Skip to content

Post-Quantum Migration Readiness in UK Public-Sector Systems

Cryptographic modernisation across public infrastructure demands an integrated approach combining governance oversight, technical crypto-agility, and procurement alignment to mitigate quantum decryption vulnerabilities. Evaluating national readiness directives alongside administrative system constraints establishes structured migration pathways for securing citizen data and public services against emerging threat horizons.

Goal of work

Evaluate the strategic, technical, and governance readiness of UK public-sector systems for transitioning to post-quantum cryptographic standards.

Methodology

Comparative documentary analysis of UK policy frameworks, international standards, and maturity models evaluating governance and technical agility.

Scientific novelty

Extends public cyber-governance by establishing a multi-dimensional readiness model addressing public-sector legacy systems and statutory retention.

Document Preview

Review the formatting and introduction. The full version will refine the structure for the selected document standard.

PhD Thesis

Degree:
Post-Quantum Migration Readiness in UK Public-Sector Systems

Author:

Group

First M. Last

Advisor:

Dr. First Last

City, 2026

Contents

Declaration of Originality
Abstract
Introduction
Chapter 1. Theoretical Foundations of Cryptographic Migration in Public Infrastructure
1.1 Quantum Computing Mechanics and Asymmetric Vulnerabilities
1.2 The Threat Horizon of Retroactive Decryption Models
1.3 Standards Evolution and Post-Quantum Cryptographic Primitives
1.4 Organisational Readiness Models in Digital Government Systems
Chapter 2. Methodological Architecture for Public-Sector Cryptographic Evaluation
2.1 Comparative Policy and Standardisation Document Corpus Selection
2.2 Analytical Criteria for Cryptographic Inventory and Dependency Mapping
2.3 Evaluating Maturity Metrics across Public Administrative Layers
2.4 Methodological Boundaries and Public-Sector Data Constraints
Chapter 3. Strategic and Governance Readiness in UK Public Administrative Bodies
3.1 Central Government Cryptographic Governance and National Policy Directives
3.2 Cross-Departmental Coordination and Policy Harmonisation Deficits
3.3 Alignment with National Cyber Security Centre Guidelines
3.4 Maturity Assessment of Central Digital and Data Systems
Chapter 4. Technical Migration Architecture and Interoperability Constraints
4.1 Legacy System Compatibility and Protocol Stack Overhead in Public Networks
4.2 Hybrid Deployment Strategies in Public Cloud and On-Premises Infrastructure
4.3 Public Key Infrastructure Modernisation and Key Material Expansion
4.4 Cryptographic Agility Implementation across Core Administrative Services
Chapter 5. Supply Chain Governance and Public Procurement Challenges
5.1 Third-Party Software Dependencies and Commercial Vendor Alignment
5.2 Public Procurement Frameworks for Quantum-Resilient Technologies
5.3 Cross-Jurisdictional Interoperability and Transnational Data Flows
5.4 Compliance Monitoring and Contractual Assurance Mechanisms
Chapter 6. Strategic Implementation Framework and Policy Recommendations
6.1 Phased Migration Roadmaps for Critical Public Services
6.3 Continuous Auditing, Risk Prioritisation, and Resilience Benchmarks
Appendix
Conclusion
Bibliography

Introduction

The systematic transition to post-quantum cryptography represents a foundational security imperative for public administrative infrastructure. Cryptographically relevant quantum computers threaten the mathematical assumptions underpinning modern public-key standards such as RSA and elliptic curve schemes, leaving critical public records and state communications exposed to retroactive decryption threats [6], [8]. Public-sector institutions bear responsibility for preserving societal data integrity and citizen confidentiality across multi-decade statutory retention horizons, which necessitates immediate preparatory action [1].

Despite the finalisation of international algorithmic standards, public-sector readiness faces significant structural, procedural, and architectural challenges [2], [4]. Traditional public administration systems maintain entrenched legacy software, distributed procurement arrangements, and fragmented governance mechanisms that impede rapid cryptographic updates [3]. Cryptographic migration extends far beyond basic algorithm replacement, requiring systemic crypto-agility, complete dependency inventories, and coordinated cross-departmental oversight to address both forward authentication requirements and historic data exposure risks [5], [7].

This dissertation evaluates post-quantum migration readiness across United Kingdom public-sector systems by establishing a multi-layered analytical framework for governance, technical agility, and procurement integration [4], [5]. Utilising a comparative documentary methodology rooted in national cybersecurity directives, international migration standards, and institutional maturity models, the study determines how public entities can transition securely without operational disruption [2], [7]. The work clarifies the essential governance mechanisms required to future-proof digital state architectures against asymmetric cryptographic vulnerabilities [3], [6].

The resulting insights provide public administrators and policymakers with structured transition pathways, addressing the practical trade-offs between technical system constraints and long-term regulatory compliance [1], [5]. By synthesising technical capability assessments with institutional governance dynamics, the research bridges conceptual quantum-threat paradigms and empirical implementation realities, thereby contributing directly to national cyber resilience frameworks and secure public digital infrastructure management [2], [8].

2.2 Analytical Criteria for Cryptographic Inventory and Dependency Mapping

Evaluating post-quantum migration readiness across public-sector environments necessitates an integrated methodological framework capable of assessing both architectural dependencies and organisational maturity. Classical evaluation paradigms frequently prioritize algorithmic benchmarks while overlooking the institutional interdependencies that govern public administrative networks. To resolve this limitation, this study establishes an analytical matrix synthesizing technical inventory protocols with structural governance dimensions. Methodologically, the evaluation model operationalises readiness assessment across discrete institutional and technical strata. Following the structural principles articulated by readiness framework literature (PQC-ORI, 2026), the assessment criteria incorporate core readiness dimensions comprising governance and policy, cryptographic agility, migration management, technical capability, operational resilience, and cryptographic awareness. These dimensions provide systematic parameters to evaluate public infrastructure beyond simple cipher replacement. Furthermore, the methodological architecture incorporates multi-layer dependency tracking (PGGF, 2026), recognizing that cryptographic algorithm rankings and operational overhead shift across protocol stack layers and hardware platforms. By integrating thematic governance layers with granular dependency mapping across enterprise systems, the research evaluates how cross-jurisdictional compliance, legacy software stacks, and parent-department governance interact during transitional phases. Consequently, the analytical procedure employs a mixed qualitative synthesis to evaluate public-sector documentation, cryptographic asset inventories, and procurement frameworks against standardized maturity levels. This methodological configuration ensures that dependency mapping captures the operational friction inherent in updating asymmetric primitives across federated administrative services. By coupling structured organizational maturity dimensions with protocol-level performance dependencies, the methodological apparatus provides a rigorous basis for quantifying institutional preparedness acro…

References

  1. Global Roadmaps for Post-Quantum Era in Finance: Policies, Timelines, and a Pragmatic Playbook for Migration
    Colin Sokol Kuka, Sanar Muhyaddin, Phoey Lee Teh et al.
    DOI Link
  2. Post-Quantum Cryptography Migration Readiness in Global Capability Centres: A Governance Framework for Enterprise Transition
    Chandrasekar Umapathy
    DOI Link
  3. Post-Quantum Cryptography Readiness: Cybersecurity Strategies for the Quantum Computing Era
    Santosh Kumar Jadala
    DOI Link
  4. Development and Preliminary Validation of PQC-ORI: A Public-Sector Readiness Assessment Instrument for Post-Quantum Cryptography
    Fadlilah Izzatus Sabila, Fauziah
  5. Quantum Readiness in Cryptography: A Maturity-Based Framework for Post-Quantum Transition
    Volkan Erol
  6. The Strategic Imperative of Quantum Readiness: A Comprehensive Review of Post-Quantum Cryptography
    Volkan Erol
  7. Post-quantum readiness and cryptographic transition planning for enterprise cloud
    Ankit Gupta, Shilpi Mittal
  8. Quantum Computing Threats to Modern Cryptography: Readiness Assessment and Post-Quantum Security Framework
    Sakir Alim, Nitin Bodade

Bibliography

Verified SourcesFormatting StandardsHigh UniquenessPro Models
Launch offer: 25% off

Dissertation

Harvard (Cite Them Right)

£21£28
  • 120+ pages
  • High originality drafting
  • Export to Word
  • Correct formatting
  • Public Preview
    A preview by another author cannot be made private. Your work will be private and completely unique.
  • Bibliography (150+, Harvard)
    +£1
  • Add alternative sources (News, .gov, .edu)

Dissertation

Harvard (Cite Them Right)