How to Prepare for the NCSC’s Post-Quantum Cryptography Migration Timelines

The arrival of post-quantum cryptography (PQC) is no longer a theoretical concern, it’s a strategic imperative for businesses across the globe.

Post-quantum timeline

The UK’s National Cyber Security Centre (NCSC) recently issued updated guidance that underscores the urgency for all organisations, particularly those operating critical infrastructure or bespoke IT systems, to begin their migration to PQC today.

The timelines are clear:

  • 2028: You should have completed a full discovery of your cryptographic estate and defined your migration goals
  • 2035: The journey to post-quantum readiness should be complete.

At FullProxy, we believe this isn’t just about cryptography. It’s a catalyst to rethink and uplift your entire cyber security posture and certificate lifecycle management is a key component of this.

Quantum computers will eventually break many of the public key cryptographic algorithms we rely on today. That puts every encrypted connection (past, present, and future) at risk.

Post-Quantum Cryptography Migration: A Complex Challenge but a Strategic Opportunity

Quantum computers will eventually break many of the public key cryptographic algorithms we rely on today. That puts every encrypted connection (past, present, and future) at risk. However, while the technology to break encryption isn’t here yet, data theft is already happening. Bad actors are stealing encrypted data now to decrypt it later, once quantum capabilities emerge.

That’s why the NCSC’s phased approach to PQC migration is both welcome and pragmatic. It encourages early discovery and most importantly, incremental, manageable action. This mirrors what we see on the ground at FullProxy: the best security strategies are those that evolve with your infrastructure, not those that try to reinvent it overnight.

 

The Role of Certificate Lifecycle Management

A frequently overlooked but foundational component of PQC readiness is your approach to digital certificates. Most enterprises already rely on Public Key Infrastructure (PKI) to issue and manage certificates for users, devices, and applications. But PQC migration will require a new root of trust and the issuance of quantum-resistant certificates – potentially to every machine in your environment.

This shift demands automation.

Manual certificate management is already a source of risk – expired certificates cause outages, while weak or misconfigured certs can open doors to attackers. Now layer in the need to track which certificates are quantum-safe, and you have a situation that’s not just unsustainable, it’s dangerous.

That’s why FullProxy strongly advocates for automated certificate lifecycle management. Automation enables faster rotation, broader visibility, and more agile response to emerging threats. And in a post-quantum world, where certificate agility could determine whether a business stays secure or becomes vulnerable, shorter lifecycles and automated renewal processes won’t just be nice to have, they’ll be essential.

Read more about our Certificate Management Services

Automation enables faster rotation, broader visibility, and more agile response to emerging threats. And in a post-quantum world, where certificate agility could determine whether a business stays secure or becomes vulnerable, shorter lifecycles and automated renewal processes won’t just be nice to have, they’ll be essential.

Act Now, Not Later

The NCSC is clear; most of the work required to prepare for PQC overlaps with best practices in cyber resilience. That includes asset discovery, cryptographic analysis, and yes, certificate lifecycle management. These aren’t abstract compliance tasks, they’re proactive steps that reduce risk today, and future-proof your organisation for tomorrow’s challenges.

If you haven’t started planning your PQC migration yet, the time is now. And if you’re unsure where to begin, focus on certificates. They’re one of the most direct, actionable areas where you can begin strengthening your security posture while laying the groundwork for quantum resistance.

At FullProxy, we’re here to help organisations make that leap safely, efficiently, and strategically. Because in a world where quantum threats are on the horizon, the best defence starts with readiness today.

About the Author

Chris Templeton
Chief Technology Officer
Chris drives FullProxy’s technical strategy, applying vast infrastructure expertise to engineer secure, resilient systems with clarity, precision, and energy.
Lightbulbs with green keyline

Quantum Innovation: Balancing Opportunity, Risk and Cyber Security Readiness

Quantum innovation is moving from theory to strategic reality, with the NCSC now strongly promoting its timeline for crypto readiness. Seen until comparatively recently as a dystopian, futuristic breakthrough, quantum computing and related quantum technologies are now becoming serious boardroom topics. Governments, technology companies and research institutions are investing heavily – in the hope that quantum systems could help solve problems that are too complex for classical computers.
Man on laptop ChatGPT

AI Agent Security: Why Guardrails and Red Teaming Matter

AI agents are quickly moving from experimentation to real business use. They are being explored for service desk automation, CRM updates, security investigations, workflow orchestration, knowledge retrieval and operational support.
F5 Unity Gold green line

Why work with an F5 Gold Partner?

When your infrastructure depends on secure, high-performing applications, choosing the right partner to deploy, optimise and support an F5 environment can make a world of difference. But with a wide spectrum of F5 partners in the UK market, it’s not always obvious why the level of accreditation matters, or what you gain by choosing an F5 Gold Partner like FullProxy.

From our experts to your inbox

Sign up to our monthly newsletter for trends, technology updates and exclusive content from our senior consultants.