This month the National Cyber Security Centre published its timeline for migrating UK organisations to post-quantum cryptography (PQC), alongside the government’s announcement of a new £10 million National Quantum Standards Network. Put plainly: the encryption that protects online banking, VPNs, email and cloud storage today will eventually be breakable by sufficiently powerful quantum computers, and the NCSC now has an official three-phase plan for organisations to move to quantum-resistant alternatives before that happens.
If “quantum computing” sounds like a problem for banks and governments rather than a 12-person consultancy in Leeds, you’re mostly right — but not entirely, and it’s worth understanding why.
What the NCSC timeline actually says
The roadmap runs in three phases stretching out to 2035, covering discovery (identifying where cryptography is used across an organisation’s systems), migration planning, and full transition to quantum-resistant algorithms. It’s aimed squarely at large enterprises, critical national infrastructure operators and government bodies that run bespoke systems with long lifespans — think banking cores, national grid control systems, defence contracts.
For most SMEs, the NCSC’s own guidance is reassuring: businesses relying on commodity IT — standard browsers, mainstream operating systems, cloud services from major vendors — should see this transition happen largely in the background, as Microsoft, Google, Apple and cloud providers update their platforms on your behalf. You won’t need a project plan for this the way a bank will.
Where SMEs genuinely need to pay attention
The exception is any business with bespoke or legacy systems — a custom-built customer database, an in-house payment integration, an older piece of line-of-business software that hasn’t been touched in years. If you can’t remember the last time a system was updated by its vendor, it may not be receiving these background upgrades at all. That’s worth a conversation with whoever built or maintains it, simply to confirm someone is tracking this on your behalf. This is exactly the kind of technical due diligence that BuildApps gets asked about when taking over or auditing custom-built systems — not because quantum computers are an imminent threat, but because “who is responsible for keeping this current” is a question every business should be able to answer.
The same logic applies to any third-party supplier you depend on for something security-sensitive — a payment processor, an identity verification tool, a document signing platform. It’s reasonable to ask any supplier handling sensitive data on your behalf whether quantum-safe migration is on their roadmap, even if the honest answer today is “not yet, it’s early.” Asking the question now means you’re not caught out asking it for the first time in 2033.
The quieter opportunity: trust and trade
The £10 million standards network is arguably more relevant to SMEs in the near term than the cryptography itself. It’s designed to give UK firms — including smaller manufacturers, testers, software houses and technical consultancies — a recognised framework for demonstrating credibility in emerging quantum-adjacent supply chains, similar to how ISO or Cyber Essentials certifications work today. If your business supplies into sectors like finance, defence, or advanced manufacturing, a UK-recognised standard is a genuine trade advantage worth watching as it develops, even if you’re years away from touching quantum technology directly.
Why “not urgent” doesn’t mean “not now”
It’s worth resisting the temptation to file this away entirely. Migrations like this tend to be planned over a decade precisely because retrofitting encryption into live systems at short notice is expensive and disruptive — the organisations that struggle most in 2034 will be the ones that never asked the question in 2026. A five-minute internal note now, listing which systems are vendor-managed and which are bespoke, costs nothing and saves a scramble later.
The takeaway
For the vast majority of UK SMEs, the NCSC’s quantum-safe timeline is not an action item for this quarter — mainstream software will handle it. The one thing worth doing today is checking whether any system your business depends on falls outside that “automatically updated” category. If you’re not sure, that uncertainty is the actual risk, not quantum computing itself.