EXPERT INSIGHT
Crypto-Agility explained; why you need it before 2028
The NCSC’s Post-Quantum Cryptography (PQC) timeline sets a 2028 milestone for completing cryptographic inventories and preparing migration paths. But crypto-agility can’t be achieved overnight.
Three reasons it matters now:
- Quantum isn’t the only risk. Attackers are already stockpiling encrypted data, ready to decrypt it later (“harvest now, decrypt later”).
- Migration takes time. Updating every certificate, application and endpoint requires years of planning and testing.
- Compliance is coming. Regulators are expected to mandate PQC preparedness — lack of agility could mean penalties.











