← All countries

United Kingdom

NIST bloc Standard-taker

The National Cyber Security Centre (NCSC) leads the United Kingdom's post-quantum cryptography posture and has set a phased national timeline to migrate to post-quantum cryptography by 2035, with discovery by 2028 and highest-priority migration by 2031, aligned with the NIST FIPS 203, 204 and 205 standards. The NCSC presents post-quantum cryptography as the primary mitigation against the quantum threat and, in its work on quantum key distribution, treats post-quantum cryptography as the preferred approach with quantum key distribution only as an additional layer. The transition is increasingly visible across government and the financial sector: the Bank of England now urges firms to prepare and plan their migration now, and Parliament has examined the issue through written questions, committee evidence and a Commons debate. None of this rests on a binding post-quantum statute; the position is carried through guidance rather than law.

Governance credibility

Governance credibility for United KingdomA six-axis reading out of two: Relevance 1.5 / 2, Coherence 1.5 / 2, Effectiveness 1.0 / 2, Efficiency 1.0 / 2, Governance 2.0 / 2, Impact 2.0 / 2.RelCohEffEff.GovImp
Governance credibility scores for United Kingdom, each out of two. Hover or focus a row to highlight its axis.
CriterionScoreConfidence
Relevance1.5 / 2High
Coherence1.5 / 2High
Effectiveness1.0 / 2High
Efficiency1.0 / 2High
Governance2.0 / 2High
Impact2.0 / 2High

Regulatory basis

  • NCSC post-quantum cryptography migration timelines and guidance (to 2035) national Guidance

There is no economy-wide post-quantum statute and no binding PQC mandate. The NIS Regulations 2018 place binding cyber security and resilience duties on designated operators of essential services and relevant digital service providers, assessed by sector regulators against the NCSC Cyber Assessment Framework, but these are technology-neutral and do not require post-quantum migration. PQC itself is addressed only through NCSC guidance, which directs migration to the NIST FIPS 203/204/205 algorithms on a phased national timeline to 2035 and carries no legal obligation.

Standards and algorithms

Standard families
NIST FIPS 203, FIPS 204, FIPS 205
Algorithms
ML-KEM, ML-DSA, SLH-DSA

Hybrid stance

None stated

Migration timeline

today
2028
2031
2035
20252036
  1. 2028Complete discovery of systems and services using cryptography
  2. 2031Complete migration of highest-priority systems and services
  3. 2035Complete migration of all systems, services and products

Target completion: 2035

International standards processes

  • RFC 9794 (IETF post-quantum terminology) NCSC contributes to and promotes the terminology standard

Governmental and standards bodies

  • NCSC UK national technical authority for cyber security; sets the PQC migration timeline and guidance
  • Bank of England Financial-sector authority; urges firms to plan and prepare PQC migration and assesses quantum risk to financial stability
  • DSIT Department for Science, Innovation and Technology; commissions research on quantum key distribution and the PQC transition
  • POST (UK Parliament) Parliamentary Office of Science and Technology; briefs Parliament on quantum and PQC
  • UK Parliament Scrutinises the PQC transition through written questions, committee evidence and debate
  • UK Government Publishes research on the plan for the PQC transition

Key institutional documents

Advising on this transition, or your own sector's? Request a briefing →