CyberAssure
Secure by design

Quantum-safe cryptography — cryptographic estate dependency model

AND = all dependencies required  ·  OR = any path suffices  ·  PQC readiness figures illustrative
Ownership: INT internal EXT external third party SHR shared config PQC readiness: ≥85% 70–85% 50–70% 30–50% <30%
Click any element for CAF v4.0 · NCSC · NIST · CNSA 2.0
Jon Silvester

Force field analysis — migration to quantum-safe cryptography

Lewin's model: a change happens when driving forces outweigh restraining forces. Drag any slider (0–5) to re-weight a force, or pick a sector profile. Click a force name for the evidence behind it and the lever that moves it.

Sector profile
0
Driving force
0
Restraining force
0
Net
Driving forces →
Change goal
Migrate the enterprise to quantum-safe cryptography
No sole dependence on traditional public-key cryptography by the NCSC deadline of 2035
← Restraining forces
Reading this: Lewin's central point is that increasing driving forces raises tension and provokes counter-pressure, whereas removing restraining forces lets the change move with less resistance. On this board the biggest restrainers — cost across leadership cycles, vendor roadmaps, and the absence of a visible incident — are largely addressed by evidence and governance rather than by technology. Weights are illustrative planning judgements as at August 2026, not measurements.
Horizon
Track
Owner
0 of 44
CyberAssure

Migration to Quantum-Safe Cryptography — Plan on a Page

Enterprise cryptographic migration  |  Jon Silvester  |  v1.0  |  August 2026  |  Two-track model — working back from the NCSC 2035 deadline

Target completion
2035
~9 years remaining · next gate 2028
2028 · 2031 · 2035
NCSC milestone gates
2 tracks
confidentiality (HNDL) & integrity (TNFL)
5 phases
delivery structure
2–3 yrs
discovery, strategy & initial plan
4–15 yrs
typical large-enterprise execution
Discover → Prioritise → Migrate → Verify
migration model
Programme timeline
Phase 1: Mobilisation & discovery
Phase 2: CBOM, risk scoring & roadmap
Phase 3: Track A — hybrid key exchange
Phase 4: Track B — PKI, signing & identity
Phase 5: Long tail, verification & closure
Critical milestone
Regulatory gate
Migration complete
2026
2027
2028
2029
2030
2031
2032
2033
2034
2035
Ph 1: Mobilisation
& discovery
2026 – mid 2028
Ph 2: CBOM, risk
scoring & roadmap
mid 2027 – 2028
Ph 3: Track A —
hybrid key exchange
2027 – 2031  ·  TLS, VPN, SSH, mTLS, data at rest
Ph 4: Track B — PKI,
signing & identity
2028 – 2033  ·  PKI, code signing, identity stack
Ph 5: Long tail,
verification & closure
2032 – 2035  ·  OT, legacy, archives, retire classical
Key milestones
M0 · 2026
Programme initiation
SRO and CISO mandate, multi-year funding envelope, board reporting line
M1 · end 2027
Cryptographic estate discovered
CBOM v1 across IT, OT and supplier-delivered services
Critical: zero float
M2 · 2028 — NCSC GATE
Discovery & assessment complete; initial plan built
Priorities, supplier and infrastructure dependencies, investment,
long-lived hardware roots of trust · supplier needs communicated
M3 · 2029
Track A at production scale
Hybrid key exchange live across Tier-1 data-in-transit channels
M4 · 2030 — REGULATORY CONVERGENCE
NIST IR 8547 deprecation · CNSA 2.0 firmware & network
Quantum-vulnerable public-key algorithms deprecated after 2030
M5 · 2031 — NCSC GATE
Highest-priority migration complete
Most critical assets protected · infrastructure PQC-ready
Clear route to full migration by 2035 · zero float
M6 · 2033
PKI migration complete · classical certificates retired
Also CNSA 2.0 gate for web, cloud and operating systems
M7 · 2034
Long tail remediated
OT, IoT, legacy protocols and signed archives closed out
or accepted as named residual risk with owners
M8 · 2035 — MIGRATION COMPLETE
No sole dependence on traditional public-key cryptography
Hybrid modes retired on defined trigger · evidence dossier closed
NIST IR 8547 disallowance · CNSA 2.0 full compliance
Five workstreams
1

Discovery, CBOM & risk scoring

Layered discovery across network, host and source · three parallel inventory tracks · data confidentiality horizon analysis · cryptographic bill of materials as a living record · risk-weighted migration backlog · CBOM secured and access-controlled as sensitive material

NCSC 2028 CAF A3 Asset Management
2

Track A — confidentiality (HNDL)

Hybrid X25519 + ML-KEM-768 on TLS 1.3 · RFC 9370 hybrid IKEv2 for VPN and IPsec · OpenSSH 9.9+ across the fleet · internal mTLS and service mesh · key wrapping for data at rest · gateway termination for constrained IoT · verify PQC is negotiated, not silently dropped

FIPS 203 ML-KEM CAF B3 Data Security
3

Track B — integrity, PKI & identity

LMS/XMSS dual-signing for firmware and secure boot now · parallel PQC enterprise PKI with ML-DSA · public Web PKI via Merkle Tree Certificates · identity stack as its own CBOM slice (passkeys, tokens, PKINIT, 802.1X) · signed archives re-anchored · OT firmware and SCADA authentication

FIPS 204 / 205 · SP 800-208 CAF B2 Identity & Access
4

Infrastructure, HSM & crypto-agility

HSM and KMS PQC capability assessment and replacement schedule · certificate lifecycle automation ahead of 47-day lifetimes · middlebox and TLS-inspection testing against hybrid handshakes · policy-driven crypto abstraction · defined trigger for retiring traditional algorithms

FIPS 140-3 CMVP CAF B4 System Security
5

Vendor governance, assurance & closure

Structured supplier questionnaires and algorithm-agility contract clauses · counterparty coordination where you cannot compel · published statement of intent · coverage metrics and evidence dossier from day one · SOC detection for classical fallback · residual risk accepted with named owners

CAF A4 Supply Chain NCSC 2035
Critical path & key dependencies
CP1

Executive mandate & multi-year funding secured

2026  ·  SRO / CISO / Board

Zero float — blocks every downstream activity
CP2

Cryptographic discovery complete across IT, OT & suppliers

2027 – mid 2028  ·  Security architecture / asset management

Zero float — gates the NCSC 2028 milestone
CP3

Data confidentiality horizon analysis

2027  ·  Information governance / risk

~6 months float — but it sets the migration order
CP4

FIPS 140-3 validated modules available for regulated systems

mid 2027 at the earliest  ·  External — NIST CMVP

Not within your control — gates regulated production
CP5

HSM & PKI platform PQC capability confirmed / procured

2028 – 2029  ·  Infrastructure & procurement

Zero float — longest procurement lead time in the plan
CP6

Supplier PQC roadmaps received & contracted

2028  ·  Vendor governance / commercial

Limited float — determines what you can actually migrate
CP7

Internal PKI migrated & classical certificates retired

2032 – 2033  ·  PKI / identity engineering

Zero float — no quantum-safe authentication until complete
CP8

Verification: no sole dependence on traditional PKC

2035  ·  CISO / SRO  ·  evidence dossier closed

Zero float — target completion date
Programme risk register (top risks)
CRIT

Harvest-now-decrypt-later exposure is already accruing

Impact: Traffic intercepted today cannot be un-captured; every day of delay permanently exposes data with a long confidentiality horizon.  Mitigation: Start Track A hybrid key exchange on Tier-1 channels immediately, ahead of full discovery; prioritise by data lifetime, not system age.

CRIT

Public Web PKI architecture unresolved — cannot be planned out

Impact: No agreed way to carry post-quantum signatures through a decentralised ecosystem of roots, CAs, CT logs and CRL providers; Merkle Tree Certificates change the trust model itself.  Mitigation: Invest in ACME automation now; keep plans flexible; track Chrome and CA roadmaps; separate public from internal PKI in the plan.

HIGH

Long-lived OT and IoT that cannot be migrated in place

Impact: 15–40 year lifecycles, resource-constrained or unreachable devices, proprietary protocols never brought to modern cryptographic standards.  Mitigation: Decide replace / gateway / isolate / tolerate per class early; align to capital replacement cycles; named exceptions with compensating controls and owners.

HIGH

Track B under-invested while Track A is declared “done”

Impact: Hybrid TLS on top endpoints looks like success but addresses only confidentiality; an integrity gap accumulates that becomes harder to close as the programme matures.  Mitigation: Run two tracks with separate milestones, budgets and reporting; launch Track B within 90 days of Track A.

HIGH

Vendor and SaaS roadmaps set the timeline, not you

Impact: Most capability is supplier-delivered, so completion dates are inherited; counterparties you cannot contractually compel gate email, federation and B2B channels.  Mitigation: Questionnaires and agility clauses at every renewal; published statement of intent; coordination pattern for non-compellable parties.

HIGH

FIPS 140-3 validation gap blocks regulated production

Impact: Regulated and national-security environments cannot deploy PQC to production until validated modules exist, compressing an already tight execution window.  Mitigation: Classify every system by environment class; pilot in unrestricted and FIPS-aware estates now; track CMVP progress as a formal dependency.

HIGH

Hybrid becomes permanent; classical is never retired

Impact: Without a defined trigger and coverage metrics, transitional hybrid modes persist indefinitely and the migration never formally closes — leaving sole dependence undetected.  Mitigation: Define switch-off criteria when hybrid is introduced; quantify PQC client coverage; SOC detection for classical fallback.

Governing frameworks:
NCSC PQC migration timelines NCSC CAF v4.0 NIST FIPS 203 / 204 / 205 NIST SP 800-208 NIST IR 8547 NSA CNSA 2.0 CA/Browser Forum SC-081v3 GovAssure
UK National Quantum Strategy  ·  Applied Quantum PQC Migration Framework v2.1
Governance
PQC Migration Board quarterly — SRO (Chair) · CISO · CTO · Head of Infrastructure · Data Protection Officer
Cryptographic Design Authority monthly — Lead Security Architect (Chair) · PKI lead · Crypto champions · OT SME
Vendor governance forum quarterly — supplier roadmaps, agility clauses, counterparty coordination
Milestone gate review at 2028, 2031 and 2035 — evidence pack to board and regulator
CyberAssure | Migration to quantum-safe cryptography | Plan on a Page | v1.0 | August 2026 Two-track model (HNDL / TNFL) | NCSC gates 2028 · 2031 · 2035 | Dates and durations illustrative for a large UK enterprise