The UK National Cyber Security Centre’s post-quantum roadmap sets three milestones: discovery and an initial migration plan by 2028, completion of the highest-priority changes by 2031 and migration across systems, services and products by 2035.
For a technology supplier, the nearest commercial question is what its customer needs to know about the products already in use. Which can be upgraded? Which depend on an upstream supplier? Which will require replacement? Those answers affect investment decisions well before the final migration date.
Later NCSC activity makes the market more concrete. A consultancy pilot covers discovery and migration planning, while a workshop report published in July 2026 identifies supplier readiness as a central concern. The opportunity includes preparing an organisation for change, rather than only selling a new cryptographic component.
The roadmap starts with the existing estate
The NCSC’s 20 March 2025 guidance is aimed especially at large organisations, critical infrastructure and businesses using bespoke technology. It places assessment before migration and recognises that the work can span several leadership and investment cycles.
The guidance distinguishes organisations relying mainly on commodity IT from those using specialised or custom systems. Routine vendor updates may handle much of the transition for the former. Bespoke products can require a more deliberate assessment of dependencies and upgrade options.
This distinction is commercially important for defense-facing companies. A startup buying standard office software has a different migration problem from a company supplying a long-lived communications product to a government customer. It can face both roles at once: purchaser of its own IT and supplier responsible for another organisation’s product lifecycle.
The roadmap’s dates are planning targets. They do not identify one new procurement programme, reserve a budget for a particular supplier or certify a product already on sale.
The customer needs an answer about each product generation
A credible supplier statement should identify which supported versions are expected to receive an upgrade and which depend on a future replacement. Where the plan relies on another company’s software or hardware, that dependency should be visible.
This is more useful than a general claim that the organisation is preparing for a quantum future. Customers plan around products, support periods and investment cycles. They need to know whether a planned refresh can accommodate the change or whether an additional migration project may be required.
Consider a hypothetical customer with two generations of the same specialist device. The newer version may have an identified upgrade path, while the older one may need replacement. A single statement about the product family would hide the budget and scheduling difference.
The supplier does not need to invent certainty where its upstream dependencies remain unresolved. It can describe the present plan, the decisions still outstanding and when the customer should expect a further update. That gives the buyer usable lifecycle information.
July 2026 reporting puts the supply chain at the centre
The NCSC’s 22 July workshop report covers a meeting held with Vodafone and the National Cyber Advisory Board in December 2025. It identifies executive sponsorship, supply-chain readiness and transparency as recurring themes.
The report encourages early discussion with suppliers and alignment with natural technology refresh cycles. It also describes the value of publishing plans and lessons so that customers can make their own migration decisions.
For a commercial team, that creates a practical reason to maintain a public migration statement and a more detailed customer briefing. The public account can explain the product direction; the customer discussion can address the installed versions and dependencies relevant to that organisation.
The workshop is evidence of issues raised by participants and the NCSC’s subsequent guidance. It is not a survey that quantifies how many government systems have migrated, nor does it establish a market size for consultancy or replacement products.
A consultancy pilot gives planning work a defined scope
The NCSC’s post-quantum consultancy pilot identifies two offerings. All participating companies are assessed for discovery and migration planning. Some are also assessed to provide more direct advice on the use of post-quantum cryptography.
The distinction is useful to buyers choosing external help. A firm can support the identification and prioritisation of affected services without claiming the same depth of specialist cryptographic advice as another provider.
As checked on 6 September 2026, the pilot page says expressions of interest are closed and gives 31 March 2027 as the expected end of the pilot. It also says participation does not guarantee membership of the later full scheme. This is an existing assurance route with a defined review point, rather than an open invitation for every consultancy to join immediately.
For suppliers, the pilot makes a specific commercial service visible: helping customers understand the migration work before they buy or replace systems. It does not establish product certification or guarantee a government contract for an assessed consultancy.
Planning, implementation and assurance are different products
A discovery engagement produces an understanding of affected services and dependencies. A migration plan organises priorities, resources and sequencing. Implementation changes the systems. Assurance concerns whether a provider or offering meets the relevant criteria.
These activities can be related without being purchased from the same organisation. A customer might use an independent specialist to assess its estate, then ask existing vendors to supply upgrades and a separate integrator to coordinate the work.
A smaller cyber company should be clear about which responsibility it accepts. A tool that helps discover dependencies can be valuable without becoming the authority for every cryptographic decision. A specialist consultancy can advise on a difficult system without owning the customer’s entire migration programme.
That clarity also helps avoid an unmanageable service promise. The customer needs an accountable scope and a useful output, not a supplier claiming control over products and infrastructure maintained by others.
Quantum networking is a separate proposition
The NCSC’s paper on quantum networking technologies recommends post-quantum cryptography as the primary response to the cryptographic threat from quantum computing. It states that the agency will not support quantum key distribution for government or military applications.
The paper distinguishes that position from continued research into other quantum technologies. A quantum-networking demonstration or investment is therefore not interchangeable with the migration path the NCSC recommends to these customers.
For product positioning, the relevant distinction is the function supplied. A migration service, a cryptographic implementation and an experimental networking capability answer different needs. They should not be grouped under an unexplained claim of quantum security.
The customer also needs to understand the assurance basis. A technology category or a provider’s participation in a consultancy scheme does not by itself establish that a particular deployed product meets every requirement of the customer’s system.
The buying decision is about continuity as well as cryptography
Migration planning has to account for the customer’s ability to keep operating while changes occur. A product upgrade can affect interfaces, support arrangements and the timing of other replacements.
That makes product and account teams part of the discussion alongside security specialists. A supplier needs to explain its release and support plans in terms that the customer can use in an investment programme.
Our MOD cyber improvement analysis covers a separate set of supplier and delivery considerations. NATO’s data strategy shows how security also interacts with controlled sharing and the wider information architecture.
The immediate commercial task is to make dependencies legible. The NCSC roadmap establishes the direction and dates; the consultancy pilot gives early planning work a defined service category; and the July workshop report reinforces the importance of supplier coordination. A useful offering helps the customer turn those signals into decisions about the products it actually owns and the services it must continue to run.