News
Vodafone and UK cyber agency urge mobile sector to prepare for quantum-safe security
Vodafone and the UK’s National Cyber Security Centre have published recommendations for organisations beginning the long transition to post-quantum cryptography, a change that will eventually affect networks, devices and mobile services.

Vodafone and the UK’s National Cyber Security Centre (NCSC) are urging organisations to start preparing for post-quantum cryptography (PQC), after a government and industry workshop examined how companies can move away from encryption vulnerable to future quantum computers.
The recommendations are aimed at security leaders, technology suppliers and the teams responsible for critical communications infrastructure. Although a cryptographically relevant quantum computer does not exist today, the migration away from current public-key cryptography could take years. Vodafone says it is already identifying vulnerable systems, defining requirements for suppliers and developing a long-term Quantum Safe programme.
The announcement matters to the mobile industry because cryptography is embedded across the communications chain. The NCSC’s guidance covers networking equipment, base stations, applications, mobile devices, servers and connected sensors. For most consumers, the eventual transition should arrive through routine software and firmware updates, but operators and enterprises must prepare well before those updates become necessary.
Why quantum-safe migration is becoming a mobile issue
Today’s public-key cryptography protects activities such as establishing secure connections and verifying digital signatures. These mechanisms support trust across digital communications, from enterprise networks and cloud services to the software that runs on connected devices.
A sufficiently powerful quantum computer could eventually break many of the mathematical problems behind widely used public-key algorithms. The NCSC also warns about a “harvest now, decrypt later” risk: an attacker could collect encrypted information today and attempt to decrypt it in the future. That makes the issue relevant now for data that must remain confidential for many years, including sensitive business, government and infrastructure records.
PQC algorithms are designed to resist attacks from both conventional and quantum computers. However, replacing cryptography is not a simple switch. Algorithms must be integrated into protocols, hardware, certificates, identity systems and software supply chains, while organisations still need to preserve interoperability with systems that have not yet migrated.
What Vodafone and the NCSC learned from the workshop
According to Vodafone’s account of the workshop, the first priority is to make PQC a business-resilience issue rather than a narrowly technical project. The recommendations include:
Give the programme senior ownership by appointing a sponsor who can explain the cost of delay and connect the work to wider cyber-resilience goals.
Map critical systems and identify where cryptography is used, including dependencies on suppliers, networks, applications and long-lived devices.
Engage vendors early and ask whether products are already PQC-ready or can be upgraded during planned refresh cycles.
Create a phased roadmap with clear priorities, investment, skills and milestones.
This emphasis on suppliers is especially important for telecoms. Mobile operators depend on equipment and software from many vendors, and a network’s cryptographic readiness cannot be assessed by looking at a single platform in isolation. A base station, core network component, management system or connected enterprise service may have different upgrade paths and support lifetimes.
A timetable for operators and enterprise users
The NCSC’s published migration timeline gives organisations a practical framework. By 2028, they should define their migration goals, complete a discovery exercise and build an initial plan. By 2031, they should have started the highest-priority migration work and refined the roadmap. The target is to complete migration across systems, services and products by 2035.
Those dates are not a promise that every phone or app will need a manual upgrade on a particular day. The NCSC says commodity IT, including standard operating systems and mobile devices, should generally receive PQC support through normal vendor updates. The harder work falls on organisations running bespoke systems, proprietary communications platforms or equipment with long replacement cycles.
For mobile operators, the practical challenge is therefore visibility. Teams need to know which systems depend on vulnerable public-key algorithms, which devices can receive secure updates, and which suppliers have a credible migration plan. They also need to consider certificate lifetimes, authentication systems and the risk of locking new infrastructure into technology that cannot be upgraded later.
What smartphone users need to do
There is no special consumer setting to enable as a result of this announcement. The NCSC advises users to keep devices and software up to date, which is already the most important step for receiving future security improvements. Users should also be cautious about unsupported phones and applications that no longer receive security updates, because they may not receive the cryptographic changes required during the transition.
The broader message is that quantum-safe security will be built gradually into mobile platforms, applications and networks. Vodafone and the NCSC’s recommendations give operators and technology suppliers a reason to start the inventory and procurement work now, while the NCSC’s milestones provide a measurable path toward a mobile ecosystem that remains trusted after today’s encryption becomes obsolete.