Keyfactor Tech Days 2027, The Trust Security Conference, is heading to San Diego!   Discover what’s coming up

Post-Quantum Readiness: The Timeline Is Now Written Down

Compliance

Post-quantum readiness for financial services has crossed a line. It used to be a theoretical concern that security teams could file under “someday.” It is now a scheduled obligation with dates attached.

Every cryptographic compliance framework a financial institution answers to points in the same direction: know what cryptography you have, prove you control it, and be ready to change it. Post-quantum cryptography is where that direction finally gets a deadline.

This article lays out the timeline that turned guidance into policy, explains why the dates are closer than they look for finance specifically, clarifies who is in scope, and maps the work into concrete cryptographic controls you can start on now.

Why the deadline is real: the timeline in writing

The case for acting now does not rest on speculation about when a cryptographically relevant quantum computer arrives. It rests on milestones that are already published.

NIST standards and the 2030 / 2035 schedule

In 2024, NIST finalized the first three post-quantum cryptographic standards and published draft a transition timeline in NIST IR 8547. That timeline in the draft deprecates the RSA and elliptic curve algorithms underpinning most financial infrastructure by 2030, with full disallowance targeted for 2035. The direction of travel is fixed: the algorithms most banking and payment systems rely on today have an expiration date.

Executive Order 14412 and OMB M-26-15

In June 2026, Executive Order 14412 converted NIST’s technical guidance into federal policy. It directed the Office of Management and Budget (OMB) and the National Cyber Director to lead an accelerated national migration, with phased deadlines for federal high-value assets. OMB Memorandum M-26-15 governs execution of that migration. The order requires all federal high value assets and high impact systems to use PQC for key establishment by December 31, 2030, and for digital signatures by December 31, 2031. OMB Memorandum M-26-15, issued June 24, 2026, sets a five phase schedule running to 2035 for remaining systems.

The G7 coordinated roadmap

In January 2026, the G7 Cyber Expert Group, co-chaired by the U.S. Treasury and the Bank of England, published a coordinated, sector-specific roadmap. It urges banks, insurers, exchanges, and financial market infrastructures to move from awareness to inventory, risk assessment, and phased migration well ahead of the mid-2030s planning horizon. For the financial sector, this is the clearest signal yet that authorities treat cryptographic transition as a systemic risk management issue rather than a future concern.

Swift sets a target

Swift plans to release SwiftNet 8.0, its post-quantum-cryptography-enabled network, at the end of July 2027. It is a mandatory major release with no upgrade path from release 7.7, and support for release 7.9 ends 15 months after 8.0 becomes available. That defines a migration window measured in months, not years, for more than 11,500 institutions connected to the network.

Treasury’s Financial Sector Quantum-Readiness Task Force

On August 24, 2026, the U.S. Treasury launched the Quantum-Readiness Task Force, a public-private initiative to accelerate the American financial sector’s transition to quantum-safe technology. It follows Executive Order 14412 and builds on the G7 Cyber Expert Group roadmap. The Task Force operates through three workstreams: Sector Alignment and PQC Transition; Third-Party and Vendor Readiness; and Digital Assets and Emerging Technology Risk.

Why it matters for financial institutions

An executive order and a G7 roadmap are not conformance standards, and no institution will be audited against either one directly. Their significance is what they signal: the cryptographic inventory, certificate management, and crypto-agility expectations already embedded in DORA, PCI DSS, and NYDFS now have dates attached.

Harvest now, decrypt later

Transaction histories, custody records, and long-retained KYC and AML data encrypted today can be captured now and decrypted once quantum capability arrives. The real deadline is therefore set by the sensitivity horizon of the data, not by the delivery date of a quantum computer. In finance, where records must stay confidential for years or decades, the exposure window has effectively already opened.

The readiness gap and weakest-link risk

Recent industry surveys have found that only a small percentage of global financial institutions have begun substantive migration. Larger Tier 1 banks lead on evaluation while smaller institutions lag, creating exactly the weakest-link risk that a correspondent-banking network cannot quietly absorb. One unprepared counterparty becomes everyone’s problem.

Procurement moves faster than regulation

Federal buyers, central banks, and correspondent partners will begin requesting PQC migration plans and cryptographic inventories well before any rule requires them. DORA’s crypto-agility provisions already point every EU financial entity toward the same foundation. The practical trigger for most institutions will be a due-diligence questionnaire, not a statute.

Who is in scope

If you recognize your institution in any of the categories below, post-quantum readiness is already your concern.

  • Banks and payment providers with federal or cross-border exposure, including institutions tied that will be captured by the FAR rule directed under Executive Order 14412.
  • SWIFT-connected and correspondent institutions facing the SwiftNet PQC-enabled release and its migration window.
  • Any institution holding long-lived financial data, such as transaction records, custody data, and KYC and AML records whose confidentiality must outlast today’s algorithms.

That reach extends further still: EU entities subject to DORA, federal contractors that will be captured by the forthcoming FAR rule requiring covered contractors to comply with NIST’s FIPS, including those incorporating standardized PQC algorithms, by the end of 2030, and institutions supervised by authorities that have set their own dates.

How post-quantum readiness maps to cryptographic controls

The timeline becomes real work across a set of interlocking control areas. Each one is a discrete capability you can stand up now.

Cryptographic inventory and CBOM readiness

Discover and inventory certificates, keys, algorithms, and embedded cryptographic libraries across core banking, payments, and open banking. That asset-level visibility is what a cryptographic bill of materials (CBOM) requires, and it aligns with Executive Order 14412 and forthcoming CISA CBOM guidance. It also supports PCI DSS Requirement 12.3.3, which calls for a maintained inventory of cryptographic cipher suites and protocols.

Quantum vulnerability assessment

Analyze discovered cryptography against approved and deprecated algorithm lists, following the NIST IR 8547 deprecation schedule. Prioritize findings by data sensitivity and retention period so the highest-risk, longest-lived assets move first.

PQC-capable certificate issuance

Issue and manage certificates using NIST-standardized PQC algorithms, including hybrid certificates that support staged migration across long-lived banking and payment infrastructure. This work maps to Executive Order 14412 and OMB M-26-15.

Cryptographic agility at estate scale

Rotate, reissue, and re-key certificates across core banking, card, and correspondent-banking infrastructure at fleet scale, without manual per-endpoint intervention. This capability reflects the G7 Cyber Expert Group roadmap and DORA RTS Articles 6 to 7.

PQC-ready messaging infrastructure

Prepare certificate and key infrastructure ahead of SwiftNet’s PQC-enabled release and the migration window that follows. Given the short window Swift has signaled, the institutions that pre-stage this infrastructure will migrate calmly rather than scrambling.

PQC-ready code and firmware signing

Sign payment applications, ATM and POS firmware, and core banking releases with quantum-resistant algorithms, so update pipelines stay trustworthy across their full support period. This aligns with Executive Order 14412’s procurement provisions and PCI DSS Requirement 12.3.3.

Readiness questions to ask now

These are the questions assessors, federal customers, and correspondents will probe. If you can answer each one with evidence, you are ahead of the curve.

  • Is your cryptographic inventory complete?
    Can you enumerate every certificate, key, algorithm, and cryptographic library across core banking, payments, and open banking, including inherited dependencies?
  • Have you classified quantum vulnerability?
    Has the inventory been assessed against the NIST deprecation schedule, with quantum-vulnerable assets ranked by data sensitivity and retention period?
  • Do you have a migration plan and an owner?
    Is there a named owner, a documented plan, and a timeline aligned to the 2030 deprecation and 2035 disallowance dates?
  • What is your long-lived data and custody strategy?
    For transaction, custody, and KYC and AML data that must stay confidential past current algorithm lifespans, are compensating controls or migration timelines documented?
  • Can you produce a CBOM today?
    If a federal customer or correspondent bank requested a cryptographic bill of materials right now, could you generate one?
  • Do you know your vendors’ PQC posture?
    Are SWIFT counterparties, card networks, and core banking or cloud vendors being assessed for their own migration plans, given that inherited cryptography becomes your exposure?

How Keyfactor can help

Post-quantum readiness is an operating capability, not a one-time project. The Keyfactor Trust Control Plane observes, analyzes, provisions, orchestrates, and governs every cryptographic asset and machine identity across core banking, payments, and open banking. The result is a single system of record from which the evidence any framework asks for can be drawn.

The supporting products surfaced in the control mapping work together across the migration:

  • Command and AgileSec for discovery, inventory, and quantum vulnerability assessment.
  • EJBCA for PQC-capable and hybrid certificate issuance.
  • SignServer and Signum for quantum-resistant code and firmware signing.

Instead of assembling evidence framework by framework, institutions get one platform that answers the cryptographic questions all of them ask.

A program, not a project

The frameworks differ in jurisdiction, scope, and enforcement, but they ask for the same underlying capability. Observe what cryptographic assets exist across the enterprise, the payment network, and every counterparty you connect to. Analyze them against current requirements and deprecation schedules. Provision trusted identities to every system, application, and workload. Orchestrate certificate and key lifecycles at institutional scale. Govern the whole estate with policy, evidence, and accountability an examiner can test.

That is not a compliance project with an end date. It is an operating capability, and the institutions that treat it that way will find that each new requirement lands on infrastructure that already answers it. The practical first steps are the same regardless of which dates apply to you: begin cryptographic inventory and quantum vulnerability assessment now, ahead of the 2030 and 2035 milestones.

Ready to see what that looks like across your estate? Request a Demo.

Got post-quantum readiness questions? We’ve got answers.

What is post-quantum readiness for financial services?
Post-quantum readiness is an institution’s ability to migrate its cryptographic systems to quantum-resistant algorithms without disruption. It combines complete visibility into cryptographic assets, a prioritized view of quantum vulnerability, and the automation to re-key and reissue certificates at estate scale.

When do financial institutions need to migrate to post-quantum cryptography?
 Draft NIST IR 8547 deprecates RSA and elliptic curve algorithms after 2030 and disallows them after 2035. Executive Order 14412 sets firmer dates for federal high value assets and high impact systems: PQC for key establishment by December 31, 2030, and for digital signatures by December 31, 2031. Sooner still, Swift plans to release its PQC-enabled SwiftNet 8.0 at the end of July 2027, giving connected institutions a migration window measured in months.

What is “harvest now, decrypt later” and why does it matter for banks?
Harvest now, decrypt later is the practice of capturing encrypted data today and decrypting it once quantum capability arrives. It matters for finance because transaction histories, custody records, and KYC and AML data must stay confidential for years, so their sensitivity horizon sets the real deadline rather than the arrival of a quantum computer.

Which institutions are in scope for post-quantum readiness?
In scope are banks and payment providers with federal or cross-border exposure, SWIFT-connected and correspondent institutions, and any institution holding long-lived financial data. It also reaches EU entities subject to DORA and federal contractors captured by the forthcoming FAR rule requiring PQC-aligned standards by the end of 2030.

What is a cryptographic bill of materials (CBOM)?
A CBOM is an asset-level inventory of the certificates, keys, algorithms, and cryptographic libraries in use across an environment. Executive Order 14412 directs CISA, in coordination with NIST, to publish the minimum elements for a CBOM, with elements that enable automated assessment of an asset’s cryptography. A CBOM also supports PCI DSS Requirement 12.3.3, which asks for an inventory of cipher suites and protocols in use, monitoring of their continued viability, and a documented plan to respond when one stops being viable.

How does Executive Order 14412 affect financial institutions?
Executive Order 14412, issued in June 2026, converted NIST’s guidance into federal policy and directed an accelerated national migration with phased deadlines for federal high-value assets. It reaches private industry through a forthcoming FAR rule requiring covered federal contractors to meet PQC-aligned standards by the end of 2030.

What is the Treasury Quantum-Readiness Task Force?
Launched by the U.S. Treasury on August 24, 2026, it is a public-private initiative to accelerate the financial sector’s transition to quantum-safe technology, building on the G7 Cyber Expert Group roadmap. It operates through three workstreams: Sector Alignment and PQC Transition, Third-Party and Vendor Readiness, and Digital Assets and Emerging Technology Risk.

How can Keyfactor help with post-quantum migration?
The Keyfactor Trust Control Plane observes, analyzes, provisions, orchestrates, and governs every cryptographic asset and machine identity across core banking, payments, and open banking. Command and AgileSec handle discovery and vulnerability assessment, EJBCA issues PQC-capable and hybrid certificates, and SignServer and Signum provide quantum-resistant code and firmware signing.