General Atomics

The 2028 quantum deadline aerospace and defence suppliers can’t afford to ignore

Despite the deadline being years away, companies in the aerospace and defence sectors are being encouraged to start their planning now to ensure compliance later

A Typhoon FGR4 (serial ZK364) from the RAF's No 3(F) Squadron taxis to the runway at the 86th Air Base in Borcea, Romania, before launching for a 'Tango' QRA training scramble on 7 April 2026. Image: MOD Crown Copyright/AS1 Ben Webb
Photo: MOD Crown Copyright/AS1 Ben Webb

For aerospace and defence businesses, 2028 may sound like a long way off. In cybersecurity terms, it is not.

The UK’s National Cyber Security Centre (NCSC) expects organisations to have completed a full discovery of their cryptographic estate and produced an initial plan for moving to post-quantum cryptography (PQC) by then. Priority migrations should follow by 2031, with the wider transition completed by 2035.

This is not simply an IT upgrade. For companies designing aircraft, vehicles, sensors, communications equipment and other long-lived systems, decisions made today can determine whether those products remain secure decades from now.

What is the quantum threat?

Modern digital security relies heavily on public-key cryptography to protect communications, authenticate systems and establish secure connections. A sufficiently powerful, fault-tolerant quantum computer could use algorithms such as Shor’s algorithm to solve the mathematical problems underpinning much of this cryptography far more efficiently than conventional computers.

The risk is not necessarily waiting for such a machine to appear. Attackers can already collect encrypted information and store it for future use – an approach known as “harvest now, decrypt later”. If the data is still valuable when quantum computers become capable of breaking the relevant encryption, information captured today could potentially be decrypted tomorrow.

That matters particularly in aerospace and defence because the useful life of information can be extremely long. Engineering designs, technical specifications, mission data, source code, intellectual property and classified or commercially sensitive communications may remain valuable for years or decades.

What do the 2028, 2031 and 2035 milestones mean?

The NCSC’s timetable is best understood as three stages rather than three deadlines for buying new encryption. By 2028, companies need to know what they have and have a plan. Organisations should define their migration goals, conduct a full discovery exercise and produce an initial migration plan.

That means identifying systems, services, products and infrastructure that depend on vulnerable cryptography, understanding which data needs protection and identifying dependencies on suppliers and long-lived physical infrastructure.

For an aerospace or defence company, this could extend well beyond corporate laptops and servers. It may include secure communications, VPNs, identity and access systems, product software, embedded devices, networking equipment, industrial control systems, sensors, firmware, certificates and hardware roots of trust.

By 2031, companies must protect the highest-value assets first. The NCSC expects organisations to have completed their highest-priority migration activities and refined their plans into a detailed route to full migration.

Photo: BAE Systems

Priority should be given to systems handling the most sensitive or long-lived information and to infrastructure where replacement or upgrade takes significant time.

By 2035, companies must have completed the transition. The target is migration to PQC across all systems, services and products, although the NCSC recognises that a small number of difficult legacy technologies may take longer.

Why aerospace and defence face a particular challenge

A conventional IT system might be replaced every few years. An aircraft, radar system, satellite component or defence platform can remain in service for decades.

That creates a problem if a product designed today contains a cryptographic component that cannot later be upgraded. A secure algorithm is only part of the equation: companies also need to consider whether the hardware has enough processing capacity, whether firmware can be updated, whether certificates can be replaced, and whether the system architecture allows cryptographic algorithms to change.

Cyber security being done by a man on a computer
Photo: stock.adobe.com

The NCSC specifically highlights the need to account for long-lived hardware roots of trust and physical infrastructure when planning migrations. It also recommends building cryptographic agility, that is, the ability to change cryptographic algorithms without redesigning an entire system.

For product designers, this makes PQC a product-lifecycle issue rather than something that can be handed to the IT department later.

What could be exposed?

The obvious targets are encrypted communications and sensitive data, but the exposure can be broader. Companies should consider:

  • Proprietary engineering and manufacturing designs;
  • Source code and firmware;
  • Customer and supplier information;
  • Authentication and identity infrastructure;
  • Secure communications and remote-access systems;
  • Certificates, keys and public-key infrastructure;
  • Embedded systems, sensors and connected equipment;
  • Industrial control and operational technology; and
  • Product-level security mechanisms such as secure boot and hardware roots of trust.

The right question is not simply, “Where do we use encryption?” It is “which systems depend on cryptography, what information do they protect, and how long does that protection need to last?”

What should SMEs and suppliers do now?

Smaller businesses should not assume that PQC requires a specialist cryptography programme. The NCSC says that much commodity IT migration should arrive through normal vendor upgrades.

The bigger challenge is identifying where a business has customised software, specialist equipment or products with long operational lives. A practical starting point is to take the four steps towards compliance.

Firstly, companies should ask suppliers. Find out which products and services that they rely on use public-key cryptography, whether they have a PQC roadmap and whether upgrades can be delivered remotely.

Secondly, companies should map their dependencies. They should create a simple inventory of critical systems, products and data, including the expected lifetime of the information and the hardware protecting it.

NCSC
Photo: NCSC

Thirdly, firms should flag long-lived products. Anything being designed or procured today that may still be operating in the 2030s or beyond deserves particular scrutiny. Companies should build upgradeability and cryptographic agility into requirements now.

Lastly, companies must put PQC into procurement and design decisions. They should ask suppliers to explain how their products will support future cryptographic standards, rather than waiting until a replacement is needed.

The key message from the NCSC is straightforward: migration will take years, and organisations should start preparing now.

For aerospace and defence, where products and information can outlive several generations of IT, the 2028 milestone is best treated not as a distant compliance date, but as a design and investment deadline that is already approaching.

Related

Syensqo powers NOEMI’s bid for the world’s first certified electric amphibious seaplane
NOEMI's all-electric amphibious seaplane.
Syensqo powers NOEMI’s bid for the world’s first certified electric amphibious seaplane
NOEMI Aerospace will use Syensqo advanced composites and adhesives to support the lightweight airframe of its pioneering all-electric amphibious aircraft.
Aerospace Member News

10 Sep 2026

Winter hydrogen trial at Exeter Airport strengthens case for lower-carbon ground operations
HyGPU trial Exeter Airport
Winter hydrogen trial at Exeter Airport strengthens case for lower-carbon ground operations
Exeter Airport’s latest hydrogen trial found a converted dual-fuel ground power unit could operate safely in winter, reducing diesel burn and carbon emissions.
Aerospace

10 Sep 2026

Ontic acquires compass specialist SIRS Navigation
SIRS Navigation compass
Ontic acquires compass specialist SIRS Navigation
The acquisition of the Kent-based precision magnetic compass manufacturer, adds a trusted brand to Ontic's expansive portfolio of critical aviation components.
Aerospace Member News

10 Sep 2026

Barbara Supplee appointed CEO of Serco North America
Barbara Supplee
Barbara Supplee appointed CEO of Serco North America
Drawing on her vast experience of supporting some of the United States' most important defence and national security missions, Barbara will lead Serco's delivery of mission-critical programmes in North America.
HMS Daring powers up Sampson radar ahead of Royal Navy return to sea
Type 45 destroyer HMS Daring
HMS Daring powers up Sampson radar ahead of Royal Navy return to sea
The Type 45 destroyer is in the finishing stages of completing her years long programme of regenerating to active service.
Defence

10 Sep 2026

UK helped foil Russian operation targeting vital Arctic subsea cables
HMS St Albans monitoring Admiral Levchenko
UK helped foil Russian operation targeting vital Arctic subsea cables
An exclusive Reuters report uncovers new details of a covert Arctic operation, with Russian subs allegedly "training to unleash a secret weapon".
Defence

10 Sep 2026

NewOrbit gains launch slot for first VLEO commercial mission
NEO1
NewOrbit gains launch slot for first VLEO commercial mission
Reading-based NewOrbit will conduct the first commercial mission on which any payload developer can fly, test and validate technology in Very Low Earth Orbit (VLEO), approximately 200-300km above the Earth.
Space

10 Sep 2026

Major General Tedman joins Seraphim Global Space Council
Satellite in orbit by uk space agency
Major General Tedman joins Seraphim Global Space Council
Seraphim Space has welcomed Major General Paul Tedman CBE - one of Europe’s most senior and military space leaders and until recently the Commander of UK Space Command - to its Global Space Futures Advisory Council.
Member News Space

10 Sep 2026

Filtronic strengthens access to India’s space and defence sectors
Filtronic and Spur Microwave MoU signing
Filtronic strengthens access to India’s space and defence sectors
Following the signing of an MoU with Spur Microwave, Sedgefield based high-frequency connectivity solutions provider Filtronic, aims to increased its access to space and defence opportunities in India.
Barbara Supplee appointed CEO of Serco North America
Barbara Supplee
Barbara Supplee appointed CEO of Serco North America
Drawing on her vast experience of supporting some of the United States' most important defence and national security missions, Barbara will lead Serco's delivery of mission-critical programmes in North America.
MBDA opens Poland missile facility as UK defence partnership deepens
MBDA facility Czosnow, Poland
MBDA opens Poland missile facility as UK defence partnership deepens
In an initiative that supports the UK’s commitment to reinforcing NATO’s eastern flank by bolstering Polish air defences, a new facility built with British expertise has been opened in Poland.
Chess introduces AI-enabled Low SWaP CHARM50
Low-SWaP-CHARM50
Chess introduces AI-enabled Low SWaP CHARM50
Chess Dynamics has expanded its Vision4ce CHARM portfolio with the introduction of its Low SWaP CHARM50, a new compact AI-enabled edge video processing module which supports growing demand for smart sensors, distributed sensing architectures and low-SWaP ISR applications.