PQC Impacts: Cryptographic Risk in Embedded and OT Estates
Quantum risk in embedded and operational technology
Embedded and operational technology estates carry the highest migration difficulty in any post-quantum programme. Devices installed today will still be running after every published deadline, many cannot be updated in the field, and some hold verification keys fixed in silicon at manufacture. Replacement, not migration, is often the only route.
Why embedded and OT estates are the hardest part of the migration
The exposure profile differs from IT. Most operational data is short-lived, so harvest now, decrypt later carries limited weight. The dominant risk is authentication and integrity: forged firmware, spoofed device identity, unauthorised commands and compromised remote access.
The difficulty is structural rather than cryptographic. Controllers, meters, sensors, signalling equipment, medical devices and industrial systems have service lives of fifteen to forty years. A device commissioned in 2026 with a twenty-five year life will still be in service in 2051, sixteen years past the NCSC completion deadline of 2035. Anything procured now without post-quantum capability is committing the organisation to a problem it will still hold in the 2040s.
Compounding this, the operator frequently cannot change the device at all. Firmware is controlled by the manufacturer, modification voids certification, and in regulated environments any change triggers revalidation or a safety case amendment.
What makes quantum resistant encryption difficult on constrained devices
Memory and compute
Post-quantum keys and signatures are one to three orders of magnitude larger than their classical equivalents. An ML-DSA-65 signature is 3,309 bytes against 64 for ECDSA P-256, and an ML-KEM-768 encapsulation key is 1,184 bytes against 32 for X25519.
On a microcontroller with 64 kilobytes of RAM and a few hundred kilobytes of flash, holding a certificate chain of that size alongside the application is frequently not possible. Library code size is a second constraint, and many embedded parts have hardware acceleration for RSA and elliptic curve operations but none for lattice arithmetic, so the performance advantage post-quantum algorithms show on general purpose processors does not transfer.
Bandwidth and protocol limits
Constrained networks impose hard message limits. A LoRaWAN payload is typically a few hundred bytes at most, narrowband cellular links are similarly restricted, and industrial serial protocols were designed without cryptographic payloads in mind at all. A certificate chain that no longer fits inside a single message forces fragmentation, which many embedded stacks handle poorly or not at all.
Power
Battery-powered devices are specified for years of unattended operation. Additional computation and larger transmissions both draw power, and on a device engineered for a ten year battery life a change in cryptographic workload can materially shorten it.
Immutable roots of trust and secure boot
The hardest single problem is the fixed verification key. Secure boot works by having an immutable bootloader verify firmware against a public key held in read-only memory or one-time-programmable fuses. That key is written at manufacture and, by design, cannot be changed.
If that key is RSA or ECDSA, the device's entire chain of trust is quantum-vulnerable for its remaining service life, and there is no field remediation. Once the corresponding private key can be derived, an adversary can sign firmware the device will accept as genuine.
This is why identifying immutable roots of trust is an early priority rather than a late one. It is also why the NCSC guidance explicitly calls out the requirement to migrate long-lived hardware roots of trust during the discovery phase. Devices in this category require replacement, and replacement requires capital planning, procurement lead time and, in regulated environments, requalification.
The update mechanism problem
A second circular dependency sits behind the first. Pushing a post-quantum capable firmware image requires an update mechanism, and that mechanism verifies the image using the algorithm already in place.
Where the update path is itself protected by a quantum-vulnerable signature, an adversary with the capability can sign an arbitrary image. The update channel becomes a remote code execution route rather than a remediation route. Where the device has no field update capability at all, which remains common in industrial and medical estates, there is no route regardless.
The practical instruction is to inventory update capability separately from device identity. Devices divide into three groups: those with an agile, updatable trust anchor, those updatable only under the current algorithm, and those not updatable at all. Only the first group can be migrated in place.
Which quantum resistant encryption algorithms suit embedded devices
Selection on constrained hardware is driven by whether the device signs or only verifies, and by available memory.

LMS and XMSS, approved in NIST SP 800-208, are the practical answer for secure boot. Verification requires only hash computation, which is cheap and frequently accelerated in hardware already, and the schemes have been supported in secure elements and hardware security modules for several years. Their stateful nature is a constraint on the signing side, in the manufacturer's or operator's signing infrastructure, not on the device, which only verifies.
Change control, safety cases and revalidation
The cryptographic work is rarely the long pole. In regulated environments, the approval process is.
In nuclear, modifications to systems important to safety require safety case amendment and regulatory engagement, and deployment must be planned into outage windows scheduled years ahead. In rail, changes to signalling and control systems require safety approval and testing against operational scenarios. In healthcare, firmware changes to medical devices may require manufacturer revalidation and, depending on the change, regulatory notification. In aviation and defence, accreditation and certification regimes impose comparable constraints.
The consequence is that OT migration must enter the planning cycle well before the intended change, and that decisions about which assets to migrate, which to replace and which to compensate for must be made early, when they can still influence capital plans.
Practical approaches where devices cannot be migrated
Where in-place migration is impossible, the objective shifts from protecting the device to protecting the path to it.
Terminating post-quantum protected sessions at a gateway in front of legacy devices is the most common pattern. The link across the collectible network is protected with quantum resistant encryption, while the legacy segment behind the gateway continues to operate as before. This is the architectural wrapper approach applied to operational estates.
Network segmentation reduces the reachable surface, so that a device whose identity cannot be trusted is not exposed to networks where forged authentication would be useful. Symmetric keying is viable in some closed environments, since pre-shared symmetric keys with AES-256 are not quantum-vulnerable, though key distribution and rotation then become the operational burden.
Monitoring and detection provide partial compensation where prevention is impossible: firmware attestation, configuration baselines and command anomaly detection do not stop a forged signature but can make its use visible.
None of these is equivalent to migration, and each should be recorded as a compensating control with an owner and a replacement date rather than as a solution.
Specifying quantum resistant encryption in procurement
Procurement is where most of the achievable risk reduction now sits, because every device bought without post-quantum capability extends the problem by its full service life.
Requirements worth specifying include a field-updatable root of trust rather than a fixed verification key, support for LMS, XMSS or another approved post-quantum scheme in the secure boot chain, an update mechanism whose trust anchor can itself be replaced, a supplier commitment to publish a cryptographic bill of materials for the device, and a stated post-quantum roadmap with dates.
These conditions are more effective applied at tender than negotiated later, and they cost little at the point of purchase compared with early replacement of an estate that cannot be upgraded.
How Unsung helps
Unsung is a UK-based, vendor-neutral consultancy specialising exclusively in public key infrastructure and cryptographic systems, working across defence, nuclear, transport, healthcare and critical national infrastructure.
We identify device identity, secure boot and root of trust dependencies across operational estates through our PKI health check and cryptographic bill of materials services, separating assets that can be migrated in place from those requiring replacement or compensating controls. We design the signing infrastructure and hardware security module configuration needed to support stateful hash-based signing, and support procurement teams in specifying post-quantum requirements at tender.
For sector context, see how post-quantum risk exposure varies by sector.
Frequently asked questions
Can existing OT devices be upgraded to quantum resistant encryption?
Which post-quantum algorithm is best for secure boot?
Is operational technology at risk from harvest now, decrypt later?
What should we do about devices that cannot be migrated?
How far ahead should OT migration be planned?
What should we require from suppliers now?


