The United Kingdom’s (UK) migration to post-quantum cryptography is now on a timetable. The National Cyber Security Centre (NCSC) has set three milestones: by 2028, organisations should have a migration plan covering their full estate; by 2031, their highest-priority services should be migrated; and by 2035, migration should be complete. The next two years therefore put discovery and planning at the centre of the national effort.
The strategic choice underneath that timetable is unusually clear. The NCSC will not support Quantum Key Distribution (QKD) for government or military applications, and describes Post-Quantum Cryptography (PQC) as the best mitigation against the quantum threat to cryptography. Its latest quantum-networking guidance goes further: a QKD implementation alone is insufficient evidence that data in transit is secure under the Cyber Assessment Framework.
That distinction should become an acquisition discipline. Choosing an algorithm answers a cryptographic question. Assuring a deployed system requires evidence about authentication, key lifecycle, control software, timing, relays, fallback behaviour, operator interfaces, and the way that these elements fail together. The NCSC roadmap understandably concentrates on discovery, planning, and migration. A programme-level artefact that assembles those wider claims into one end-to-end assurance case would make migration more governable without changing the underlying cryptographic policy.
The NCSC’s own migration guidance points to the same systems problem. It describes algorithm standards as building blocks from which protocols, products, and services still have to be constructed, and identifies difficult areas such as industrial-control protocols and the Web Public Key Infrastructure (PKI), where migration cannot be reduced to swapping one cryptographic primitive – the ‘building block’ of cryptographic programs – for another. Here is precisely where an assurance case adds value: it makes the surrounding dependencies and failure behaviour visible before an approved algorithm is mistaken for an approved system.
Why QKD still matters to Britain
The UK has good reason to retain the ability to judge technologies it has chosen not to deploy for governmental and military use. The 2023 National Quantum Strategy committed £2.5 billion of public funding from 2024 over ten years and set an ambition for Britain to become a leading quantum-enabled economy. Using the example of quantum sensing, it has been argued that the UK should prioritise in areas where it already leads. The strategic principle applies here as well: leadership includes the ability to evaluate claims made by domestic suppliers, allies, and competitors alike.
British networks will encounter those claims. BT and Toshiba operate a quantum-secured metropolitan network in London, while the European Union is building the European Quantum Communication Infrastructure (EuroQCI) – a terrestrial and satellite quantum-communications infrastructure that uses QKD and now includes dedicated testing and evaluation work aimed at certification. British forces, departments, and companies may therefore encounter products or allied systems described as quantum-secured even while the NCSC maintains a different procurement position for government and defence.
The ‘quantum-secured’ label itself is becoming less useful as architectures diversify. A vendor may use it for QKD, PQC, or a hybrid design that combines quantum and classical mechanisms. As these systems can have very different trust assumptions and failure modes, procurement therefore needs to translate the label into a specific claim: what is protected, against what threat, under what operating conditions, and with what dependencies inside the assurance boundary.
The physics provides a strong but bounded claim. In an ideal QKD protocol, interception disturbs quantum states in ways that the endpoints can detect, while the implemented system still depends on devices, calibration, classical authentication, key management, and control mechanisms. The United States (US) National Security Agency lists the consequences plainly: QKD does not authenticate the transmission source, requires special-purpose equipment, may rely on trusted relays, presents significant implementation assurance challenges, and carries denial-of-service risk.
Those limitations expose two linked attack surfaces. The first is classical and operational: authentication services and credentials, key-management software, trusted relay facilities, network orchestration, operator consoles, and the systems that decide what happens when a link degrades. The second lies in the quantum implementation: detector behaviour, source imperfections, calibration, timing side channels, and optical injection. Experimental work by the US National Security Agency has demonstrated attacks on commercial QKD equipment, including detector-blinding and timing attacks.
A security claim fails if either surface falls outside the evidence. A commander could therefore be told, accurately, that the quantum link is secure, while the conversation as a whole remains vulnerable elsewhere in the system. The US Department of War’s Defence Advanced Research Projects Agency’s (DARPA) Quantum-Augmented Network programme illustrates why the boundary matters: it explicitly integrates quantum and classical communications infrastructure, placing the seam between them within the engineering problem.
The same logic applies to the PQC route that the UK has chosen. A cryptographic inventory can identify which algorithms and protocols are present, but it cannot establish whether key management is compromised, whether a transitional hybrid connection falls back into an unexpected mode, whether an operator is warned when protection changes, or whether an implementation behaves safely under denial. Algorithm approval and system assurance are therefore separate evidence problems, even when the algorithm choice is sound.
Goals before 2028
Britain can turn this distinction into a practical acquisition artefact. Before a system is described operationally as quantum-secured, and as departments assemble evidence for PQC migration, programmes should produce a quantum communications assurance case with four parts.
Firstly, the security claim and the trust boundary should be stated. Documents should say which property the cryptography provides; where authentication comes from; who manages keys through their lifecycle; which relay nodes or infrastructure components are trusted; and whether timing, calibration, control software, and operator displays sit inside the assessed boundary.
Secondly, classical and quantum dependencies should be named and tested together. QKD systems should demonstrate robust quantum-resistant authentication alongside the quantum channel, using mechanisms consistent with NCSC guidance or appropriately managed pre-placed symmetric keys. PQC systems should identify the protocol, implementation, and key-management dependencies around standardised algorithms. In both cases, the evidence should continue from the cryptographic primitive through to the system built around it.
Thirdly, denial and downgrade behaviour should be specified before deployment. If a quantum channel is interrupted, or a transitional connection cannot negotiate its intended protection, the system should have a pre-approved response: halt, fail over to a defined mode, or continue under an explicitly accepted risk. The operator display should show which state is active and who accepted the residual risk.
Finally, the whole system should be adversarially evaluated. Link-level measurements such as key rate, quantum bit-error rate, photon loss, or entanglement fidelity establish technical performance where they are relevant. Security evaluation should also attack authentication, key management, control software, trusted nodes, timing and calibration paths, detectors and optical interfaces, fallback logic, and the consoles that report system state.
These requirements preserve research and migration while adding an evidence gate for operational security claims. Security credit follows only when both the classical and quantum dependencies are inside one evidence package and have been tested as a system. The approach also matches the NCSC’s own judgement that a QKD label cannot serve as a substitute for evidence of data-in-transit security.
The UK has an advantage in setting that standard. It possesses a clear national cryptographic position, a large quantum research and industrial base, and a national strategy that explicitly seeks leadership in quantum standards. Indeed, it has recently been argued that domestic or tightly allied control of next-generation technologies including quantum computing is a fundamental British interest. Assurance is one way to exercise that control while allowing allies to retain different technological choices.
A British assurance standard could travel across procurement, allied interoperability, and vendor evaluation, even where the underlying architectures differ. The 2028 milestone should therefore produce more than a complete map of algorithms and migration plans: it should also establish what evidence a system must present before anyone can label it quantum-secured.
The UK has already made the difficult choice about cryptography. The next task is to make the security claim auditable.
Burak Oktenli is an independent researcher based in Washington, DC, focusing on authority, assurance, and governance in autonomous and Artificial Intelligence (AI)-enabled systems. He holds an MBA and is completing a Master of Professional Studies in Applied Intelligence at Georgetown University.
To stay up to date with Britain’s World, please subscribe or pledge your support!
What do you think about this Memorandum? Why not leave a comment below?


