Keyfactor Tech Days 2027 – Be Part of The Trust Security Conference in San Diego Register now!

Post-Quantum Readiness for FinServ:

The timeline is now written down

Updated: August 24, 2026
RegionUnited States reinforced by coordinated international guidance from the G7, the EU, and national financial regulators
ApplicabilityBanks and Payment Providers with Federal or Cross-Border Exposure: institutions engaging with federal counterparties or subject to expectations tied to CNSA 2.0 and adjacent federal cryptographic policy SWIFT-Connected and Correspondent Institutions: the roughly 11,000 SWIFT users worldwide facing SwiftNet’s planned PQC-enabled release and migration window Any Institution Holding Long-Lived Financial Data: transaction records, custody data, and KYC/AML records whose confidentiality must outlast today’s algorithms
Relevant sectionsExecutive Order 14412: Securing the Nation Against Advanced Cryptographic Attacks (June 22, 2026) OMB Memorandum M-26-15: Execution of the Migration to Post-Quantum Cryptography NIST IR 8547: Transition to Post-Quantum Cryptography Standards G7 Cyber Expert Group Roadmap: Advancing a Coordinated Roadmap for the Transition to Post-Quantum Cryptography in the Financial Sector (January 2026)

Overview

Every framework in this guide points in the same direction: know what cryptography you have, prove you control it, and be ready to change it. Post-quantum cryptography is where that direction gets a deadline.

In 2024, NIST finalized the first three post-quantum cryptographic standards and published a transition timeline that deprecates the RSA and elliptic curve algorithms underpinning most financial infrastructure by 2030, with full disallowance targeted for 2035. In June 2026, Executive Order 14412 converted that technical guidance into federal policy, directing OMB and the National Cyber Director to lead an accelerated national migration and setting phased deadlines for federal high-value assets. In January 2026, the G7 Cyber Expert Group, co-chaired by the U.S. Treasury and the Bank of England, published a coordinated, sector-specific roadmap urging banks, insurers, exchanges, and financial market infrastructures to move from awareness to inventory, risk assessment, and phased migration well ahead of the mid-2030s planning horizon.

For financial institutions, two threads matter most. First, the same executive order directs the FAR Council to require covered federal contractors to meet PQC-aligned cybersecurity standards by the end of 2030, extending the migration obligation into any institution that sells services into federal supply chains. Second, SWIFT itself has signaled a target date: SwiftNet is expected to become PQC-enabled around 2027, with a migration window measured in months rather than years for the roughly 11,000 institutions connected to the network.

Why it matters 

An executive order and a G7 roadmap are not conformance standards, and financial institutions will not be audited against either one directly. Their significance is what they signal: the questions this guide has raised in every chapter, DORA’s crypto-agility expectations, PCI DSS’s cryptographic inventory requirement, NYDFS’s certificate and key inventory, now have dates attached.

The economics of finance make those dates closer than they look. Transaction histories, custody records, and long-retained KYC/AML data encrypted today can be harvested now and decrypted once quantum capability arrives, which means the sensitivity horizon of the data, not the delivery date of a quantum computer, sets the real deadline. Recent industry surveys have found that fewer than 3% of global financial institutions have begun substantive migration, even as SWIFT’s own readiness assessment found the large majority of Tier 1 banks have started evaluation, while smaller institutions lag, creating exactly the weakest-link risk a correspondent-banking network cannot absorb quietly.

Procurement and counterparty due diligence will move faster than regulation. Federal buyers, central banks, and correspondent partners will begin asking for PQC migration plans and cryptographic inventories well before any rule requires them to, and DORA’s own crypto-agility provisions already point every EU financial entity toward the same foundation.

How this maps to cryptography 

Post-Quantum Readiness addresses cryptography through several interlocking control areas. The key areas with direct cryptographic implications are:

SectionFunctionWhat it saysSupporting Products
EO 14412 §4; forthcoming CISA CBOM guidanceCryptographic Inventory and CBOM ReadinessDiscover and inventory certificates, keys, algorithms, and embedded cryptographic libraries across core banking, payments, and open banking systems, producing the asset-level visibility a cryptographic bill of materials requires.Command / AgileSec
NIST IR 8547 deprecation scheduleQuantum Vulnerability AssessmentAnalyze discovered cryptography against approved and deprecated algorithm lists to identify quantum-vulnerable assets and prioritize by data sensitivity and retention period.AgileSec
EO 14412 §3; OMB M-26-15PQC-Capable Certificate IssuanceIssue and manage certificates using NIST-standardized PQC algorithms, including hybrid certificates that support staged migration across long-lived banking and payment infrastructure.EJBCA
G7 CEG Roadmap; DORA RTS Articles 6–7Cryptographic Agility at Estate ScaleRotate, reissue, and re-key certificates across core banking, card, and correspondent-banking infrastructure at fleet scale, without manual per-endpoint intervention.Command / EJBCA
SWIFT SwiftNet PQC migration targetPQC-Ready Messaging InfrastructurePrepare certificate and key infrastructure ahead of SwiftNet’s planned PQC-enabled release and the migration window that follows it.EJBCA / Command
EO 14412 procurement provisions; PCI DSS Requirement 12.3.3PQC-Ready Code and Firmware SigningSign payment applications, ATM and POS firmware, and core banking releases with quantum-resistant algorithms so update pipelines remain trustworthy across their full support period.SignServer / Signum

Readiness questions

PQC migration reviews, whether initiated by a federal customer, a correspondent counterparty, or an internal risk function, focus on whether the organization knows its exposure and has a governed plan. Key areas assessors will probe:

  • Cryptographic inventory completeness: Can the organization enumerate every certificate, key, algorithm, and cryptographic library in use across core banking, payments, and open banking systems, including inherited dependencies?
  • Quantum vulnerability classification: Has the inventory been assessed against the NIST deprecation schedule, with quantum-vulnerable assets identified and ranked by data sensitivity and retention period?
  • Migration plan and ownership: Is there a named owner, a documented migration plan, and a timeline aligned to the 2030 deprecation and 2035 disallowance dates?
  • Long-lived data and custody strategy: For transaction, custody, and KYC/AML data that must remain confidential well past current algorithm lifespans, are compensating controls or migration timelines documented?
  • Cryptographic bill of materials production capability: Could the organization produce a cryptographic inventory for its systems today if a federal customer or correspondent bank requested one?
  • Vendor and correspondent PQC posture: Are SWIFT counterparties, card networks, and core banking or cloud vendors being assessed for their own migration plans, given that inherited cryptography becomes the institution’s exposure?