Post-Quantum Readiness for FinServ:
The timeline is now written down
| Region | United States reinforced by coordinated international guidance from the G7, the EU, and national financial regulators |
| Applicability | Banks and Payment Providers with Federal or Cross-Border Exposure: institutions engaging with federal counterparties or subject to expectations tied to CNSA 2.0 and adjacent federal cryptographic policy SWIFT-Connected and Correspondent Institutions: the roughly 11,000 SWIFT users worldwide facing SwiftNet’s planned PQC-enabled release and migration window Any Institution Holding Long-Lived Financial Data: transaction records, custody data, and KYC/AML records whose confidentiality must outlast today’s algorithms |
| Relevant sections | Executive Order 14412: Securing the Nation Against Advanced Cryptographic Attacks (June 22, 2026) OMB Memorandum M-26-15: Execution of the Migration to Post-Quantum Cryptography NIST IR 8547: Transition to Post-Quantum Cryptography Standards G7 Cyber Expert Group Roadmap: Advancing a Coordinated Roadmap for the Transition to Post-Quantum Cryptography in the Financial Sector (January 2026) |
Overview
Every framework in this guide points in the same direction: know what cryptography you have, prove you control it, and be ready to change it. Post-quantum cryptography is where that direction gets a deadline.
In 2024, NIST finalized the first three post-quantum cryptographic standards and published a transition timeline that deprecates the RSA and elliptic curve algorithms underpinning most financial infrastructure by 2030, with full disallowance targeted for 2035. In June 2026, Executive Order 14412 converted that technical guidance into federal policy, directing OMB and the National Cyber Director to lead an accelerated national migration and setting phased deadlines for federal high-value assets. In January 2026, the G7 Cyber Expert Group, co-chaired by the U.S. Treasury and the Bank of England, published a coordinated, sector-specific roadmap urging banks, insurers, exchanges, and financial market infrastructures to move from awareness to inventory, risk assessment, and phased migration well ahead of the mid-2030s planning horizon.
For financial institutions, two threads matter most. First, the same executive order directs the FAR Council to require covered federal contractors to meet PQC-aligned cybersecurity standards by the end of 2030, extending the migration obligation into any institution that sells services into federal supply chains. Second, SWIFT itself has signaled a target date: SwiftNet is expected to become PQC-enabled around 2027, with a migration window measured in months rather than years for the roughly 11,000 institutions connected to the network.
Why it matters
An executive order and a G7 roadmap are not conformance standards, and financial institutions will not be audited against either one directly. Their significance is what they signal: the questions this guide has raised in every chapter, DORA’s crypto-agility expectations, PCI DSS’s cryptographic inventory requirement, NYDFS’s certificate and key inventory, now have dates attached.
The economics of finance make those dates closer than they look. Transaction histories, custody records, and long-retained KYC/AML data encrypted today can be harvested now and decrypted once quantum capability arrives, which means the sensitivity horizon of the data, not the delivery date of a quantum computer, sets the real deadline. Recent industry surveys have found that fewer than 3% of global financial institutions have begun substantive migration, even as SWIFT’s own readiness assessment found the large majority of Tier 1 banks have started evaluation, while smaller institutions lag, creating exactly the weakest-link risk a correspondent-banking network cannot absorb quietly.
Procurement and counterparty due diligence will move faster than regulation. Federal buyers, central banks, and correspondent partners will begin asking for PQC migration plans and cryptographic inventories well before any rule requires them to, and DORA’s own crypto-agility provisions already point every EU financial entity toward the same foundation.
How this maps to cryptography
Post-Quantum Readiness addresses cryptography through several interlocking control areas. The key areas with direct cryptographic implications are:
| Section | Function | What it says | Supporting Products |
| EO 14412 §4; forthcoming CISA CBOM guidance | Cryptographic Inventory and CBOM Readiness | Discover and inventory certificates, keys, algorithms, and embedded cryptographic libraries across core banking, payments, and open banking systems, producing the asset-level visibility a cryptographic bill of materials requires. | Command / AgileSec |
| NIST IR 8547 deprecation schedule | Quantum Vulnerability Assessment | Analyze discovered cryptography against approved and deprecated algorithm lists to identify quantum-vulnerable assets and prioritize by data sensitivity and retention period. | AgileSec |
| EO 14412 §3; OMB M-26-15 | PQC-Capable Certificate Issuance | Issue and manage certificates using NIST-standardized PQC algorithms, including hybrid certificates that support staged migration across long-lived banking and payment infrastructure. | EJBCA |
| G7 CEG Roadmap; DORA RTS Articles 6–7 | Cryptographic Agility at Estate Scale | Rotate, reissue, and re-key certificates across core banking, card, and correspondent-banking infrastructure at fleet scale, without manual per-endpoint intervention. | Command / EJBCA |
| SWIFT SwiftNet PQC migration target | PQC-Ready Messaging Infrastructure | Prepare certificate and key infrastructure ahead of SwiftNet’s planned PQC-enabled release and the migration window that follows it. | EJBCA / Command |
| EO 14412 procurement provisions; PCI DSS Requirement 12.3.3 | PQC-Ready Code and Firmware Signing | Sign payment applications, ATM and POS firmware, and core banking releases with quantum-resistant algorithms so update pipelines remain trustworthy across their full support period. | SignServer / Signum |
Readiness questions
PQC migration reviews, whether initiated by a federal customer, a correspondent counterparty, or an internal risk function, focus on whether the organization knows its exposure and has a governed plan. Key areas assessors will probe:
- Cryptographic inventory completeness: Can the organization enumerate every certificate, key, algorithm, and cryptographic library in use across core banking, payments, and open banking systems, including inherited dependencies?
- Quantum vulnerability classification: Has the inventory been assessed against the NIST deprecation schedule, with quantum-vulnerable assets identified and ranked by data sensitivity and retention period?
- Migration plan and ownership: Is there a named owner, a documented migration plan, and a timeline aligned to the 2030 deprecation and 2035 disallowance dates?
- Long-lived data and custody strategy: For transaction, custody, and KYC/AML data that must remain confidential well past current algorithm lifespans, are compensating controls or migration timelines documented?
- Cryptographic bill of materials production capability: Could the organization produce a cryptographic inventory for its systems today if a federal customer or correspondent bank requested one?
- Vendor and correspondent PQC posture: Are SWIFT counterparties, card networks, and core banking or cloud vendors being assessed for their own migration plans, given that inherited cryptography becomes the institution’s exposure?
TAKE THIS TO MANAGEMENT
The post-quantum transition now has dates attached, from more than one direction. NIST deprecates today’s core algorithms by 2030, Executive Order 14412 requires federal contractors to meet PQC-aligned standards by the end of that year, and SWIFT is targeting a PQC-enabled SwiftNet around 2027. Our transaction records, custody data, and correspondent-banking infrastructure will still be relying on today’s cryptography well past those dates unless we act on our own schedule rather than someone else’s.
The practical first step is the same one every framework in this guide asks for: a complete cryptographic inventory. The cryptographic bill of materials concept will formalize that expectation for federal counterparties, and correspondent banks and card networks will follow. If we build the inventory, assessment, and lifecycle automation now, PQC becomes a managed migration on our schedule rather than a scramble on someone else’s


