Questions? Answers.

What is the "Harvest Now, Decrypt Later" (HNDL) attack vector?

Adversaries are actively intercepting and storing encrypted financial communications, wire transactions, and sensitive customer data today. When Cryptanalytically Relevant Quantum Computers (CRQCs) become operational, this stored ciphertext can be decrypted retroactively. Assets with 10–30 year confidentiality requirements (such as long-dated credit agreements, trade secrets, and institutional ledgers) require post-quantum protection today.

How does Post-Quantum Cryptography differ from Quantum Key Distribution?

Post-Quantum Cryptography (PQC) relies on mathematical problems (such as lattice-based cryptography in NIST FIPS 203 ML-KEM) running on standard servers, network routers, and existing internet protocols. Quantum Key Distribution (QKD) uses quantum physics (photons) over dedicated optical fibre lines to exchange encryption keys. PQC operates globally over existing infrastructure; QKD provides physical-layer assurance between core inter-bank data centres.

Are regulators mandating PQC migrations with fines today?

No. Neither the US SEC/Fed nor the European Central Bank has issued a binding private-sector PQC penalty mandate yet. However, DORA Article 9 enforces cryptographic agility in Europe, the Bank of Israel requires transition roadmaps, and the G7 Cyber Expert Group has established coordinated transition expectations. Claims of active fines are vendor marketing overreach.

Why does the NIST FIPS 140-2 sunset matter on 21 September 2026?

On 21 September 2026, the NIST Cryptographic Module Validation Program (CMVP) moves all remaining FIPS 140-2 certificates to the Historical list. Banking Hardware Security Modules (HSMs) must transition to FIPS 140-3 compliance to maintain procurement and regulatory validation.

Can quantum algorithms actually speed up derivative pricing on today's hardware?

No bank currently runs a live production trading system on pure quantum hardware. However, hybrid quantum-classical algorithms (such as HSBC/IBM's 2025 bond-fill research) demonstrate up to 34% accuracy improvements in predictive modeling on noisy quantum processors with classical co-processing.

What is a Cryptographic Bill of Materials (CBOM)?

A CBOM is a structured, machine-readable inventory (typically in CycloneDX format) that details every cryptographic algorithm, key length, certificate, protocol, and library deployed across an institution's software supply chain and network infrastructure.

Does Banking On Quantum accept vendor sponsorship or fees?

No. Banking On Quantum is completely vendor-neutral and independent. No vendor pays to appear in our research, vendor landscape maps, or readiness scorecards.

How can our institution schedule a confidential briefing?

You can book an exploratory 30-minute discovery call directly via our Contact Page or by requesting an executive briefing pack for your risk committee.

Back to the top ↑