General Atomics

The 2028 quantum deadline aerospace and defence suppliers can’t afford to ignore

Despite the deadline being years away, companies in the aerospace and defence sectors are being encouraged to start their planning now to ensure compliance later

A Typhoon FGR4 (serial ZK364) from the RAF's No 3(F) Squadron taxis to the runway at the 86th Air Base in Borcea, Romania, before launching for a 'Tango' QRA training scramble on 7 April 2026. Image: MOD Crown Copyright/AS1 Ben Webb
Photo: MOD Crown Copyright/AS1 Ben Webb

For aerospace and defence businesses, 2028 may sound like a long way off. In cybersecurity terms, it is not.

The UK’s National Cyber Security Centre (NCSC) expects organisations to have completed a full discovery of their cryptographic estate and produced an initial plan for moving to post-quantum cryptography (PQC) by then. Priority migrations should follow by 2031, with the wider transition completed by 2035.

This is not simply an IT upgrade. For companies designing aircraft, vehicles, sensors, communications equipment and other long-lived systems, decisions made today can determine whether those products remain secure decades from now.

What is the quantum threat?

Modern digital security relies heavily on public-key cryptography to protect communications, authenticate systems and establish secure connections. A sufficiently powerful, fault-tolerant quantum computer could use algorithms such as Shor’s algorithm to solve the mathematical problems underpinning much of this cryptography far more efficiently than conventional computers.

The risk is not necessarily waiting for such a machine to appear. Attackers can already collect encrypted information and store it for future use – an approach known as “harvest now, decrypt later”. If the data is still valuable when quantum computers become capable of breaking the relevant encryption, information captured today could potentially be decrypted tomorrow.

That matters particularly in aerospace and defence because the useful life of information can be extremely long. Engineering designs, technical specifications, mission data, source code, intellectual property and classified or commercially sensitive communications may remain valuable for years or decades.

What do the 2028, 2031 and 2035 milestones mean?

The NCSC’s timetable is best understood as three stages rather than three deadlines for buying new encryption. By 2028, companies need to know what they have and have a plan. Organisations should define their migration goals, conduct a full discovery exercise and produce an initial migration plan.

That means identifying systems, services, products and infrastructure that depend on vulnerable cryptography, understanding which data needs protection and identifying dependencies on suppliers and long-lived physical infrastructure.

For an aerospace or defence company, this could extend well beyond corporate laptops and servers. It may include secure communications, VPNs, identity and access systems, product software, embedded devices, networking equipment, industrial control systems, sensors, firmware, certificates and hardware roots of trust.

By 2031, companies must protect the highest-value assets first. The NCSC expects organisations to have completed their highest-priority migration activities and refined their plans into a detailed route to full migration.

Photo: BAE Systems

Priority should be given to systems handling the most sensitive or long-lived information and to infrastructure where replacement or upgrade takes significant time.

By 2035, companies must have completed the transition. The target is migration to PQC across all systems, services and products, although the NCSC recognises that a small number of difficult legacy technologies may take longer.

Why aerospace and defence face a particular challenge

A conventional IT system might be replaced every few years. An aircraft, radar system, satellite component or defence platform can remain in service for decades.

That creates a problem if a product designed today contains a cryptographic component that cannot later be upgraded. A secure algorithm is only part of the equation: companies also need to consider whether the hardware has enough processing capacity, whether firmware can be updated, whether certificates can be replaced, and whether the system architecture allows cryptographic algorithms to change.

Cyber security being done by a man on a computer
Photo: stock.adobe.com

The NCSC specifically highlights the need to account for long-lived hardware roots of trust and physical infrastructure when planning migrations. It also recommends building cryptographic agility, that is, the ability to change cryptographic algorithms without redesigning an entire system.

For product designers, this makes PQC a product-lifecycle issue rather than something that can be handed to the IT department later.

What could be exposed?

The obvious targets are encrypted communications and sensitive data, but the exposure can be broader. Companies should consider:

  • Proprietary engineering and manufacturing designs;
  • Source code and firmware;
  • Customer and supplier information;
  • Authentication and identity infrastructure;
  • Secure communications and remote-access systems;
  • Certificates, keys and public-key infrastructure;
  • Embedded systems, sensors and connected equipment;
  • Industrial control and operational technology; and
  • Product-level security mechanisms such as secure boot and hardware roots of trust.

The right question is not simply, “Where do we use encryption?” It is “which systems depend on cryptography, what information do they protect, and how long does that protection need to last?”

What should SMEs and suppliers do now?

Smaller businesses should not assume that PQC requires a specialist cryptography programme. The NCSC says that much commodity IT migration should arrive through normal vendor upgrades.

The bigger challenge is identifying where a business has customised software, specialist equipment or products with long operational lives. A practical starting point is to take the four steps towards compliance.

Firstly, companies should ask suppliers. Find out which products and services that they rely on use public-key cryptography, whether they have a PQC roadmap and whether upgrades can be delivered remotely.

Secondly, companies should map their dependencies. They should create a simple inventory of critical systems, products and data, including the expected lifetime of the information and the hardware protecting it.

NCSC
Photo: NCSC

Thirdly, firms should flag long-lived products. Anything being designed or procured today that may still be operating in the 2030s or beyond deserves particular scrutiny. Companies should build upgradeability and cryptographic agility into requirements now.

Lastly, companies must put PQC into procurement and design decisions. They should ask suppliers to explain how their products will support future cryptographic standards, rather than waiting until a replacement is needed.

The key message from the NCSC is straightforward: migration will take years, and organisations should start preparing now.

For aerospace and defence, where products and information can outlive several generations of IT, the 2028 milestone is best treated not as a distant compliance date, but as a design and investment deadline that is already approaching.

Related

Edgewing opens engineering hub in Italy with UK site to follow
The GCAP fighter jet
Edgewing opens engineering hub in Italy with UK site to follow
The first of three engineering hubs designed to support the development of the future GCAP fighter has opening, with similar sites in the UK and Japan coming soon.
Aerospace Defence

9 Oct 2026

Marshall Aerospace begins new chapter as Aurelius acquisition completes
Marshall Aerospace C-130s
Marshall Aerospace begins new chapter as Aurelius acquisition completes
The completion of AURELIUS' acquisition of Marshall Aerospace marks a new chapter in the company's illustrious history, which spans more than a century of engineering excellence, innovation and service.
UK and Germany back SaxaVord in new European space launch deal
SaxaVord Spaceport, Shetland
UK and Germany back SaxaVord in new European space launch deal
The UK and Germany have agreed to deepen space launch cooperation, with Scotland's SaxaVord Spaceport securing European access to orbit.
Aerospace Defence Space

9 Oct 2026

RAF Marham runway repairs strengthen its operational resilience
RAF F-35B 207 sqdrn
RAF Marham runway repairs strengthen its operational resilience
The resilience of RAF Marham’s airfield infrastructure has been reinforced following the completion of vital runway repairs, whilst maintaining support for Lightning Force operations.
Defence Member News

11 Oct 2026

Sentinel Photonics brings multiple laser detection sensors into one hub
Sentinel Photonics' LASARD MAX Connect
Sentinel Photonics brings multiple laser detection sensors into one hub
With one single hub that joins up laser detection sensors, operators can now see, share and act on laser threats across a wide area in real time.
AI to help SMEs win defence contracts: Inside Strategical’s solution
Aerospace SME using AI to win defence contracts
AI to help SMEs win defence contracts: Inside Strategical’s solution
Smaller suppliers can struggle to turn technical capability into defence orders. Strategical is using AI to make specialist bidding expertise more accessible and help businesses focus on work they can realistically secure.
Defence Member News

10 Oct 2026

UK and Germany back SaxaVord in new European space launch deal
SaxaVord Spaceport, Shetland
UK and Germany back SaxaVord in new European space launch deal
The UK and Germany have agreed to deepen space launch cooperation, with Scotland's SaxaVord Spaceport securing European access to orbit.
Aerospace Defence Space

9 Oct 2026

Excelerate Technology to build UK CNI robotic security solution
Satellite in Earth orbit
Excelerate Technology to build UK CNI robotic security solution
In a project co-funded by the European Space Agency Business Applications and Space Solutions (ESA BASS) and supported by the UK Space Agency, Excelerate Technology will build and demonstrate how space-enabled assets can provide innovative safety and security solutions, including protection of Critical National Infrastructure (CNI) at a site in the UK.
World Space Week: How British technology will help ESA return to the Moon
ESA Argonaut
World Space Week: How British technology will help ESA return to the Moon
As Europe prepares to return to the Moon, British-developed LEIA LiDAR technology will help ESA's Argonaut lander autonomously identify safe touchdown zones on the lunar surface.
Space

5 Oct 2026

Sentinel Photonics brings multiple laser detection sensors into one hub
Sentinel Photonics' LASARD MAX Connect
Sentinel Photonics brings multiple laser detection sensors into one hub
With one single hub that joins up laser detection sensors, operators can now see, share and act on laser threats across a wide area in real time.
Big cargo drones complete first BVLOS delivery to North Sea wind farm
Skyports and Ørsted North Sea wind farm cargo drone trial
Big cargo drones complete first BVLOS delivery to North Sea wind farm
Skyports and Ørsted conducted a complex North Sea cargo drone trial, illustrating how heavy loads can safely and efficiently be delivered offshore beyond visual line of sight (BVLOS).
Aerospace Security

9 Oct 2026

UK Government and UKRI invest £54m to prevent future disease outbreaks
Poultry facility
UK Government and UKRI invest £54m to prevent future disease outbreaks
The UK Government and UKRI are investing £54 million in biosecurity research to tackle antimicrobial resistance, improve disease outbreak preparedness, develop next-generation vaccines and strengthen protection against emerging biological threats.
Security

8 Oct 2026