Blog

Local Government Quantum Readiness

Councils hold some of the longest-retention records in the public sector. Practical post quantum cyber security steps for authorities without a PKI team.

Post-quantum readiness for local authority services

Local authorities hold records with some of the longest statutory retention periods in the public sector, and most have no dedicated PKI capability. The realistic position is that migration arrives mainly through suppliers, which makes inventory, procurement specification and supplier pressure the council's own workstream.

Why retention periods put councils in the high exposure group

Exposure follows how long data must remain confidential, and local government holds records measured in decades.

Children's social care records, particularly for looked-after children, are retained for up to 75 years from date of birth. Adoption records are retained for 100 years. Planning permissions and building control records are retained permanently, as are land charges. Electoral registration, council tax, housing and licensing records all carry multi-year or indefinite retention.

Any of that material transmitted today under classical key exchange is exposed to harvest now, decrypt later collection. The council may not be a priority intelligence target, but the material has a confidentiality lifetime that outlasts every published migration deadline, and the regulatory obligation for it stays with the authority.

Alongside this, councils issue and rely on credentials for citizen-facing services, and increasingly operate connected assets: CCTV, traffic management, building systems, waste fleet telematics and social alarm systems, several of which have long service lives and constrained update paths.

The constraints that make local government different

Most authorities have no PKI specialist. Certificate management is typically handled within a small infrastructure team alongside everything else, and the entire internal PKI is often a single Active Directory Certificate Services instance that has been running for years without review.

Core systems are supplier-delivered. Revenues and benefits, social care case management, planning, housing and finance are usually commercial applications, frequently hosted by the supplier. The authority's cryptographic position on those systems is the supplier's cryptographic position.

Infrastructure is frequently outsourced or shared. Managed service providers, shared service arrangements between authorities, and regional partnerships mean the party who would perform discovery is often not the council itself.

Budget cycles are annual and contested, and there is no binding UK deadline forcing prioritisation. Post-quantum migration competes against statutory service pressures, which it will lose if presented as a technology programme.

What a council can realistically do

Three things sit within the authority's control, and they are the ones worth resourcing.

Establish what cryptography exists

Discovery does not require a specialist team to begin. Existing endpoint management, network monitoring and asset management tooling will enumerate certificates and TLS configurations across the corporate estate. Where an AD CS instance is in use, its issued certificate list is a starting inventory. Where a managed service provider runs the infrastructure, the discovery obligation should be raised with them under existing contract governance.

The output should be a dated inventory with stated coverage, not a claim of completeness. This is also the artefact that satisfies audit and the Cyber Assessment Framework expectations for local government, so it earns its cost outside the quantum argument.

Put cryptographic requirements into procurement

This is the highest-leverage action available and it costs nothing. Adding algorithm disclosure, a dated post-quantum roadmap, subprocessor disclosure and notice periods for cryptographic change to the standard specification means every subsequent procurement carries them.

Councils have more leverage here collectively than individually. Requirements written into national frameworks, regional purchasing consortia and shared service contracts apply across many authorities at once, and suppliers respond to framework requirements in a way they do not respond to individual authority questionnaires.

Ask suppliers the assessable questions at renewal

General questions produce general answers. The questions that produce evidence are which algorithms protect council data in transit and at rest today, in which product version, whether post-quantum key agreement is enabled by default, what the dated roadmap is for key establishment and signatures, and which subprocessors are involved. These belong in contract renewal discussions rather than in a separate exercise.

Where the exposure concentrates

The AD CS question

For many authorities the internal certificate authority is a single AD CS deployment, frequently configured a decade ago and rarely reviewed. Two things follow.

Microsoft added ML-DSA support to AD CS on Windows Server 2025 through the May 2026 security update, but there is no in-place migration. A parallel hierarchy must be stood up alongside the existing one and endpoints moved across.

Because that is the same exercise as a platform migration, it is a reasonable point to assess whether AD CS remains the right issuing platform for the authority, particularly where the current instance has accumulated configuration debt. Our note on Active Directory Certificate Services in modern IT covers the considerations.

How to fund it

Post-quantum migration is unlikely to be funded as a standalone programme in local government, and it does not need to be.

Discovery can be justified on its own merits: it supports audit, the Cyber Assessment Framework, incident response and prevention of certificate-related service outages, all of which are current concerns. Procurement specification changes cost nothing and should not require a business case. Supplier engagement runs within existing contract management. The remaining direct cost, principally any internal PKI work, is small and can generally be aligned to a planned infrastructure refresh, as set out in funding post-quantum migration through refresh cycles.

How Unsung helps

Unsung is a UK-based, vendor-neutral consultancy specialising exclusively in public key infrastructure and cryptographic systems, working across central government, healthcare, defence and critical national infrastructure.

We deliver bounded discovery engagements suited to organisations without a PKI team, producing a dated inventory with stated coverage through our PKI health check and cryptographic bill of materials services. Where an authority's internal PKI needs remediation or replacement, our PKI design and build practice covers it, and we support procurement teams in writing cryptographic requirements into specifications and frameworks.

For sector comparison, see how post-quantum risk exposure varies by sector.

Frequently asked questions

Are local authorities really at risk from quantum computing?

Yes, principally through data retention. Children's social care records are retained for up to 75 years and adoption records for 100, with planning and land charges retained permanently. Material with that confidentiality lifetime transmitted today under classical key exchange is exposed to future decryption, and the obligation remains with the authority.

We have no PKI team. Where do we start?

With discovery, using tooling already deployed. Endpoint management, network monitoring and asset management platforms will enumerate certificates and TLS configurations, and an existing AD CS instance provides an issued certificate list. The output should state its coverage honestly rather than claim completeness.

Most of our systems are supplier-hosted. Is this our problem?

The regulatory obligation for the data remains with the authority regardless of who processes it. The practical response is to raise assessable questions at contract renewal and to place cryptographic requirements into procurement specifications, since the supplier's roadmap determines when those systems can migrate.

How can a single council influence suppliers?

Individually, not much. Collectively, considerably. Requirements written into national frameworks, regional purchasing consortia and shared service contracts apply across many authorities simultaneously, and suppliers respond to framework requirements far more readily than to individual questionnaires.

Does our AD CS instance need replacing?

It needs assessing. ML-DSA support in AD CS on Windows Server 2025 offers no in-place migration, so a parallel hierarchy is required regardless of platform choice. Since that is equivalent to a migration exercise, it is a sensible point to review whether AD CS remains appropriate for the authority.

How do we fund this against statutory service pressures?

Largely by not requesting a dedicated programme. Discovery is justifiable on audit, Cyber Assessment Framework and outage prevention grounds. Procurement specification changes cost nothing. Supplier engagement sits within existing contract management. Only internal PKI work needs direct funding, and it can usually align to a planned refresh.
Author
Unsung Ltd
September 18, 2026
-