The migration clock is running.
Here is exactly where it stands.
Independent research, a board-ready readiness index, and open-source cryptography for banks, payment infrastructures and fintechs preparing for the post-quantum era. Written by a practitioner, Sigstore-signed, and free.
Who are you planning for?
Targeted playbooks, scorecards, and engineering architectures tailored to your organizational mandate.
Core Ledgers, SWIFT & Payment Rails
Full lifecycle migration blueprint: Cryptographic Bill of Materials (CBOM), hybrid TLS 1.3 tunnels, HSM firmware transitions, and quantum-safe ISO 20022 messaging.
Third-Party Due Diligence & Agility
Pass Tier-1 bank cryptographic security audits. Implement lightweight ML-KEM/ML-DSA primitives and eliminate hardcoded asymmetric keys in days, not quarters.
Fiduciary Governance & Risk Oversight
Clear fiduciary metrics, board-pack briefings, and risk committee oversight frameworks without vendor jargon or sensationalist timelines.
Four Strategic Pillars of Quantum-Safe Finance
Rigorous analysis across security engineering, computational algorithms, regulatory compliance, and open-source code.
"You Cannot Migrate What You Cannot Enumerate"
Cryptographic dependencies are frequently undocumented across legacy batch jobs, database storage engines, and internal microservice meshes. Automated Cryptographic Bill of Materials (CBOM) generation is the mandatory foundation of post-quantum resilience.
NIST FIPS Finalized
- FIPS 203 (ML-KEM): Key encapsulation mechanism
- FIPS 204 (ML-DSA): Primary digital signatures
- FIPS 205 (SLH-DSA): Stateless hash-based backup
HSBC & IBM: Up to 34% Fill-Prediction Accuracy Lift
In September 2025, HSBC and IBM published joint research demonstrating a hybrid quantum-classical machine learning pipeline that achieved up to a 34% improvement in bond-fill prediction accuracy on production market data — a validated algorithmic accuracy benchmark on noisy hardware with classical co-processing.
Quantum Amplitude Estimation (QAE)
Quadratic speedup for Value-at-Risk (VaR), Credit Valuation Adjustment (CVA), and intraday liquidity stress-testing. Why noisy intermediate-scale quantum (NISQ) systems require error mitigation before live production deployment.
Explore Quantum Risk Algorithms →The Real Regulatory Map (No Sensationalism)
No US or European financial supervisors (EBA/ESAs) have issued a binding PQC private-sector penalty mandate yet. However, DORA Article 9 and its RTS on ICT risk management (crypto-agility), the EU Cyber Resilience Act, and the G7 CEG Roadmap (13 Jan 2026) set supervisory expectations for inventory readiness.
View Global Matrix by Jurisdiction →Active Supervisory Frameworks
- HKMA (Hong Kong): Sector readiness score 2.3/10 (July 2026); target 2030.
- Bank of Israel: Mandatory institutional transition plans (Jan 2026).
- G7 CEG / BoE / Fed: 2030–2032 critical systems transition window.
- BIS Project Leap: Experimental PQC in central bank settlement rails.
45.7M+ Downloads (as of Sep 2026). Apache-2.0 / MIT. Zero Cloud Lock-In.
Complete, production-tested Rust implementations of ML-KEM (KyberLib), cryptographic password and digest suites (hsh), and automated ISO 20022 message parsers with zero external network dependencies.
Practitioner Research & Briefings
Original essays, mathematical breakdowns, and supervisory analysis. Every article is Sigstore-signed.
You Cannot Migrate What You Cannot Enumerate
Why cryptographic inventories fail in core banking ledgers and how automated Cryptographic Bill of Materials (CBOM) scanning prevents blind spots.
The 2026 Post-Quantum Security Scorecard: A Board-Level Metric Framework
Translating mathematical lattice cryptography into six quantifiable governance indicators for audit and risk committees.
Always-On CIB: Cyber Recovery, Fallback Rails and Quantum-Safe Treasury
Designing hybrid post-quantum payment tunnels across SWIFT MT/MX and ISO 20022 rails under zero-downtime constraints.
The Red Team Became a Supervised Supply Chain: DORA TLPT & Cryptography
How European supervisors are auditing third-party cryptographic dependencies under Threat-Led Penetration Testing guidelines.
Post-Quantum Banking Resilience Index (PQ-BRI)
Evaluate your institution's exposure across 6 core dimensions: Governance, Cryptographic Inventory, Crypto-Agility, Payment Rails, Supply Chain, and Testing. Compare your posture against the HKMA July 2026 banking benchmark (2.3/10).
- 1. Board Governance & Policy
- 2. Cryptographic Inventory & CBOM
- 3. Crypto-Agility Architecture
- 4. Payment Rail & SWIFT Readiness
- 5. Third-Party Vendor Supply Chain
- 6. Algorithm Testing & HSM Compliance
What the Banks Are Actually Doing
Public programme disclosures and research benchmarks from global financial institutions.
Quantum Algorithmic Bond Trading
Trained hybrid quantum machine learning models on high-volume production fixed-income market data, achieving up to 34% lift in bond-fill prediction accuracy compared to classical baseline models.
Metropolitan Quantum Key Distribution (QKD) Trial
Demonstrated a 2022 research proof-of-concept trial of 800 Gbps QKD across a metropolitan dark-fibre testbed in partnership with Toshiba and Ciena to evaluate physical-layer key exchange for mission-critical blockchain workloads.
Open Source Engineering Toolkit
Production-grade cryptographic engines with CycloneDX SBOMs and verifiable Sigstore provenance.
KyberLib
High-assurance, zero-allocation Rust implementation tracking the finalized NIST FIPS 203 (ML-KEM) standard with comprehensive test vectors and constant-time execution primitives.
hsh
High-performance cryptographic password-hashing and digest utilities in Rust implementing Argon2, bcrypt, scrypt, and secure key derivation functions.
Questions? Answers.
What is the "Harvest Now, Decrypt Later" (HNDL) attack vector?
Adversaries are currently intercepting and storing encrypted financial communications, payment messages, and wire payloads. When cryptanalytically relevant quantum computers (CRQCs) become operational, this stored ciphertext will be decrypted retroactively. Financial records and long-dated contracts (10–30 year lifespans) require post-quantum protection today.
How does Post-Quantum Cryptography differ from Quantum Key Distribution?
Post-Quantum Cryptography (PQC) uses classical mathematical problems (such as lattice-based math in FIPS 203 ML-KEM) running on standard servers, routers, and existing internet protocols. Quantum Key Distribution (QKD) uses quantum physics (photons) over dedicated dark-fibre lines to exchange encryption keys. PQC operates globally on existing infrastructure; QKD provides physical-layer assurance between core inter-bank data centres.
Are regulators mandating PQC migrations with fines today?
No. Neither the US SEC/Fed nor European financial supervisors (EBA/ESAs) have issued a binding private-sector PQC penalty mandate yet. However, DORA Article 9 and its RTS on ICT risk management enforces cryptographic agility in Europe, the Bank of Israel requires transition roadmaps, and the G7 Cyber Expert Group (13 Jan 2026) established coordinated transition expectations. Claims of active fines are vendor marketing overreach.
Why does NIST FIPS 140-2 sunset matter on 21 September 2026?
On 21 September 2026, the NIST Cryptographic Module Validation Program (CMVP) moves all remaining FIPS 140-2 certificates to the Historical list. Banking Hardware Security Modules (HSMs) must transition to FIPS 140-3 compliance to maintain procurement and regulatory validation.
Can quantum algorithms actually speed up derivative pricing on today's hardware?
No bank currently runs a live production trading system on pure quantum hardware. However, hybrid quantum-classical algorithms (such as HSBC/IBM's 2025 bond-fill research) demonstrate up to 34% accuracy improvements in predictive modeling on noisy quantum processors with classical co-processing.
What is a Cryptographic Bill of Materials (CBOM)?
A CBOM is a structured, machine-readable inventory (typically in CycloneDX format) that details every cryptographic algorithm, key length, certificate, protocol, and library deployed across an institution's software supply chain and network infrastructure.
Does Banking On Quantum accept vendor sponsorship or fees?
No. Banking On Quantum is completely vendor-neutral and independent. No vendor pays to appear in our research, vendor landscape maps, or readiness scorecards.
How can our institution schedule a confidential briefing?
You can book an exploratory 30-minute discovery call directly via our Contact Page or by requesting an executive briefing pack for your risk committee.
Take the Next Step in Quantum Readiness
Three clear routes to accelerate your institution's post-quantum roadmap:
Primary Source Citations & Footnotes
- NIST Cryptographic Module Validation Program (CMVP), FIPS 140-2 Transition Notice (Moving all remaining FIPS 140-2 modules to Historical List on 21 September 2026).
- European Commission, Recommendation on Post-Quantum Cryptography (Member-state national transition roadmaps by end-2026).
- UK National Cyber Security Centre (NCSC), Next Generation Cryptography: Quantum Readiness (Discovery milestone: 2028; high-priority milestone: 2031; full migration: 2035).
- Executive Office of the President, Executive Order 14412 on Post-Quantum Cryptography Migration (High-Value Assets key establishment: 31 Dec 2030; digital signatures: 31 Dec 2031; contractor FIPS compliance: end-2030).
- G7 Cyber Expert Group (CEG), Fundamental Elements for Quantum Readiness in Financial Services (Published 13 January 2026; 2030–2032 critical systems transition window).