Almost every secure interaction in banking, from mobile log-ins and card authorisations to SWIFT messages, API calls and code signing, relies on public-key cryptography such as RSA and elliptic-curve algorithms. A sufficiently powerful quantum computer would break those algorithms. Nobody knows exactly when such a machine will exist, but the uncertainty is narrowing, and the migration to quantum-resistant cryptography will take longer than most technology programmes banks have run.
The standards are ready; the clock has started
In August 2024 the US National Institute of Standards and Technology approved the first three post-quantum Federal Information Processing Standards: FIPS 203 (ML-KEM) for key establishment, FIPS 204 (ML-DSA) for digital signatures and FIPS 205 (SLH-DSA), a hash-based signature scheme1. NIST's draft transition guidance, IR 8547, proposes that quantum-vulnerable algorithms offering 112-bit security, such as RSA-2048 and P-256 elliptic-curve cryptography, be deprecated after 2030 and disallowed after 20352.
Regulators and cyber agencies have aligned around those dates. The UK's National Cyber Security Centre asks organisations to define migration goals, complete discovery and build an initial plan by 2028; to complete their highest-priority migrations by 2031; and to finish migrating all systems, services and products by 20353. The EU's coordinated roadmap, published in June 2025, asks member states to begin by the end of 2026, move high-risk use cases by the end of 2030 and complete as much as feasible by 20354. In January 2026 the G7 Cyber Expert Group, which advises G7 finance ministers and central bank governors, published a roadmap for the financial sector that points to 2035 for the overall transition and suggests addressing the most critical systems in 2030–325.
The deadlines are converging
Selected official post-quantum migration milestones
| Body | Near term | Mid term | Completion |
|---|---|---|---|
| UK NCSC | 2028: goals, discovery, initial plan | 2031: highest-priority migrations | 2035: all systems migrated |
| EU NIS Cooperation Group | End-2026: start national transition, inventories | End-2030: high-risk use cases | End-2035: as many systems as feasible |
| US NIST (draft IR 8547) | n/a | After 2030: 112-bit RSA/ECC deprecated | After 2035: quantum-vulnerable algorithms disallowed |
| G7 Cyber Expert Group | Now: awareness, inventory, planning | 2030–32: most critical financial systems | 2035: overall sector target |
Note: Compiled from NCSC, EU NIS Cooperation Group, NIST and G7 Cyber Expert Group publications cited in the text. G7 dates are non-authoritative planning targets.
Why 2035 is later than it looks
Two features of the threat compress the timeline. The first is harvest now, decrypt later: adversaries can intercept and store encrypted data today and decrypt it once a capable machine exists, so data with a long confidentiality life, such as customer records, credit files and strategic communications, is already at risk. The BIS stresses this point in its quantum-readiness roadmap for the financial system6, and the G7 group cites it explicitly in setting its targets5. The second is expert opinion. The Global Risk Institute's 2025 survey of 26 experts put the probability of a cryptographically relevant quantum computer within ten years at 28–49%, the highest in the survey's history, and within 15 years at 51–70%7.
Our view: for data that must stay confidential for ten years or more, the quantum deadline is not 2035. It is today.
Banks are ahead of other sectors, but not far enough
Surveys suggest banking is among the more prepared industries. In Capgemini's 2025 survey of large organisations, 86% of banks said they were working on or planning to use quantum-safe solutions within five years, against a 70% average; among early adopters, 47% of banks said they had already budgeted for post-quantum initiatives or planned to start transitioning within two years, against 38% across sectors8. But only a minority of respondents, 11% of the full sample, qualified as "quantum-safe champions" combining mature governance with strong technical execution8.
Banks are planning earlier than most
When early-adopter organisations expect to initiate a formal plan to adopt post-quantum cryptography, % of respondents, 2025 (%)
Note: Capgemini Research Institute survey, April–May 2025, 703 early-adopter organisations. Rows may not sum to 100 due to rounding.
Migration will not be a single switch. Many institutions are starting with hybrid schemes that combine classical and post-quantum algorithms, which the G7 roadmap notes are already in use in web infrastructure5. New algorithms bring larger keys and signatures, which can affect latency, bandwidth and hardware such as payment terminals, smart cards and hardware security modules. Testing those effects on payments and card rails, where timings are tight and devices long-lived, is one reason the full programme spans a decade.
Crypto-inventory is a data problem
Every official roadmap starts in the same place. The NCSC's first milestone is a full discovery exercise3; the G7 roadmap calls for a comprehensive inventory of cryptographic assets, communication protocols and third-party dependencies5; the BIS describes the cryptographic inventory as a critical foundation6. In a large bank that inventory spans hardware security modules, certificates, TLS endpoints, databases, mainframe and payment protocols, embedded libraries in thousands of applications, and cryptography buried inside vendor and cloud services. The G7 group notes that obtaining detailed vendor roadmaps for specific cloud and cryptographic services can be essential5.
This is fundamentally a data-management challenge: discovering assets from scanners, code repositories, configuration databases and supplier attestations; reconciling duplicates; linking each asset to applications, business services, data classifications and owners; and keeping the result current as systems change. It is the same discipline banks have built for data lineage and operational resilience mapping, and it should reuse that investment rather than create another spreadsheet.
- Discover and reconcile. Combine automated scanning with application and vendor attestations into a single cryptographic bill of materials.
- Prioritise by data life and criticality. Rank systems by how long their data must stay secret and how critical the service is, not by technical convenience.
- Build crypto-agility. Abstract cryptography behind services and policies, so algorithms can be swapped without rewriting applications; this will not be the last transition.
- Pull the supply chain along. Write post-quantum roadmaps and evidence into vendor contracts and third-party risk reviews.
The first milestone is close. For a bank that has not yet begun, 2028 leaves roughly two budget cycles to complete discovery and planning across the whole estate and its suppliers. The practical priority for 2026 and 2027 is therefore not choosing algorithms, which standards bodies have largely done, but establishing ownership, funding and the inventory that every later decision depends on.