Local Government Quantum Readiness
Post-quantum readiness for local authority services
Local authorities hold records with some of the longest statutory retention periods in the public sector, and most have no dedicated PKI capability. The realistic position is that migration arrives mainly through suppliers, which makes inventory, procurement specification and supplier pressure the council's own workstream.
Why retention periods put councils in the high exposure group
Exposure follows how long data must remain confidential, and local government holds records measured in decades.
Children's social care records, particularly for looked-after children, are retained for up to 75 years from date of birth. Adoption records are retained for 100 years. Planning permissions and building control records are retained permanently, as are land charges. Electoral registration, council tax, housing and licensing records all carry multi-year or indefinite retention.
Any of that material transmitted today under classical key exchange is exposed to harvest now, decrypt later collection. The council may not be a priority intelligence target, but the material has a confidentiality lifetime that outlasts every published migration deadline, and the regulatory obligation for it stays with the authority.
Alongside this, councils issue and rely on credentials for citizen-facing services, and increasingly operate connected assets: CCTV, traffic management, building systems, waste fleet telematics and social alarm systems, several of which have long service lives and constrained update paths.
The constraints that make local government different
Most authorities have no PKI specialist. Certificate management is typically handled within a small infrastructure team alongside everything else, and the entire internal PKI is often a single Active Directory Certificate Services instance that has been running for years without review.
Core systems are supplier-delivered. Revenues and benefits, social care case management, planning, housing and finance are usually commercial applications, frequently hosted by the supplier. The authority's cryptographic position on those systems is the supplier's cryptographic position.
Infrastructure is frequently outsourced or shared. Managed service providers, shared service arrangements between authorities, and regional partnerships mean the party who would perform discovery is often not the council itself.
Budget cycles are annual and contested, and there is no binding UK deadline forcing prioritisation. Post-quantum migration competes against statutory service pressures, which it will lose if presented as a technology programme.
What a council can realistically do
Three things sit within the authority's control, and they are the ones worth resourcing.
Establish what cryptography exists
Discovery does not require a specialist team to begin. Existing endpoint management, network monitoring and asset management tooling will enumerate certificates and TLS configurations across the corporate estate. Where an AD CS instance is in use, its issued certificate list is a starting inventory. Where a managed service provider runs the infrastructure, the discovery obligation should be raised with them under existing contract governance.
The output should be a dated inventory with stated coverage, not a claim of completeness. This is also the artefact that satisfies audit and the Cyber Assessment Framework expectations for local government, so it earns its cost outside the quantum argument.
Put cryptographic requirements into procurement
This is the highest-leverage action available and it costs nothing. Adding algorithm disclosure, a dated post-quantum roadmap, subprocessor disclosure and notice periods for cryptographic change to the standard specification means every subsequent procurement carries them.
Councils have more leverage here collectively than individually. Requirements written into national frameworks, regional purchasing consortia and shared service contracts apply across many authorities at once, and suppliers respond to framework requirements in a way they do not respond to individual authority questionnaires.
Ask suppliers the assessable questions at renewal
General questions produce general answers. The questions that produce evidence are which algorithms protect council data in transit and at rest today, in which product version, whether post-quantum key agreement is enabled by default, what the dated roadmap is for key establishment and signatures, and which subprocessors are involved. These belong in contract renewal discussions rather than in a separate exercise.
Where the exposure concentrates

The AD CS question
For many authorities the internal certificate authority is a single AD CS deployment, frequently configured a decade ago and rarely reviewed. Two things follow.
Microsoft added ML-DSA support to AD CS on Windows Server 2025 through the May 2026 security update, but there is no in-place migration. A parallel hierarchy must be stood up alongside the existing one and endpoints moved across.
Because that is the same exercise as a platform migration, it is a reasonable point to assess whether AD CS remains the right issuing platform for the authority, particularly where the current instance has accumulated configuration debt. Our note on Active Directory Certificate Services in modern IT covers the considerations.
How to fund it
Post-quantum migration is unlikely to be funded as a standalone programme in local government, and it does not need to be.
Discovery can be justified on its own merits: it supports audit, the Cyber Assessment Framework, incident response and prevention of certificate-related service outages, all of which are current concerns. Procurement specification changes cost nothing and should not require a business case. Supplier engagement runs within existing contract management. The remaining direct cost, principally any internal PKI work, is small and can generally be aligned to a planned infrastructure refresh, as set out in funding post-quantum migration through refresh cycles.
How Unsung helps
Unsung is a UK-based, vendor-neutral consultancy specialising exclusively in public key infrastructure and cryptographic systems, working across central government, healthcare, defence and critical national infrastructure.
We deliver bounded discovery engagements suited to organisations without a PKI team, producing a dated inventory with stated coverage through our PKI health check and cryptographic bill of materials services. Where an authority's internal PKI needs remediation or replacement, our PKI design and build practice covers it, and we support procurement teams in writing cryptographic requirements into specifications and frameworks.
For sector comparison, see how post-quantum risk exposure varies by sector.
Frequently asked questions
Are local authorities really at risk from quantum computing?
We have no PKI team. Where do we start?
Most of our systems are supplier-hosted. Is this our problem?
How can a single council influence suppliers?
Does our AD CS instance need replacing?
How do we fund this against statutory service pressures?


