PQC migration isn’t a cryptography problem

by | Sep 21, 2026

Saying that post-quantum cryptography (PQC) migration isn’t really a cryptography problem might sound like an odd statement from someone who spends a lot of time talking to organisations about post-quantum cryptography.

But it’s a point I kept coming back to during a recent webinar led by Graham Peters from Arqit, PQC Migration: Strategies to Address the Board-Level Issue That Won’t Wait, alongside Lucy Potter from Frazer-Nash Consultancy and Daryl Flack from Avella Security.

When people hear ‘PQC migration’, they naturally focus on the cryptography element. Which algorithms will replace today’s standards? When will quantum computers arrive? How quickly do we need to migrate?

These are important questions, but in reality, they aren’t the hardest ones to answer.

The bigger challenge is for boards and senior leaders to fully understand how deeply cryptography is embedded across modern organisations. Far more than a technology upgrade, PQC migration touches systems, supply chains, governance, risk and long-term business resilience. This makes understanding both where cryptography is today and what it will take to change it crucial.

This is maybe the most important takeaway from our discussion – that if organisations treat PQC migration as a technical exercise alone, they’ll miss the scale of the challenge entirely.

When a cyber security challenge becomes a business transformation challenge

The challenge is no longer theoretical. Governments, regulators and major technology providers are establishing timelines and expectations. Organisations are increasingly being asked not whether they should prepare, but how.

Part of the urgency comes from what’s commonly known as ‘harvest now, decrypt later’ (HNDL). Sensitive data encrypted today can be captured and stored in the hope that future quantum computers will eventually be able to decrypt it. For organisations responsible for long-lived confidential information, from defence and critical infrastructure to financial and healthcare data, that’s a risk that needs to be factored into decisions being made today.

But what makes this different from previous cyber security challenges is its reach. PQC migration doesn’t sit neatly within a single team or function, demanding coordination across technology, operations, procurement, risk and leadership teams.

Procurement is a good example of why. If you haven’t stemmed the flow of classical cryptography into your ecosystem, you’re in danger of playing whack-a-mole as new systems that need migrating appear halfway through your programme. Once you’ve started moving away from older cryptography, you need to make sure you’re not continuing to buy more of it. That means working with procurement teams to favour quantum-safe or easily updatable cryptography wherever possible – and where that isn’t available, suppliers should have a clear roadmap in place that aligns with your organisation’s risk profile.

That’s why PQC migration is a business transformation challenge. Getting it right depends on policy, procurement, governance and organisational change just as much as it depends on technology, taking it all the way up to board level.

Visibility before migration

What’s interesting is that many leaders instinctively jump straight to migration. They start asking which algorithms they need, what technologies they should deploy or what their future architecture might look like.

But during the webinar, a different theme emerged: visibility. If you don’t know what you have, then you can’t risk assess against it. You can’t manage it, you can’t see it and you can’t plan for it. It’s a simple observation, but an important one.

In my experience, many organisations are looking for a migration strategy before they’ve established a clear view of their cryptographic estate. Yet understanding that landscape is often where the most valuable conversations begin. That doesn’t mean waiting until you’ve completed a full discovery of your estate before you start migrating. If you wait until that exercise is finished, you’ll never start. The important thing is knowing where your cryptographic assets are and building visibility of the systems that matter most. From there, cryptographic discovery should evolve into an ongoing monitoring and compliance activity, because your estate is constantly changing. In parallel, organisations should already be starting migration, or else they risk spending years discovering the problem without ever reducing the risk.

At CC, that’s where we’re helping organisations focus first: building visibility across complex estates, identifying cryptographic dependencies, understanding the implications of quantum risk, and developing practical migration roadmaps that align with broader business and technology objectives.

The organisations moving first

We also explored why some sectors appear to be moving faster than others. Financial services often receive attention for its early activity, but in my view, telecoms, energy and other critical infrastructure sectors are also making significant progress. What they tend to have in common is an understanding that trust, resilience and secure communications sit at the heart of their business models.

Another theme that emerged was the importance of collaboration. Whether it’s supply chains, standards bodies, government guidance or cross-functional leadership teams, no organisation can navigate this challenge in isolation. PQC migration touches procurement, governance, operations, risk, compliance and technology strategy in equal measure.

The organisations making the strongest progress are recognising this early and building the structures, governance, visibility and policies needed to support long-term change.

Watch the full discussion

When it comes to PQC, the organisations that succeed won’t necessarily be the ones with the most advanced technology but the ones that see PQC migration as a vital long-term business transformation programme that demands visibility, coordination and leadership across the organisation.

In PQC Migration: Strategies to Address the Board-Level Issue That Won’t Wait, I join Graham Peters (Arqit), Lucy Potter (Frazer-Nash Consultancy) and Daryl Flack (Avella Security) to discuss:

  • Why quantum risk has become a board-level concern
  • The implications of harvest now, decrypt later attacks
  • Why visibility is emerging as a critical first step
  • Lessons from sectors already moving ahead
  • The role of governance, regulation and organisational change

Watch the webinar to hear the full discussion and explore how CC can help your organisation understand its cryptographic landscape, build migration strategies and develop the capabilities needed to navigate PQC migration with confidence.

Expert authors

Bob Oates
Bob Oates
Associate Director at Cambridge Consultants | View profile

Bob is the technical lead for Cambridge Consultants' PQC offerings and a specialist in the interaction between safety and security for operational technology, critical infrastructure, and IoT devices.

Related insights

Deep tech

Are you curious about new technologies, and how they can lead to long-term sustainable value?

We think creatively at the intersection of business and technology, inventing solutions to redefine what you do.

Industries

You need a partner with intimate knowledge of your industry and proven experience of delivering value from deep tech breakthroughs.

Discover more about the work we do in your sector and how we can create real commercial advantage for you.

Insights

Take a look at the latest insights, ideas and perspectives from CC.

Explore a cross-section of up-to-date content on the deep tech trends shaping the future of business and society.

Careers

Are you looking for an opportunity for your abilities to be recognised, and make a real difference?

Whether you are just starting out or you’re an experienced professional, we would love to hear from you.