Migration roadmap

Post-Quantum Cryptography Migration Roadmap: 2026 to 2035

A practical roadmap for organisations that need to move from awareness to implementation: cryptographic inventory, risk ranking, pilot deployments, standards alignment and long-term crypto-agility.

Updated: 2 September 2026|14 min read
Now to 2028

Define and Discover

  • -Build a cryptographic inventory across public endpoints, internal systems, signing workflows and suppliers.
  • -Identify long-lived sensitive data exposed to harvest-now-decrypt-later risk.
  • -Choose pilot systems for TLS, VPN, API and signature testing.
2028 to 2031

Prioritise and Pilot

  • -Deploy early hybrid ML-KEM pilots where provider support is mature.
  • -Test ML-DSA and SLH-DSA around code signing, document workflows and identity systems.
  • -Refine the migration roadmap based on compatibility, performance and vendor readiness.
2031 to 2035

Scale and Complete

  • -Migrate high-priority services and products to approved post-quantum controls.
  • -Remove legacy downgrade paths when client and supplier compatibility permits.
  • -Embed crypto-agility into procurement, architecture review and incident response.

NCSC PQC Migration Milestones and Evidence

A useful roadmap pairs each NCSC deadline with an accountable outcome and evidence that risk owners can review. Use this checklist to turn the national timeline into an implementation programme rather than a list of intentions.

DeadlineRequired outcomeEvidence to retain
By 2028Complete discovery and assessment, then approve an initial migration plan.Cryptographic inventory, risk-ranked systems, supplier dependencies, budget needs and named owners.
By 2031Complete the highest-priority migrations and ready infrastructure for wider PQC adoption.Pilot results, production change records, compatibility findings and an approved route to 2035.
By 2035Complete PQC migration across systems, services and products.Updated architecture records, retired quantum-vulnerable dependencies and governed exception records.

Use the detailed post-quantum cryptography implementation guide to organise the work, then record affected systems with the cryptographic inventory method.

1. Start With a Cryptographic Inventory

A PQC migration plan fails if it only looks at web certificates. The real inventory should include TLS endpoints, API gateways, VPNs, SSH, database encryption, object storage, code signing, document signatures, identity tokens, embedded devices and third-party cryptographic dependencies.

The output should be structured enough to answer three questions: what cryptography is used, what data it protects, and how long that data or signature must remain secure.

2. Rank by Data Lifetime and Exposure

Harvest-now-decrypt-later risk is highest where encrypted traffic can be captured today and remains valuable for many years. Healthcare data, legal records, government communications, financial data and trade secrets should move up the priority list.

Public endpoints are easy to scan, but internal systems may carry the highest business risk. A good roadmap distinguishes visible readiness from actual organisational risk.

3. Pilot Hybrid Transport Security

Transport security is usually the best first pilot because vendors, browsers and CDNs are actively adding support for hybrid post-quantum key exchange. The goal is not to replace every system immediately; it is to prove compatibility, performance and operational ownership.

For public web services, this means confirming TLS 1.3, testing hybrid ML-KEM support, reviewing legacy protocol fallbacks and documenting what each provider can and cannot support today.

4. Treat Signatures as a Separate Workstream

Digital signatures need separate planning because they affect trust chains, archives, software releases, audit evidence and legal records. The migration path for a TLS key exchange is not the same as the migration path for document or firmware signing.

Teams should test ML-DSA and SLH-DSA around key sizes, signature sizes, verifier support, certificate workflows and long-term validation requirements before committing to production deployment.

5. Build Crypto-Agility Into Governance

PQC migration is not a one-time algorithm replacement. Future standards, parameter updates and implementation findings will require change. Crypto-agility means systems can rotate algorithms, keys and providers without a full application redesign.

Procurement should ask vendors for PQC roadmaps, algorithm support, certificate lifecycle handling, fallback behaviour and documented upgrade paths.

Primary Reference

NCSC timelines for migration to post-quantum cryptography

Post-Quantum Migration Roadmap Questions

What is a post-quantum cryptography migration roadmap?

It is a phased plan for finding quantum-vulnerable cryptography, prioritising systems by risk, testing post-quantum controls, coordinating suppliers and completing migration with accountable owners and retained evidence.

What should organisations complete by 2028?

The NCSC milestone is to complete discovery and assessment, define migration goals and create an initial plan covering priorities, supplier dependencies, investment needs and long-lived hardware roots of trust.

When should post-quantum cryptography migration be complete?

The NCSC sets 2035 as the target for completing migration across systems, services and products, with the highest-priority migration activities completed by 2031.

Get a Baseline Before the Roadmap

Run the free public scan first. If the website is already weak on TLS or security headers, fix those before deeper PQC work.

Free readiness account

Keep This Guide Connected to a Real Website Scan

A PQC guide is more useful when it is attached to current evidence. Create a free account, add a public domain now or later, and keep a repeatable baseline for TLS, security headers and visible post-quantum readiness.

No cardStart the free evidence path without a paid plan.
Saved scanKeep the public endpoint result after the browser session.
Rescan laterRerun after TLS, header or provider changes.

Prefer to scan first? Open the free quantum security scanner.

Create Your Free Account

Start with Google, Microsoft or a one-time email code. You can add a domain now if you want the scanner to run after signup, but it is not required.

No cardNo passwordFree saved scan
Add a domain to scan after signup (optional)

Leave this blank to create the account first and scan later.

or use email code

No card or password is needed. The free account can keep scan evidence for rescans and badge qualification when you add a public domain.