The 2028 quantum deadline aerospace and defence suppliers can’t afford to ignore
For aerospace and defence businesses, 2028 may sound like a long way off. In cybersecurity terms, it is not.
The UK’s National Cyber Security Centre (NCSC) expects organisations to have completed a full discovery of their cryptographic estate and produced an initial plan for moving to post-quantum cryptography (PQC) by then. Priority migrations should follow by 2031, with the wider transition completed by 2035.
This is not simply an IT upgrade. For companies designing aircraft, vehicles, sensors, communications equipment and other long-lived systems, decisions made today can determine whether those products remain secure decades from now.
What is the quantum threat?
Modern digital security relies heavily on public-key cryptography to protect communications, authenticate systems and establish secure connections. A sufficiently powerful, fault-tolerant quantum computer could use algorithms such as Shor’s algorithm to solve the mathematical problems underpinning much of this cryptography far more efficiently than conventional computers.
The risk is not necessarily waiting for such a machine to appear. Attackers can already collect encrypted information and store it for future use – an approach known as “harvest now, decrypt later”. If the data is still valuable when quantum computers become capable of breaking the relevant encryption, information captured today could potentially be decrypted tomorrow.
That matters particularly in aerospace and defence because the useful life of information can be extremely long. Engineering designs, technical specifications, mission data, source code, intellectual property and classified or commercially sensitive communications may remain valuable for years or decades.
What do the 2028, 2031 and 2035 milestones mean?
The NCSC’s timetable is best understood as three stages rather than three deadlines for buying new encryption. By 2028, companies need to know what they have and have a plan. Organisations should define their migration goals, conduct a full discovery exercise and produce an initial migration plan.
That means identifying systems, services, products and infrastructure that depend on vulnerable cryptography, understanding which data needs protection and identifying dependencies on suppliers and long-lived physical infrastructure.
For an aerospace or defence company, this could extend well beyond corporate laptops and servers. It may include secure communications, VPNs, identity and access systems, product software, embedded devices, networking equipment, industrial control systems, sensors, firmware, certificates and hardware roots of trust.
By 2031, companies must protect the highest-value assets first. The NCSC expects organisations to have completed their highest-priority migration activities and refined their plans into a detailed route to full migration.

Priority should be given to systems handling the most sensitive or long-lived information and to infrastructure where replacement or upgrade takes significant time.
By 2035, companies must have completed the transition. The target is migration to PQC across all systems, services and products, although the NCSC recognises that a small number of difficult legacy technologies may take longer.
Why aerospace and defence face a particular challenge
A conventional IT system might be replaced every few years. An aircraft, radar system, satellite component or defence platform can remain in service for decades.
That creates a problem if a product designed today contains a cryptographic component that cannot later be upgraded. A secure algorithm is only part of the equation: companies also need to consider whether the hardware has enough processing capacity, whether firmware can be updated, whether certificates can be replaced, and whether the system architecture allows cryptographic algorithms to change.

The NCSC specifically highlights the need to account for long-lived hardware roots of trust and physical infrastructure when planning migrations. It also recommends building cryptographic agility, that is, the ability to change cryptographic algorithms without redesigning an entire system.
For product designers, this makes PQC a product-lifecycle issue rather than something that can be handed to the IT department later.
What could be exposed?
The obvious targets are encrypted communications and sensitive data, but the exposure can be broader. Companies should consider:
- Proprietary engineering and manufacturing designs;
- Source code and firmware;
- Customer and supplier information;
- Authentication and identity infrastructure;
- Secure communications and remote-access systems;
- Certificates, keys and public-key infrastructure;
- Embedded systems, sensors and connected equipment;
- Industrial control and operational technology; and
- Product-level security mechanisms such as secure boot and hardware roots of trust.
The right question is not simply, “Where do we use encryption?” It is “which systems depend on cryptography, what information do they protect, and how long does that protection need to last?”
What should SMEs and suppliers do now?
Smaller businesses should not assume that PQC requires a specialist cryptography programme. The NCSC says that much commodity IT migration should arrive through normal vendor upgrades.
The bigger challenge is identifying where a business has customised software, specialist equipment or products with long operational lives. A practical starting point is to take the four steps towards compliance.
Firstly, companies should ask suppliers. Find out which products and services that they rely on use public-key cryptography, whether they have a PQC roadmap and whether upgrades can be delivered remotely.
Secondly, companies should map their dependencies. They should create a simple inventory of critical systems, products and data, including the expected lifetime of the information and the hardware protecting it.

Thirdly, firms should flag long-lived products. Anything being designed or procured today that may still be operating in the 2030s or beyond deserves particular scrutiny. Companies should build upgradeability and cryptographic agility into requirements now.
Lastly, companies must put PQC into procurement and design decisions. They should ask suppliers to explain how their products will support future cryptographic standards, rather than waiting until a replacement is needed.
The key message from the NCSC is straightforward: migration will take years, and organisations should start preparing now.
For aerospace and defence, where products and information can outlive several generations of IT, the 2028 milestone is best treated not as a distant compliance date, but as a design and investment deadline that is already approaching.
Sign up for our newsletter and get our latest content in your inbox.
Similar Reads
Sign up for our newsletter. Select all sectors relevant to you.
Related















