PlatformPlatform architectureProduct tourProduct graphRisk intelligenceContinuous governanceEvidence & auditDeploymentIntegrationsExecutive view
BOM SuiteSBOMCBOMQBOMAIBOMHBOMBOM Governance
SolutionsSecurityComplianceSupply chain riskQuantum readinessAI governanceDigital trust
ComplianceCERT-InRBISEBI / CSCRFMeitYNISTEU CRAEU AI ActCERT-In SBOM guide
IndustriesBanking & Financial ServicesGovernment & Public SectorDefence & Critical InfrastructureHealthcareIndian enterprises
ResourcesResource centreSBOM resourcesCBOM resourcesQBOM resourcesAIBOM resourcesHBOM resourcesProgramme & regulationBlog
CompanyAboutSecurity & trustContact
Request a DemoTalk to an expert
Industry4 min readReviewed September 20266 sources

Quantum readiness for banks and financial services

Banks hold long-lived data, run dense webs of partner connections and depend on vendors for much of their cryptography. Financial-sector bodies have started to set out what quantum readiness looks like.

Key takeaways
  • The G7 Cyber Expert Group's January 2026 roadmap suggests addressing the most critical systems around 2030 to 2032 and completing the sector transition by 2035.
  • BIS Project Leap phase 2 tested post-quantum signatures in a live payment system and found significant performance differences from classical algorithms.
  • RBI formed the Q-SAFE expert committee in May 2026, with terms of reference that include a CBOM-based assessment of the sector's cryptographic vulnerabilities.
  • India's DST task force names banking and finance among the sectors needing accelerated migration.
  • Vendor transparency is a recurring obstacle; the QBOM should record supplier roadmaps alongside internal assets.

Why finance is a priority sector

Financial institutions protect data that must stay confidential for long periods, depend on public-key cryptography for payments, customer channels and interbank messaging, and rely heavily on third-party technology. Several policy documents single the sector out. The EU's PQC roadmap names finance among the critical infrastructure whose high-risk use cases should be migrated by the end of 2030 [1]. India's DST task force lists banking and finance among the sectors requiring accelerated timelines [2].

The G7 Cyber Expert Group roadmap

In January 2026 the G7 Cyber Expert Group published a coordinated roadmap for the financial sector's transition to post-quantum cryptography [3]. It sets out six phases: awareness and preparation; discovery and inventory; risk assessment and planning; migration execution; migration testing; and validation and monitoring. The inventory phase calls for a "comprehensive inventory of cryptographic assets, communication protocols, and relevant third-party dependencies" [3]. The roadmap suggests prioritising the most critical systems, for example by addressing them in 2030 to 2032, with an overall sector target of 2035 aligned with government guidance [3]. It also flags limited transparency, including obtaining detailed vendor roadmaps for cloud and cryptographic services, as a barrier [3].

Testing in payment systems: Project Leap

The BIS Innovation Hub's Project Leap phase 2, published on 11 December 2025, worked with the Bank of Italy, Bank of France, Deutsche Bundesbank, Nexi-Colt and Swift to test post-quantum cryptography in live payment operations by replacing traditional digital signatures [4]. The report found significant performance differences between traditional and post-quantum algorithms, and stressed that migration also involves organisational readiness, training, system inventory and cross-institution coordination [4]. For a QBOM, that means recording performance-sensitive paths, not only algorithms.

India: RBI's Q-SAFE committee

On 25 May 2026 the Reserve Bank of India constituted an expert committee on a Quantum Secure and Adaptive Financial Ecosystem (Q-SAFE), convened by Dr Anil Prabhakar of IIT Madras [5]. Its terms of reference include examining the benefits, risks and challenges of quantum technology for the financial sector; assessing the sector's cryptographic vulnerabilities through a Cryptography Bill of Materials evaluation and identifying critical at-risk systems; evaluating industry readiness and vendor solutions; and developing a roadmap and framework to quantum-secure the Indian financial system [5]. The committee is to report within six months. Regulated entities should watch for its recommendations; until then, CERT-In's CBOM/QBOM guidance [6] and the DST targets [2] are the most specific Indian references.

Where banks' quantum-vulnerable cryptography sits

AreaTypical cryptographyQBOM notes
Internet and mobile bankingTLS key exchange and server certificatesInternet-exposed; candidates for hybrid key exchange early
Payment and interbank messagingSignatures and PKI on messages and channelsPerformance-sensitive; coordinate with scheme operators
HSMs and key managementKey wrapping, PIN and card keys, signingVendor-controlled; record firmware versions and roadmaps
Customer and transaction archivesEncryption at rest, backups, key transportLong retention drives harvest-now priority
Partner and fintech APIsMutual TLS, token signingThird-party dependency; include in supplier requirements

A practical sequence for a bank

  1. Build a CBOM for customer-facing channels, payment flows and HSM estates first (see How to build a QBOM).
  2. Record data retention periods from records-management policy and score assets (see Quantum risk assessment).
  3. Request CBOMs and PQC roadmaps from core banking, HSM, network and cloud suppliers (see PQC procurement requirements).
  4. Test hybrid key exchange on selected external channels and measure performance.
  5. Track progress by business service and report it to the board alongside other operational-resilience metrics.

How IntelliXBOM helps

IntelliXBOM correlates cryptographic assets with the software, HSM and network hardware and business services that depend on them, which suits a bank's mix of in-house and vendor systems. It validates supplier BOMs against required-field policies, keeps version history, and produces timestamped evidence mapped to framework controls, deployable on-premise or air-gapped. This article summarises public guidance and is not legal advice.

Frequently asked questions

Has RBI issued post-quantum requirements for banks?

As of September 2026, RBI has constituted the Q-SAFE expert committee, formed on 25 May 2026, to assess quantum risks, including through a CBOM evaluation, and to develop a roadmap for the financial sector. Watch for its report and any follow-up guidance.

What does the G7 roadmap recommend for banks?

It sets out six phases from awareness to validation and monitoring, starting with a comprehensive inventory of cryptographic assets, protocols and third-party dependencies. It suggests addressing the most critical systems around 2030 to 2032 and completing the transition by 2035.

Why is post-quantum migration harder for payment systems?

BIS Project Leap found significant performance differences between post-quantum and traditional algorithms in a live payment setting. Payment systems also involve many institutions, so changes must be coordinated across participants.

Sources

  1. Roadmap for the Transition to Post-Quantum Cryptography (DG CONNECT presentation, June 2025)European Commission, hosted by ENISAwww.enisa.europa.eu/media/56885
  2. Implementation of Quantum Safe Ecosystem in India: Report of the Task Force (February 2026)Department of Science & Technology, Government of Indiadst.gov.in/sites/default/files/Report_TaskForce_PQMigration_4Feb26%20(v1).pdf
  3. Advancing a Coordinated Roadmap for the Transition to Post-Quantum Cryptography in the Financial Sector (January 2026)G7 Cyber Expert Group, via U.S. Treasuryhome.treasury.gov/system/files/136/G7-CEG-Quantum-Roadmap.pdf
  4. Project Leap phase 2: quantum-proofing payment systems (December 2025)Bank for International Settlementswww.bis.org/publications/project-leap-phase-2-quantum-proofing-payment-systems
  5. RBI constitutes Expert Committee on Quantum Secure and Adaptive Financial Ecosystem (Q-SAFE) (25 May 2026)Reserve Bank of Indiarbi.org.in/Scripts/BS_PressReleaseDisplay.aspx?prid=62803
  6. Technical Guidelines on SBOM, QBOM & CBOM, AIBOM and HBOM, Version 2.0 (9 July 2025)CERT-In, Government of Indiawww.cert-in.org.in/PDF/TechnicalGuidelines-on-SBOM,QBOM&CBOM,AIBOM_and_HBOM_ver2.0.pdf

Sources checked in September 2026. Regulations and guidance change; always refer to the issuing body’s current publication. This content is for general information and is not legal advice.

Related QBOM guides

Across the BOM Suite

Put your QBOM under governance.Quantum readiness with continuous correlation and timestamped evidence.