Critical National Infrastructure and Quantum Vulnerability: The UK Picture

The UK's Critical National Infrastructure is not a single sector. It is thirteen, each with its own regulatory authority, its own technology stack, and its own interpretation of what "appropriate security" means. That structural diversity is also the structural problem. When the NCSC published its PQC migration timeline, the guidance applied uniformly across all of them. The operators did not respond uniformly. Most have not yet completed a cryptographic inventory. Many have not started one.

NCSC sets the 2031 milestone for the highest-priority systems: those protecting long-lived sensitive data and those underpinning critical national infrastructure. For the majority of CNI operators, that is not a background deadline. It is the operative one. The 2035 backstop that appears in briefing summaries applies to general systems with lower risk profiles. Energy SCADA, financial clearing, NHS genomic records, and core telecoms routing are not low-risk general systems. For the organisations running them, 2031 is approximately four planning cycles away. And the first planning cycle, the cryptographic inventory, takes between six and eighteen months for a large operator.

This article maps the UK's thirteen CNI sectors against the NCSC timeline, identifies the regulatory levers that give that timeline real enforcement consequence, and names the operational technology systems where deferral creates the most serious exposure.

The Thirteen Sectors and the Two Regulatory Regimes

The Cabinet Office designates thirteen sectors as Critical National Infrastructure under UK government policy: chemicals, civil nuclear, communications, defence, emergency services, energy, finance, food, government, health, space, transport, and water. The Cabinet Office leads policy; sector-specific security regulation sits with sector regulators including Ofwat, Ofgem, the FCA, the CQC, the CAA, and the ONR. For government systems, NCSC and the Cabinet Office's Cyber and Government Security Directorate hold the primary assurance role.

Two distinct regulatory regimes create the enforcement mechanism across these sectors. The first is the UK NIS Regulations 2018, SI 2018/506, which applies to Operators of Essential Services in six of the thirteen sectors: transport, energy, health, drinking water supply and distribution, digital infrastructure, and banking and financial market infrastructure. Regulation 10 of SI 2018/506 requires OES to take "appropriate and proportionate technical and organisational measures" to manage risks to network and information systems. As NCSC guidance on quantum risk matures, what counts as "appropriate" increasingly includes PQC migration planning for high-priority systems.

The second regime covers government CNI through GovAssure. The Cabinet Office's GovAssure scheme applies the Cyber Assessment Framework as the technical baseline for government departments and arm's-length bodies. For departments, agencies, and government-owned critical systems, CAF assessments are not advisory. They are evidenced, reported obligations with accountability to Cabinet Office and NCSC.

What the NCSC Migration Timeline Actually Requires

The NCSC's published PQC migration guidance sets three milestones for UK organisations. By 2028, organisations should have developed a migration plan and identified and prioritised high-risk systems. By 2031, the highest-priority systems should be migrated. By 2035, all systems should be using quantum-safe cryptography.

The critical distinction is what the NCSC means by "highest-priority." The guidance defines this category as systems protecting long-lived sensitive data and systems underpinning critical national infrastructure. Most CNI operators should read that definition and recognise that the majority of their systems fall within it, not outside it. An energy operator's SCADA network protecting distribution control systems is CNI infrastructure. An NHS trust's genomic data repository holding records for decades qualifies as long-lived sensitive data. A financial institution's SWIFT messaging infrastructure, processing systemic clearing operations, sits squarely in the high-priority category.

The practical consequence of this misreading is already visible in sector planning. I have seen PQC programme timelines that point to 2035 as the operative deadline when the 2031 milestone applies to the systems being planned around. The time is shorter than most sector plans reflect.

CAF Objective B4 as the Assurance Mechanism

For organisations assessed under the CAF, which includes government CNI under GovAssure and many OES assessed by sector competent authorities, the regulatory hook for PQC migration is CAF Objective B4: Cryptography. CAF v3.2, published April 2024 and now the operative version for GovAssure assessments, requires assessed organisations to use appropriate cryptographic measures to protect information in transit and at rest, to maintain managed control over cryptographic key lifecycles, and to keep cryptographic controls under review "as standards evolve."

That final phrase is doing significant work. It explicitly incorporates the obligation to track NIST and NCSC PQC guidance as it develops. A CAF B4 assessment that was passed in 2023 against the cryptographic controls in place at that time is not a standing pass. NCSC guidance on quantum risk has developed materially since then. The cryptographic controls that satisfied B4 two years ago may not satisfy it today.

For government CNI operators under GovAssure, this is an assessed, evidenced obligation with reporting consequence. For non-government OES, the relevant competent authority, whether Ofgem, Ofwat, the FCA, or the CAA, will increasingly reference CAF B4 as the technical standard against which PQC migration planning is evaluated.

Sector Snapshots: Where the Operational Exposure Is Highest

Three sectors illustrate the range of operational technology exposure that makes CNI migration more complex than a standard IT migration.

Energy. SMETS2 smart metering infrastructure uses PKI-based authentication under the Great Britain Companion Specification. Distribution SCADA systems using DNP3 Secure Authentication operate on networks with 10-to-20-year asset lifespans. You cannot defer the PQC migration of these systems to 2034 and then migrate them in twelve months. The operational technology constraints mean migration planning must start now to be complete by 2031 for these systems. Ofgem is the competent authority under NIS Regulations for this sector.

Finance. SWIFT messaging infrastructure, FIX and FpML encrypted communications, and the emerging CBDC infrastructure all carry PKI dependencies that are quantum-vulnerable under Shor's algorithm. The FCA and PRA's operational resilience requirements, articulated through Supervisory Statement SS1/21, create an additional overlay: systems classified as "important business services" must be able to remain within defined tolerance for disruption. A PQC migration that disrupts clearing services outside tolerance is not compliant with SS1/21, even if it achieves technical security objectives. The migration must be designed around operational continuity from the outset.

Health. NHS England's CNI designation means its highest-priority systems fall under the 2031 NCSC milestone. Genomic data collected by NHS England and Genomics England is retained for decades. Patient records in the Summary Care Record system carry long retention periods. Both represent exactly the class of long-lived sensitive data that Harvest Now, Decrypt Later attacks target. Adversaries recording encrypted health data exchanges now can decrypt those records post-CRQC. The HNDL risk assessment framework sets out how to classify which data categories face the greatest exposure across sectors. The data sensitivity horizon for health records extends well beyond 2033-2035, placing NHS data squarely within the active HNDL risk window.

Common Planning Errors in CNI Sectors

Four misconceptions recur consistently in CNI PQC planning conversations.

The first is that the 2035 deadline is the operative one. For most CNI operators, it is not. The 2031 milestone applies to the systems that matter most, and those systems represent the majority of what most CNI operators run.

The second is that air-gapped OT systems are outside the HNDL threat model. Air gaps do not prevent encrypted data from leaving an environment through corporate IT overlays, management interfaces, or external data feeds. They also do not eliminate the need to migrate cryptographic controls that exist on the OT network itself. Many SCADA systems have authenticated communications channels. Those channels need to migrate even if the wider network is isolated.

The third is that passing a recent CAF assessment provides ongoing assurance. CAF assessments are point-in-time. The phrase "as standards evolve" in B4 means the obligation is continuous. Standards have evolved materially since 2023.

The fourth is that NIS Regulations do not mention quantum and therefore create no quantum obligation. Regulation 10's "appropriate and proportionate measures" standard is a living requirement that tracks NCSC guidance as it matures. The absence of explicit PQC language in the 2018 SI does not constrain what "appropriate" means in 2026.

What Operators Need to Do Now

The CNI sector protection roadmap details migration priorities for each of the thirteen designated sectors. The sequence for CNI operators begins with a cryptographic inventory: a systematic audit of where encryption is used across the organisation, which algorithms, which key sizes, and which systems qualify as highest-priority under the NCSC's 2031 criteria. Without the inventory, there is no migration plan. Without the migration plan, there is no 2028 compliance with the NCSC's first milestone.

Systems that meet the "long-lived sensitive data" or "CNI" criteria for the 2031 deadline should be identified and separated from the general estate early. The migration timeline for OT systems, particularly those with long asset lifecycles or operational continuity constraints, commonly runs three to five years from planning to completion. Operators should be working backwards from 2031, not forwards from today's planning cycle. The PQC migration timeline sets out the key milestones and what each requires in practice.

Competent authority engagement on CAF B4 evidence gathering is the assurance mechanism. Operators under GovAssure should ensure that PQC migration planning is documented as evidence for the next CAF assessment cycle. Operators under sector-regulator oversight should check whether their competent authority has published any sector-specific PQC guidance since 2024, and track that guidance as it develops.

QSECDEF's Q-Day timeline risk calculator provides a starting framework for assessing your organisation's quantum timeline exposure against the NCSC milestones. The cryptographic inventory guide covers the methodology for the first migration prerequisite. For OES assessing their NIS Regulations obligations specifically, the NCSC PQC migration guidance explainer translates the regulatory timeline into operational priorities.

The Window Is Shorter Than the Numbers Suggest

The Global Risk Institute's 2024 survey of 37 quantum computing and security experts estimated a 14-34% probability that a cryptographically relevant quantum computer capable of breaking RSA-2048 will exist by 2033-2035. That range is not a comfort margin. A 14% probability of Q-Day within nine years is a material risk for any organisation that will take three to five years to complete an OT migration and has not started planning.

The 2031 deadline is nine years away. A cryptographic inventory takes six to eighteen months. Architecture design and hybrid deployment testing takes another twelve to twenty-four months. OT migration planning in energy, transport, and health sectors adds further lead time. The arithmetic is straightforward. The organisations that are treating this as a 2029 problem are already in the risk window they are trying to avoid.

QSECDEF's membership community includes security practitioners and consultants with direct experience in CNI PQC migration across energy, finance, and health. Individual and company membership provides access to practitioner-level methodology documentation and the member network working on these questions across sectors.


Steven Vaile — Director, Quantum Security Defence

View on LinkedIn | View Team | QSecDef Events