Readiness Baseline

Start with a free external scan, save the result, then use it as a practical input to Cyber Essentials remediation and PQC migration planning.

Free readiness account

Keep This Guide Connected to a Real Website Scan

A PQC guide is more useful when it is attached to current evidence. Create a free account, add a public domain now or later, and keep a repeatable baseline for TLS, security headers and visible post-quantum readiness.

No cardStart the free evidence path without a paid plan.
Saved scanKeep the public endpoint result after the browser session.
Rescan laterRerun after TLS, header or provider changes.

Prefer to scan first? Open the free quantum security scanner.

Create Your Free Account

Start with Google, Microsoft or a one-time email code. You can add a domain now if you want the scanner to run after signup, but it is not required.

No cardNo passwordFree saved scan
Add a domain to scan after signup (optional)

Leave this blank to create the account first and scan later.

or use email code

No card or password is needed. The free account can keep scan evidence for rescans and badge qualification when you add a public domain.