General Atomics

The 2028 quantum deadline aerospace and defence suppliers can’t afford to ignore

Despite the deadline being years away, companies in the aerospace and defence sectors are being encouraged to start their planning now to ensure compliance later

A Typhoon FGR4 (serial ZK364) from the RAF's No 3(F) Squadron taxis to the runway at the 86th Air Base in Borcea, Romania, before launching for a 'Tango' QRA training scramble on 7 April 2026. Image: MOD Crown Copyright/AS1 Ben Webb
Photo: MOD Crown Copyright/AS1 Ben Webb

For aerospace and defence businesses, 2028 may sound like a long way off. In cybersecurity terms, it is not.

The UK’s National Cyber Security Centre (NCSC) expects organisations to have completed a full discovery of their cryptographic estate and produced an initial plan for moving to post-quantum cryptography (PQC) by then. Priority migrations should follow by 2031, with the wider transition completed by 2035.

This is not simply an IT upgrade. For companies designing aircraft, vehicles, sensors, communications equipment and other long-lived systems, decisions made today can determine whether those products remain secure decades from now.

What is the quantum threat?

Modern digital security relies heavily on public-key cryptography to protect communications, authenticate systems and establish secure connections. A sufficiently powerful, fault-tolerant quantum computer could use algorithms such as Shor’s algorithm to solve the mathematical problems underpinning much of this cryptography far more efficiently than conventional computers.

The risk is not necessarily waiting for such a machine to appear. Attackers can already collect encrypted information and store it for future use – an approach known as “harvest now, decrypt later”. If the data is still valuable when quantum computers become capable of breaking the relevant encryption, information captured today could potentially be decrypted tomorrow.

That matters particularly in aerospace and defence because the useful life of information can be extremely long. Engineering designs, technical specifications, mission data, source code, intellectual property and classified or commercially sensitive communications may remain valuable for years or decades.

What do the 2028, 2031 and 2035 milestones mean?

The NCSC’s timetable is best understood as three stages rather than three deadlines for buying new encryption. By 2028, companies need to know what they have and have a plan. Organisations should define their migration goals, conduct a full discovery exercise and produce an initial migration plan.

That means identifying systems, services, products and infrastructure that depend on vulnerable cryptography, understanding which data needs protection and identifying dependencies on suppliers and long-lived physical infrastructure.

For an aerospace or defence company, this could extend well beyond corporate laptops and servers. It may include secure communications, VPNs, identity and access systems, product software, embedded devices, networking equipment, industrial control systems, sensors, firmware, certificates and hardware roots of trust.

By 2031, companies must protect the highest-value assets first. The NCSC expects organisations to have completed their highest-priority migration activities and refined their plans into a detailed route to full migration.

Photo: BAE Systems

Priority should be given to systems handling the most sensitive or long-lived information and to infrastructure where replacement or upgrade takes significant time.

By 2035, companies must have completed the transition. The target is migration to PQC across all systems, services and products, although the NCSC recognises that a small number of difficult legacy technologies may take longer.

Why aerospace and defence face a particular challenge

A conventional IT system might be replaced every few years. An aircraft, radar system, satellite component or defence platform can remain in service for decades.

That creates a problem if a product designed today contains a cryptographic component that cannot later be upgraded. A secure algorithm is only part of the equation: companies also need to consider whether the hardware has enough processing capacity, whether firmware can be updated, whether certificates can be replaced, and whether the system architecture allows cryptographic algorithms to change.

Cyber security being done by a man on a computer
Photo: stock.adobe.com

The NCSC specifically highlights the need to account for long-lived hardware roots of trust and physical infrastructure when planning migrations. It also recommends building cryptographic agility, that is, the ability to change cryptographic algorithms without redesigning an entire system.

For product designers, this makes PQC a product-lifecycle issue rather than something that can be handed to the IT department later.

What could be exposed?

The obvious targets are encrypted communications and sensitive data, but the exposure can be broader. Companies should consider:

  • Proprietary engineering and manufacturing designs;
  • Source code and firmware;
  • Customer and supplier information;
  • Authentication and identity infrastructure;
  • Secure communications and remote-access systems;
  • Certificates, keys and public-key infrastructure;
  • Embedded systems, sensors and connected equipment;
  • Industrial control and operational technology; and
  • Product-level security mechanisms such as secure boot and hardware roots of trust.

The right question is not simply, “Where do we use encryption?” It is “which systems depend on cryptography, what information do they protect, and how long does that protection need to last?”

What should SMEs and suppliers do now?

Smaller businesses should not assume that PQC requires a specialist cryptography programme. The NCSC says that much commodity IT migration should arrive through normal vendor upgrades.

The bigger challenge is identifying where a business has customised software, specialist equipment or products with long operational lives. A practical starting point is to take the four steps towards compliance.

Firstly, companies should ask suppliers. Find out which products and services that they rely on use public-key cryptography, whether they have a PQC roadmap and whether upgrades can be delivered remotely.

Secondly, companies should map their dependencies. They should create a simple inventory of critical systems, products and data, including the expected lifetime of the information and the hardware protecting it.

NCSC
Photo: NCSC

Thirdly, firms should flag long-lived products. Anything being designed or procured today that may still be operating in the 2030s or beyond deserves particular scrutiny. Companies should build upgradeability and cryptographic agility into requirements now.

Lastly, companies must put PQC into procurement and design decisions. They should ask suppliers to explain how their products will support future cryptographic standards, rather than waiting until a replacement is needed.

The key message from the NCSC is straightforward: migration will take years, and organisations should start preparing now.

For aerospace and defence, where products and information can outlive several generations of IT, the 2028 milestone is best treated not as a distant compliance date, but as a design and investment deadline that is already approaching.

Related

Which UK airports will actually need more capacity by 2050?
Heathrow third runway
Which UK airports will actually need more capacity by 2050?
UK air travel could grow 68% by 2050, but the capacity crunch will not be evenly spread. New DfT data reveals which airports will fill terminals and runways.
Aerospace

26 Aug 2026

Lockerbie bombmaker’s trial could mark longest wait for justice in commercial aviation history
Pan Am Flight 103 crash Lockerbie Scotland
Lockerbie bombmaker’s trial could mark longest wait for justice in commercial aviation history
Nearly 38 years after Pan Am Flight 103 was destroyed over Lockerbie, alleged bombmaker Abu Agila Mas’ud is still awaiting trial.
Aerospace

26 Aug 2026

National Wealth Fund invests £71m in Tungsten West to unlock critical UK tungsten supply
Hemerdon Mine.
National Wealth Fund invests £71m in Tungsten West to unlock critical UK tungsten supply
A £71 million National Wealth Fund investment will help restart the Hemerdon mine in Devon, securing a UK source of tungsten for defence, aerospace and energy applications.
Aerospace Defence

26 Aug 2026

British naval gun maker wins NATO order while Royal Navy buys elsewhere
30mm MSI-DS Naval Gun
British naval gun maker wins NATO order while Royal Navy buys elsewhere
MSI Defence Systems has secured a €19.4m contract from an unnamed NATO country for three 30mm naval gun systems configured for counter-UAS missions.
Defence

26 Aug 2026

National Wealth Fund invests £71m in Tungsten West to unlock critical UK tungsten supply
Hemerdon Mine.
National Wealth Fund invests £71m in Tungsten West to unlock critical UK tungsten supply
A £71 million National Wealth Fund investment will help restart the Hemerdon mine in Devon, securing a UK source of tungsten for defence, aerospace and energy applications.
Aerospace Defence

26 Aug 2026

Defence Academy extends King’s College London and Cranfield contracts to 2031
Defence Academy library
Defence Academy extends King’s College London and Cranfield contracts to 2031
The renewed agreements will continue to support professional military education and defence learning across the UK and allied nations.
Defence Member News

26 Aug 2026

STFC reveals latest Ernest Rutherford Fellows
space nebula
STFC reveals latest Ernest Rutherford Fellows
Backed by an investment of £6 million, seven early-career physicists have been awarded Ernest Rutherford Fellowship’s by the Science and Technology Facilities Council (STFC), supporting research, from the search for dark matter to the physics of black holes.
Space

25 Aug 2026

Austrian ENPULSION moves to acquire UK space propulsion specialist Lift Me Off
Enpulsion space propulsion manufacturer buys UK company lift me off
Austrian ENPULSION moves to acquire UK space propulsion specialist Lift Me Off
Austrian spacecraft propulsion manufacturer ENPULSION has agreed to acquire British specialist Lift Me Off, bringing together electric and chemical propulsion capabilities in a deal that will require UK Government approval.
Member News Space

21 Aug 2026

Lanarkshire AI Growth Zone gains £300m investment as Dell establishes Scottish base
Lanarkshire’s AI Innovation Park
Lanarkshire AI Growth Zone gains £300m investment as Dell establishes Scottish base
A £202 million guarantee from the UK National Wealth Fund has attracted an investment of £300 million in Lanarkshire's AI Growth Zone, which with Dell Technologies establishing a base there too, is set to support over 3,400 skilled jobs.
Serco to support prison infrastructure at Christchurch Men’s Prison
Rachel Leota, New Zealand​ Department of Corrections Chief Executive and Ben Tracey, Serco Asia Pacific Director Facilities Management and Public Private Partnerships
Serco to support prison infrastructure at Christchurch Men’s Prison
As the New Zealand Government looks to add much needed capacity to its prison system, it has selected Serco to provide facilities management and maintenance services to support a safe and resilient prison infrastructure at Christchurch Men’s Prison.
Member News Security

25 Aug 2026

UK defence jobs jump by 26,000 as MoD spending supports 274,000 workers
UK defence jobs jump by 26,000 as MoD spending supports 274,000 workers
Ministry of Defence spending with UK industry now supports one in every 100 jobs, according to new figures.
Defence Security

21 Aug 2026

Darktrace among first cybersecurity firms selected to integrate risk signals into Microsoft Agent 365
Using laptop and mobile phone
Darktrace among first cybersecurity firms selected to integrate risk signals into Microsoft Agent 365
The integration will bring Darktrace's behavioural risk signals into Microsoft Agent 365, enabling customers to view organisation-specific insights alongside Microsoft signals in a single interface.
Security

20 Aug 2026