The National Cyber Security Centre (NCSC), a part of GCHQ, and Vodafone have shared key recommendations emerging from the UK’s first government and industry workshop on post-quantum cryptography (PQC) migration, designed to help organisations prepare for the transition to a quantum-safe future.
While quantum computing has the potential to benefit society, for example by modelling new medicines, it could also inherently undermine the cryptographic principles digital communications rely on today.
Together with the National Cyber Advisory Board, NCSC and Vodafone hosted the first UK government and industry workshop focused on PQC migration. It brought together security leaders and those responsible for PQC in their organisations from across industry, academia and government.
Why PQC migration matters
As the NCSC has explained, in the future, a sufficiently powerful quantum computer will be able to break the public key cryptography that protects today’s networks and systems. It is vital that these systems migrate to PQC algorithms, which rely on mathematical problems resistant to both quantum and classical computer attacks.
Last year, the NCSC published key PQC migration milestones, urging organisations to act now. As the NCSC stresses, PQC migration is not only a technical challenge but a global strategic priority for resilience across industry and government.
Why bring organisations together?
Lizzie Moseley, Vodafone Cyber Strategy & Content Manager, explained that the workshop brought together industry, government and academia to share experiences, discuss common challenges and explore how organisations can plan for the transition to PQC.
She said: “No organisation can make the transition alone, and by sharing experiences, engaging suppliers and working together across industry and government, we can help build a more quantum-safe future for the UK.”
Engaging the board and building the business case
The workshop identified ways to engage the board of an organisation, including:
- Emphasising the cost of delay: Starting sooner can reduce future cost and complexity by spreading effort over time.
- Connecting to broader benefits: Link PQC migration to wider goals, such as addressing legacy systems and improving cyber resilience.
- Making it organisation-specific: Show how PQC migration supports priorities such as system availability, legal compliance or the bottom line.
- Identifying a senior sponsor: Find a CTO, CIO, CISO or other leader who understands the need and can represent it at board level.
- Using peer and industry benchmarks: Board members often respond to evidence of what peers are doing.
- Doing the pre-work: Strengthen the case by engaging suppliers, identifying critical assets before, or alongside, board engagement.
- Prioritising: Focus first on systems where a breach would have the greatest impact, or where migration will take longest.
- Laying out a phased roadmap: Set clear phases, timelines, targets, investments and skills needed to show how migration will progress and build confidence in the plan.
Supply-chain readiness is critical
An organisation’s quantum readiness depends on its suppliers. A key workshop theme was the need to build PQC into supplier security assessments and sourcing. Participants emphasised:
- Early supplier engagement: Discuss PQC migration with suppliers as soon as possible. Understanding and influencing their roadmaps, while making your requirements clear, is essential to a realistic migration plan.
- Making your requirements clear: Efficient PQC migration should align with technology refresh cycles, ensuring products are PQC-ready or upgradeable when updates are planned.
Transparency and collaboration
PQC migration is complex and requires expertise across many areas. Collective progress will determine national resilience; no single organisation will have all the answers, making collaboration essential. Participants highlighted:
- Industry transparency: Organisations migrating to PQC could share plans, progress, challenges and lessons learned. This would help others, especially smaller security teams, and guide future NCSC support.
- Cross-sector collaboration: Many PQC migration lessons apply across sectors, creating opportunities to share best practice and reuse proven approaches.
- A united voice from industry and government: Organisations are more likely to invest in PQC if competitors and partners do the same. A consistent message will support UK-wide resilience.
- Workshops, events and conferences: Events like this help PQC practitioners share expertise and learn from one another.
What’s next?
The NCSC is working with the National Cyber Advisory Board to shape continued conversations on PQC across industry and government. Interested parties can get in touch using the PQC workshop feedback form.
Lizzie continued: “Meeting the threat from quantum computing may sound like a far-off challenge, but post-quantum cryptography is a long-term business resilience priority that requires organisations to start planning today. The workshop highlighted the importance of building momentum now, supported by clear leadership and long-term planning.”
Vodafone is identifying where cryptography is potentially vulnerable to attack from quantum computers, defining supplier requirements and developing the ability to update cryptography when new threats emerge. It has set up a long-term Quantum Safe programme and has planned migration activities in collaboration with suppliers.
Want to know more?
Read more about our work in Quantum Computing.
Watch our Quantum Computing explainer.
Find out more about what a quantum-safe future looks like.