top of page
Specialised Consulting · Post-Quantum Readiness

Data your organisation protects today may be readable before the decade is out. That is a current exposure, not a future one.

The first core standards are final. NIST published them in August 2024. The harder work is integrating them across enterprise systems, protocols, certificates and supply chains, and that work is still developing.

The complication is that the risk does not begin when quantum computers arrive. Encrypted traffic can be captured and stored now for decryption later. Data that must remain confidential into the 2030s may already be exposed to collection where its protection depends on quantum vulnerable public key cryptography.

Governments and national cyber authorities have begun publishing migration timelines. Boards are beginning to be asked whether the organisation has a credible transition plan.

Midships offers a complimentary private briefing for boards and senior executives at large enterprises. The purpose is to establish where you stand, not to sell you a programme.

01

The timelines that now exist

United Kingdom

The NCSC set phased expectations: cryptographic discovery and an initial migration plan complete by 2028, highest priority systems migrated by 2031, full transition by 2035.

European Union

The Commission's migration recommendation sets 2030 for critical infrastructure, with member state national roadmaps expected by the end of 2026.

United States

Executive Order 14412, signed 22 June 2026, sets 31 December 2030 for transitioning the most sensitive federal systems and 31 December 2031 for post quantum authentication.

Other jurisdictions and sector bodies have issued guidance of their own, and part of the briefing is establishing which of it reaches you.

The dates sit further out than most compliance deadlines. The work is larger than most compliance programmes.

02

Why the deadline is closer than it looks

There is a simple test that boards find clarifying.

Add the number of years your data must remain confidential to the number of years your migration will take. If that total extends past the point at which a cryptographically relevant quantum computer becomes plausible, you are exposed today.

Regulated financial and insurance data routinely carries confidentiality obligations measured in years or decades, and the specific periods vary by jurisdiction and data type. A full cryptographic migration across a large regulated estate is a multi year programme.

For most institutions the arithmetic closes faster than executives expect.

03

Where the harder problem sits

Migration has not proceeded evenly, and the pattern matters.

Moved first — confidentiality

Confidentiality mechanisms have moved first. Protecting data in transit is comparatively straightforward and directly addresses the collection risk, so that is where adoption has concentrated.

Moved slowly — authentication

Authentication has moved more slowly. Certificates touch everything: identity providers, service to service authentication, code signing, device trust, and every application that depends on them. Standards and interoperability in this area remain less mature, and the estate is usually less well documented than teams assume.

Discovery frequently identifies undocumented certificates, cryptographic dependencies and supplier constraints. This is the harder half of the problem and the half most organisations have not started.

04

The binding constraint is agility, not algorithms

The algorithms exist. The difficulty is that most enterprise systems have cryptography embedded in ways that cannot be changed without re engineering the application.

The practical objective is not migrating to a specific algorithm. It is reaching a position where algorithms can be replaced without redesign, because they will need to be replaced again. Standards bodies are consulting on further signature standards, and deprecation schedules already contemplate the current generation being retired.

Organisations that invest in cryptographic agility should be able to replace algorithms with materially less re engineering in future migrations.

05

Three questions for your next board meeting

Do we have a cryptographic inventory?

Not a policy on cryptography. An inventory: which algorithms, in which systems, protecting which data, expiring when.

Which of our data must remain confidential beyond 2035?

Where that data depends on quantum vulnerable public key cryptography, it is exposed to collection now. It should be migrated first, and it rarely is.

Can we change a cryptographic algorithm without changing the applications that depend on it?

If the answer is no, the timeline is not your constraint. The architecture is.

06

The briefing — complimentary · 60 minutes · private

A complimentary 60 minute private session for boards, audit and risk committees, and senior technology, security and risk leaders at large enterprises.

You leave with:

Clarity

Which timelines apply given where you operate and what regulates you.

Priorities

An initial view of where your estate is likely to be most exposed, based on how your identity and cryptographic infrastructure is built.

A plan

A 90 day action plan focused on discovery and sequencing, which is where every credible migration begins. Yours to keep and execute with your own teams.

07

When this briefing is not worth your time

We would rather say so now than in the meeting.

Already ahead

If you have completed a cryptographic inventory and have a funded migration plan with named owners, you are ahead of most and do not need this.

Not yet board level

If your organisation holds no data requiring confidentiality beyond the next few years and operates outside the regimes above, this is not yet a board level issue.

Vendor evaluation

If you want a vendor evaluation, we do not do that here.

08

What we do, and what we do not

What we do not

We do not sell cryptographic products and we do not resell them. We are not a certificate authority and we take no position on which vendors an organisation should use.

What we do

Our work is identity and security infrastructure for large regulated enterprises. Certificates, authentication and the systems that depend on them are what we operate. That gives us a view of the part of the migration most organisations find hardest, and no commercial reason to recommend one path over another.

Cryptographic policy, regulatory interpretation and formal risk assessment remain with your security leadership, counsel and auditors.

The migration is not urgent because a quantum computer exists. It is urgent because the data being collected today will still be sensitive when one does.

For boards and senior decision makers at large enterprises.

bottom of page