Post-quantum cryptography becomes mandatory for financial institutions

1 week ago 21

The cryptographic foundations underpinning the global financial system are about to get a forced upgrade. A coordinated push from regulators across the G7, the US federal government, and Switzerland is turning post-quantum cryptography from a theoretical concern into a compliance deadline with real teeth.

The regulatory squeeze

The G7 Cyber Expert Group published a roadmap in January 2026 laying out a phased migration plan for the financial sector. The timeline breaks into three stages: planning from 2025 to 2027, risk assessments through 2029, and full execution of the migration by 2034.

The US moved faster and harder. Executive Order 14412, issued on June 22, 2026, mandates that federal agencies migrate to NIST post-quantum cryptography standards. The deadlines are specific: key establishment algorithms must be in place by December 31, 2030, and digital signature algorithms by December 31, 2031.

Switzerland’s financial regulator, FINMA, added its own layer with Guidance 05/2026, published in July 2026. It requires all supervised institutions to have board-approved PQC strategies in place by mid-2027.

Then in August 2026, the US Treasury established a Quantum-Readiness Task Force specifically designed to coordinate the transition across the financial sector, with particular attention to third-party vendor risk and emerging digital assets.

The technical groundwork was laid earlier. NIST finalized its core PQC standards, designated FIPS 203, 204, and 205, back in August 2024. These standards are built on algorithms like ML-KEM (for key encapsulation) and ML-DSA (for digital signatures), which were selected after years of evaluation as quantum-resistant replacements for current cryptographic methods.

The readiness gap

According to a Swiss survey, fewer than 8% of institutions currently have a formal PQC roadmap in place.

The challenge is compounded by the “harvest now, decrypt later” threat model. Adversaries can intercept encrypted data today, store it, and decrypt it once quantum computers become capable. For financial data with long sensitivity windows, like customer records, trade secrets, or national security-adjacent transactions, the threat isn’t theoretical. It’s already in progress.

What this means for crypto

The regulatory frameworks published so far are conspicuously silent on cryptocurrencies and tokens. The G7 roadmap, the US executive order, and FINMA’s guidance all focus on traditional financial infrastructure. None of them explicitly address the cryptographic vulnerabilities embedded in blockchain networks.

Most major blockchain protocols, including Bitcoin and Ethereum, rely on elliptic curve cryptography (ECC) for transaction signing and wallet security. ECC is precisely the type of cryptography that quantum computers are expected to break. A sufficiently powerful quantum computer running Shor’s algorithm could theoretically derive private keys from public keys, putting any on-chain assets at risk.

The US Treasury’s Quantum-Readiness Task Force does reference “emerging digital assets” in its scope, which suggests some awareness of the issue.

Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.

Read Entire Article