UK Post-Quantum Cryptography Readiness: What the Evidence Actually Shows
- Brian Couzens
- Aug 12
- 5 min read

UK Post-Quantum Cryptography Readiness: What the Evidence Actually Shows
Every organisation holding data today with a shelf life beyond the next decade has a quantum problem, whether it has been named yet or not. Encrypted traffic intercepted now can be stored and decrypted later, once a cryptographically relevant quantum computer exists. That risk, harvest now, decrypt later, is why post-quantum cryptography readiness has moved from a research topic to a governance question for regulators, boards and national authorities alike.
SITG-Consulting has published an independent, evidence-based assessment of UK post-quantum cryptography readiness, classifying the United Kingdom at Tier 2, active national PQC development with structured government preparation, at high confidence. The assessment is a supplement to our earlier report, Europe's Post-Quantum Readiness 2026: An Empirical Assessment of the EU-27, which applied the same methodology across all 27 EU Member States.
Both reports are openly available. The UK assessment carries its own DOI, 10.5281/zenodo.21901778, permanently citable at https://doi.org/10.5281/zenodo.21901778.
What Post-Quantum Cryptography Readiness Actually Means
Post-quantum cryptography, or PQC, refers to cryptographic algorithms designed to resist attack from a sufficiently powerful quantum computer, replacing the RSA and elliptic-curve schemes that underpin most of today's digital security. Readiness is not a statement about whether an organisation, or a country, has adopted new algorithms yet. Almost none have, at scale. Readiness is a statement about whether the machinery exists to find out what needs to change, plan the change, and prove it has happened.
That machinery has a specific, checkable shape: a named accountable authority, a cryptographic inventory of where vulnerable algorithms are actually in use, dated migration milestones, procurement rules that require vendors to demonstrate crypto-agility, and public evidence that any of this is actually happening rather than merely planned. Declarations of intent are cheap. Execution evidence is not, which is exactly why it is the right basis for an assessment.
How the Assessment Was Built
The UK assessment applies the same five-tier framework used in the EU-27 report, running from Tier 1, denoting government-led national migration programmes with substantive implementation machinery, down to Tier 5, denoting no publicly verifiable PQC-specific activity. Classification rests entirely on publicly verifiable national evidence, not on stated intentions, vendor marketing, or general cybersecurity posture.
Every claim in the report was checked against the primary document or the issuing authority's own published page, not against secondary commentary or press summaries. That mattered more for the UK than it did for the EU-27 work. EU Member State evidence tends to sit in one or two national authority publications. UK evidence is scattered across the National Cyber Security Centre (NCSC), GCHQ, the Department for Science, Innovation and Technology, HM Treasury, the Bank of England and Parliament, several of which have themselves changed shape or reporting lines during the period the assessment covers. Bringing that evidence together, and testing every figure and date against its origin rather than a repeated citation of it, was the bulk of the work.
The UK Is Classified Tier 2: Here Is the Evidence
The classification rests on a substantial, well-documented body of national activity, led by NCSC, which operates as part of GCHQ:
A published national migration roadmap with dated milestones for post-quantum cryptography adoption.
A government-backed consultancy assurance pilot, run through NCSC's Assured Cyber Security Consultancy scheme, giving organisations a route to vetted PQC migration support.
Sector-specific financial services guidance from the Cross Market Operational Resilience Group (CMORG), whose membership spans the Bank of England, the FCA and the PRA alongside industry participants, setting out a four-phase migration approach: cryptographic inventory, risk assessment, prioritisation, and remediation.
A departmental study assessing migration readiness across five critical national infrastructure sectors.
Active UK contribution to international post-quantum cryptography standards work.
Taken together, the UK's guidance depth is at least equal to France and Germany, both classified Tier 2 in the EU-27 assessment, and in some operational respects exceeds them. The NCSC-backed consultancy pilot in particular has no direct equivalent among the EU Member States assessed.
Why the UK Falls Short of Tier 1
One distinction determines the tier, and it is worth being precise about it rather than rounding it away. The UK's guidance is comprehensive and technically well-articulated. It is advisory rather than mandatory for the general economy.
Concretely: NCSC advises organisations to complete cryptographic discovery exercises by 2028. That is a target set out in guidance, not a legal deadline, and no equivalent of a mandatory, recurring cryptographic inventory obligation currently exists at UK national level. Compare that with Lithuania, the single EU Member State that reached Tier 1 in the parent assessment, which has a government-approved national transition plan carrying a mandatory cryptographic inventory obligation on a recurring three-year cycle, with a published methodology and a downloadable return form. Guidance tells organisations what good looks like. Obligation tells a national authority whether anyone has actually done it. The UK currently has the former and not the latter, and that is the entire distance between Tier 2 and Tier 1.
What This Means for UK Organisations Now
The practical implication is not that UK organisations can wait for a mandate before acting. It is closer to the opposite. Every national authority examined across both assessments that addresses the timing question reaches the same conclusion: harvest-now-decrypt-later collection means the migration clock is already running against the confidentiality lifetime of data being encrypted today, regardless of when any given country's guidance becomes binding.
The organisations best placed when obligation does arrive, in the UK or in any jurisdiction, will be the ones that have already completed a cryptographic inventory rather than waiting to be told to. CMORG's own four-phase sequencing for financial services, inventory first, then risk assessment, prioritisation and remediation, is a reasonable model for any sector to follow now, voluntarily, ahead of any UK mandate that may follow the pattern already set in Lithuania and increasingly discussed elsewhere in Europe.
Read the Full Assessment
The complete UK Post-Quantum Readiness Assessment, including full source citations, tier definitions and the evidence standard applied, is openly available under a Creative Commons Attribution 4.0 licence.
DOI: 10.5281/zenodo.21901778 Full report: https://doi.org/10.5281/zenodo.21901778
It should be read alongside the parent report, Europe's Post-Quantum Readiness 2026: An Empirical Assessment of the EU-27 (DOI: 10.5281/zenodo.21782641), which applies the same framework across all 27 EU Member States and provides the comparative context for the UK's position.
Where authoritative evidence would materially change a finding in either report, SITG-Consulting welcomes it. Get in touch if your organisation needs an independent assessment of its own post-quantum migration position, or advisory support building the cryptographic inventory this report identifies as the critical next step.




Comments