Quantum-Safe Finance · Independent Reference Desk · Updated September 2026

The migration clock is running.
Here is exactly where it stands.

Independent research, a board-ready readiness index, and open-source cryptography for banks, payment infrastructures and fintechs preparing for the post-quantum era. Written by a practitioner, Sigstore-signed, and free.

The Quantum-Safe Regulatory & Technology Clock
View Full Jurisdiction Matrix →
20 days
NIST FIPS 140-2 Sunset
21 Sep 2026: Remaining FIPS 140-2 module certificates move to Historical list. Impact: HSM validation.[1]
End 2026
EU National Transition Roadmaps
31 Dec 2026: European Commission recommendation for member states to establish PQC banking transition plans.[2]
2028
UK NCSC Discovery Milestone
Target discovery & cryptographic inventory milestone under UK national cyber strategy.[3]
1,582 days
US Federal HVAs (EO 14412)
31 Dec 2030: Key establishment on High-Value Assets. 31 Dec 2031: Digital signatures. Contractor rule: end 2030.[4]
2030 / 2032
G7 Cyber Expert Group Window
Target migration window for systemic financial institutions published in 13 Jan 2026 Roadmap.[5]

Who are you planning for?

Targeted playbooks, scorecards, and engineering architectures tailored to your organizational mandate.

Banks & Payment Infrastructures

Core Ledgers, SWIFT & Payment Rails

Full lifecycle migration blueprint: Cryptographic Bill of Materials (CBOM), hybrid TLS 1.3 tunnels, HSM firmware transitions, and quantum-safe ISO 20022 messaging.

Explore Bank Architecture →
Fintechs & Scale-Ups

Third-Party Due Diligence & Agility

Pass Tier-1 bank cryptographic security audits. Implement lightweight ML-KEM/ML-DSA primitives and eliminate hardcoded asymmetric keys in days, not quarters.

Explore Fintech Due Diligence →
Boards, CROs & Supervisors

Fiduciary Governance & Risk Oversight

Clear fiduciary metrics, board-pack briefings, and risk committee oversight frameworks without vendor jargon or sensationalist timelines.

Download Board Briefing →

Four Strategic Pillars of Quantum-Safe Finance

Rigorous analysis across security engineering, computational algorithms, regulatory compliance, and open-source code.

Cryptographic Discovery

"You Cannot Migrate What You Cannot Enumerate"

Cryptographic dependencies are frequently undocumented across legacy batch jobs, database storage engines, and internal microservice meshes. Automated Cryptographic Bill of Materials (CBOM) generation is the mandatory foundation of post-quantum resilience.

Source: S. Rousseau, "You Cannot Migrate What You Cannot Enumerate", July 2026.
Read CBOM Technical Architecture →
Standardized Primitives

NIST FIPS Finalized

  • FIPS 203 (ML-KEM): Key encapsulation mechanism
  • FIPS 204 (ML-DSA): Primary digital signatures
  • FIPS 205 (SLH-DSA): Stateless hash-based backup
View KyberLib Implementation →
Algorithmic Trading & Liquidity

HSBC & IBM: Up to 34% Fill-Prediction Accuracy Lift

In September 2025, HSBC and IBM published joint research demonstrating a hybrid quantum-classical machine learning pipeline that achieved up to a 34% improvement in bond-fill prediction accuracy on production market data — a validated algorithmic accuracy benchmark on noisy hardware with classical co-processing.

Up to 34% Accuracy Lift
Read Algorithmic State of Play →
Monte Carlo & Portfolio Optimization

Quantum Amplitude Estimation (QAE)

Quadratic speedup for Value-at-Risk (VaR), Credit Valuation Adjustment (CVA), and intraday liquidity stress-testing. Why noisy intermediate-scale quantum (NISQ) systems require error mitigation before live production deployment.

Explore Quantum Risk Algorithms →
Supervisory Nuance

The Real Regulatory Map (No Sensationalism)

No US or European financial supervisors (EBA/ESAs) have issued a binding PQC private-sector penalty mandate yet. However, DORA Article 9 and its RTS on ICT risk management (crypto-agility), the EU Cyber Resilience Act, and the G7 CEG Roadmap (13 Jan 2026) set supervisory expectations for inventory readiness.

View Global Matrix by Jurisdiction →
Central Bank Action

Active Supervisory Frameworks

  • HKMA (Hong Kong): Sector readiness score 2.3/10 (July 2026); target 2030.
  • Bank of Israel: Mandatory institutional transition plans (Jan 2026).
  • G7 CEG / BoE / Fed: 2030–2032 critical systems transition window.
  • BIS Project Leap: Experimental PQC in central bank settlement rails.
Check Deadline Tracker →
Production Open Source

45.7M+ Downloads (as of Sep 2026). Apache-2.0 / MIT. Zero Cloud Lock-In.

Complete, production-tested Rust implementations of ML-KEM (KyberLib), cryptographic password and digest suites (hsh), and automated ISO 20022 message parsers with zero external network dependencies.

Practitioner Research & Briefings

Original essays, mathematical breakdowns, and supervisory analysis. Every article is Sigstore-signed.

View All 6 Research Papers →

You Cannot Migrate What You Cannot Enumerate

Why cryptographic inventories fail in core banking ledgers and how automated Cryptographic Bill of Materials (CBOM) scanning prevents blind spots.

Read Full Essay ↗

The 2026 Post-Quantum Security Scorecard: A Board-Level Metric Framework

Translating mathematical lattice cryptography into six quantifiable governance indicators for audit and risk committees.

Read Full Essay ↗

Always-On CIB: Cyber Recovery, Fallback Rails and Quantum-Safe Treasury

Designing hybrid post-quantum payment tunnels across SWIFT MT/MX and ISO 20022 rails under zero-downtime constraints.

Read Full Essay ↗

The Red Team Became a Supervised Supply Chain: DORA TLPT & Cryptography

How European supervisors are auditing third-party cryptographic dependencies under Threat-Led Penetration Testing guidelines.

Read Full Essay ↗
Self-Assessment Tool

Post-Quantum Banking Resilience Index (PQ-BRI)

Evaluate your institution's exposure across 6 core dimensions: Governance, Cryptographic Inventory, Crypto-Agility, Payment Rails, Supply Chain, and Testing. Compare your posture against the HKMA July 2026 banking benchmark (2.3/10).

6 Evaluation Dimensions
  • 1. Board Governance & Policy
  • 2. Cryptographic Inventory & CBOM
  • 3. Crypto-Agility Architecture
  • 4. Payment Rail & SWIFT Readiness
  • 5. Third-Party Vendor Supply Chain
  • 6. Algorithm Testing & HSM Compliance

What the Banks Are Actually Doing

Public programme disclosures and research benchmarks from global financial institutions.

HSBC & IBM (Sep 2025)

Quantum Algorithmic Bond Trading

Trained hybrid quantum machine learning models on high-volume production fixed-income market data, achieving up to 34% lift in bond-fill prediction accuracy compared to classical baseline models.

JPMorgan Chase, Toshiba & Ciena (2022)

Metropolitan Quantum Key Distribution (QKD) Trial

Demonstrated a 2022 research proof-of-concept trial of 800 Gbps QKD across a metropolitan dark-fibre testbed in partnership with Toshiba and Ciena to evaluate physical-layer key exchange for mission-critical blockchain workloads.

Open Source Engineering Toolkit

Production-grade cryptographic engines with CycloneDX SBOMs and verifiable Sigstore provenance.

View All Repositories →
Rust · FIPS 203 ML-KEM
Apache-2.0 / MIT

KyberLib

High-assurance, zero-allocation Rust implementation tracking the finalized NIST FIPS 203 (ML-KEM) standard with comprehensive test vectors and constant-time execution primitives.

Rust · Password & Digest Suite
Apache-2.0 / MIT

hsh

High-performance cryptographic password-hashing and digest utilities in Rust implementing Argon2, bcrypt, scrypt, and secure key derivation functions.

Sebastien Rousseau

Sebastien Rousseau

Founder & Principal Cryptographic Architect · 19 Years in Production Finance

19 years designing, shipping, and securing high-throughput payment rails, institutional ledgers, and cryptographic infrastructure. Author of open-source cryptographic suites with over 45.7 million downloads (as of September 2026). Maintains KyberLib, hsh, and ISO 20022 message parsers. Every published analysis on this site is Sigstore-signed for provenance and cryptographic integrity.

Transparency & Independence Disclosure: All research, scoring models, and open-source tools on Banking On Quantum are published independently by Sebastien Rousseau under open-source licences (Apache-2.0 / MIT) without institutional sponsorship. Professional affiliations with financial institutions do not represent corporate endorsement.

Questions? Answers.

What is the "Harvest Now, Decrypt Later" (HNDL) attack vector?

Adversaries are currently intercepting and storing encrypted financial communications, payment messages, and wire payloads. When cryptanalytically relevant quantum computers (CRQCs) become operational, this stored ciphertext will be decrypted retroactively. Financial records and long-dated contracts (10–30 year lifespans) require post-quantum protection today.

How does Post-Quantum Cryptography differ from Quantum Key Distribution?

Post-Quantum Cryptography (PQC) uses classical mathematical problems (such as lattice-based math in FIPS 203 ML-KEM) running on standard servers, routers, and existing internet protocols. Quantum Key Distribution (QKD) uses quantum physics (photons) over dedicated dark-fibre lines to exchange encryption keys. PQC operates globally on existing infrastructure; QKD provides physical-layer assurance between core inter-bank data centres.

Are regulators mandating PQC migrations with fines today?

No. Neither the US SEC/Fed nor European financial supervisors (EBA/ESAs) have issued a binding private-sector PQC penalty mandate yet. However, DORA Article 9 and its RTS on ICT risk management enforces cryptographic agility in Europe, the Bank of Israel requires transition roadmaps, and the G7 Cyber Expert Group (13 Jan 2026) established coordinated transition expectations. Claims of active fines are vendor marketing overreach.

Why does NIST FIPS 140-2 sunset matter on 21 September 2026?

On 21 September 2026, the NIST Cryptographic Module Validation Program (CMVP) moves all remaining FIPS 140-2 certificates to the Historical list. Banking Hardware Security Modules (HSMs) must transition to FIPS 140-3 compliance to maintain procurement and regulatory validation.

Can quantum algorithms actually speed up derivative pricing on today's hardware?

No bank currently runs a live production trading system on pure quantum hardware. However, hybrid quantum-classical algorithms (such as HSBC/IBM's 2025 bond-fill research) demonstrate up to 34% accuracy improvements in predictive modeling on noisy quantum processors with classical co-processing.

What is a Cryptographic Bill of Materials (CBOM)?

A CBOM is a structured, machine-readable inventory (typically in CycloneDX format) that details every cryptographic algorithm, key length, certificate, protocol, and library deployed across an institution's software supply chain and network infrastructure.

Does Banking On Quantum accept vendor sponsorship or fees?

No. Banking On Quantum is completely vendor-neutral and independent. No vendor pays to appear in our research, vendor landscape maps, or readiness scorecards.

How can our institution schedule a confidential briefing?

You can book an exploratory 30-minute discovery call directly via our Contact Page or by requesting an executive briefing pack for your risk committee.

Take the Next Step in Quantum Readiness

Three clear routes to accelerate your institution's post-quantum roadmap:

Primary Source Citations & Footnotes

  1. NIST Cryptographic Module Validation Program (CMVP), FIPS 140-2 Transition Notice (Moving all remaining FIPS 140-2 modules to Historical List on 21 September 2026).
  2. European Commission, Recommendation on Post-Quantum Cryptography (Member-state national transition roadmaps by end-2026).
  3. UK National Cyber Security Centre (NCSC), Next Generation Cryptography: Quantum Readiness (Discovery milestone: 2028; high-priority milestone: 2031; full migration: 2035).
  4. Executive Office of the President, Executive Order 14412 on Post-Quantum Cryptography Migration (High-Value Assets key establishment: 31 Dec 2030; digital signatures: 31 Dec 2031; contractor FIPS compliance: end-2030).
  5. G7 Cyber Expert Group (CEG), Fundamental Elements for Quantum Readiness in Financial Services (Published 13 January 2026; 2030–2032 critical systems transition window).
Back to the top ↑