Post-quantum cryptography: what organisations should know

A concise look at post-quantum cryptography, why it matters for data security, and practical steps organisations can take to prepare.

24 July 2026

Publication

Loading...

Listen to our publication

0:00 / 0:00

Fail to Prepare, prepare to fail? Understanding data security and cryptography challenges in the quantum era

Webinar: 16 July 2026

Speakers

  • Andrew Joint – Partner and Head of the Quantum Group at Simmons & Simmons
  • Luke Vile – Technical Specialist in Technology Resilience & Cyber at the Financial Conduct Authority (FCA)
  • Olga Mamlyga – CEO of Quantum Scouts ApS
  • Lord Holmes of Richmond – Member of the House of Lords and a leading voice on technology, innovation and regulation.

Key takeaways

Background

Quantum computing has the potential to fundamentally change cybersecurity because of its ability to break some of the cryptographic systems that underpin modern digital communications.

Quantum computers use qubits (quantum bits), a basic unit of information used to encode data. In 'classical computing' (i.e. the device you are reading this on) it stores data in bits that exist in one state at any time, either a '1' or a '0'. In quantum computing that can exist in multiple states simultaneously (called "superposition"). This enables the quantum computer to solve certain complex problems much faster.

Much of current global data cryptography (e.g. HTTPS or emails) operate on Public Key Infrastructure ("PKI). This relies on cryptographic algorithms secured by complex mathematical problems that would take classical computers thousands of years to solve. In 1994, Peter Shor developed a quantum algorithm which demonstrated that sufficiently powerful quantum computers could solve these problems far more quickly, potentially breaking some of the cryptographic systems that underpin PKI. The future milestone when quantum computers become powerful enough to break standard PKI is known as "Q-Day".

Prepare

While Q-Day has not yet arrived, the timeline for its arrivals is now measured in months and years, not decades. Organisations should begin preparing now due to the risk of what is called "Harvest Now, Decrypt Later" attacks, where encrypted data is collected today where it is anticipated that it can be decrypted in the future post Q-Day.

Preparing for the impact of quantum computing on cryptography is known as post-quantum cryptography or "PQC".

Laws and regulations

Although there is currently no dedicated legislation governing PQC, existing legal and regulatory obligations already require organisations to manage cybersecurity, data protection and resilience risks. Relevant frameworks include the Companies Act 2006, UK GDPR, NIS Regulations, NCSC guidance, the law of confidentiality and tort, and emergisg NIST standards. This is already likely to involve considering and planning a migration to a PQC environment.

Regulatory perspective

From a regulatory perspective, the FCA supports early action and alignment with the UK's National Cyber Security Centre (NCSC) guidance. Current recommendations are to:

  • Develop a risk-assessed migration plan by 2028.
  • Migrate critical systems by 2031-32.
  • Complete wider migration by 2035.

Delaying preparation is expected to increase both complexity and cost.

Practical challenges

A key message from industry practitioners is that PQC migration is not simply a cryptographic upgrade. It is an organisational transformation programme involving governance, architecture, risk management and business resilience. The greatest challenges are likely to arise from legacy infrastructure, hybrid environments, supply-chain dependencies and limited visibility of cryptographic assets. Organisations should focus on building cryptographic agility so that future cryptographic changes can be implemented without major system redesign.

Practical preparation should begin with:

  • Identifying where cryptography is used across the organisation.
  • Mapping cryptographic dependencies through tools such as SBOMs and CBOMs.
  • Assessing business and regulatory risks.
  • Prioritising critical systems and sensitive data.
  • Establishing governance structures and migration roadmaps.

The UK environment

In meeting the challenge of PQC migration and the impact of quantum more generally, the UK is considered to be in a strong position globally. This is due to significant investment, world-leading research and a growing quantum ecosystem.

Quantum technologies present substantial economic opportunities alongside cybersecurity challenges. The importance of quantum sovereignty, international collaboration and government leadership through standards, investment and regulation was highlighted throughout the discussion.

Key questions & answers

  • What are the most common migration challenges?
    • Managing hybrid environments where traditional and post-quantum cryptography must operate alongside one another.
  • How do you deal with the challenge of third-party dependencies within your 'tech stack'?
    • Successful migration requires early engagement with vendors and suppliers, as organisations rarely control their entire technology stack.
  • How does the UK compare to other international approaches?
    • Quantum strategies vary significantly across jurisdictions, but the UK can remain competitive through targeted investment and strong research capability.
  • Should we be prepared now for 'Harvest Now, Decrypt Later'?
    • Organisations should treat this as a current risk rather than a future problem and prioritise sensitive information that requires long-term confidentiality.
  • What are the key conclusions?
    • Organisations should start planning now. Early discovery, prioritisation and preparation will reduce future costs, support compliance and improve resilience against future quantum-related risks while positioning businesses to take advantage of emerging opportunities.

This document (and any information accessed through links in this document) is provided for information purposes only and does not constitute legal advice. Professional legal advice should be obtained before taking or refraining from any action as a result of the contents of this document.