Quantum readiness for banks and financial services
Banks hold long-lived data, run dense webs of partner connections and depend on vendors for much of their cryptography. Financial-sector bodies have started to set out what quantum readiness looks like.
- The G7 Cyber Expert Group's January 2026 roadmap suggests addressing the most critical systems around 2030 to 2032 and completing the sector transition by 2035.
- BIS Project Leap phase 2 tested post-quantum signatures in a live payment system and found significant performance differences from classical algorithms.
- RBI formed the Q-SAFE expert committee in May 2026, with terms of reference that include a CBOM-based assessment of the sector's cryptographic vulnerabilities.
- India's DST task force names banking and finance among the sectors needing accelerated migration.
- Vendor transparency is a recurring obstacle; the QBOM should record supplier roadmaps alongside internal assets.
Why finance is a priority sector
Financial institutions protect data that must stay confidential for long periods, depend on public-key cryptography for payments, customer channels and interbank messaging, and rely heavily on third-party technology. Several policy documents single the sector out. The EU's PQC roadmap names finance among the critical infrastructure whose high-risk use cases should be migrated by the end of 2030 [1]. India's DST task force lists banking and finance among the sectors requiring accelerated timelines [2].
The G7 Cyber Expert Group roadmap
In January 2026 the G7 Cyber Expert Group published a coordinated roadmap for the financial sector's transition to post-quantum cryptography [3]. It sets out six phases: awareness and preparation; discovery and inventory; risk assessment and planning; migration execution; migration testing; and validation and monitoring. The inventory phase calls for a "comprehensive inventory of cryptographic assets, communication protocols, and relevant third-party dependencies" [3]. The roadmap suggests prioritising the most critical systems, for example by addressing them in 2030 to 2032, with an overall sector target of 2035 aligned with government guidance [3]. It also flags limited transparency, including obtaining detailed vendor roadmaps for cloud and cryptographic services, as a barrier [3].
Testing in payment systems: Project Leap
The BIS Innovation Hub's Project Leap phase 2, published on 11 December 2025, worked with the Bank of Italy, Bank of France, Deutsche Bundesbank, Nexi-Colt and Swift to test post-quantum cryptography in live payment operations by replacing traditional digital signatures [4]. The report found significant performance differences between traditional and post-quantum algorithms, and stressed that migration also involves organisational readiness, training, system inventory and cross-institution coordination [4]. For a QBOM, that means recording performance-sensitive paths, not only algorithms.
India: RBI's Q-SAFE committee
On 25 May 2026 the Reserve Bank of India constituted an expert committee on a Quantum Secure and Adaptive Financial Ecosystem (Q-SAFE), convened by Dr Anil Prabhakar of IIT Madras [5]. Its terms of reference include examining the benefits, risks and challenges of quantum technology for the financial sector; assessing the sector's cryptographic vulnerabilities through a Cryptography Bill of Materials evaluation and identifying critical at-risk systems; evaluating industry readiness and vendor solutions; and developing a roadmap and framework to quantum-secure the Indian financial system [5]. The committee is to report within six months. Regulated entities should watch for its recommendations; until then, CERT-In's CBOM/QBOM guidance [6] and the DST targets [2] are the most specific Indian references.
Where banks' quantum-vulnerable cryptography sits
| Area | Typical cryptography | QBOM notes |
|---|---|---|
| Internet and mobile banking | TLS key exchange and server certificates | Internet-exposed; candidates for hybrid key exchange early |
| Payment and interbank messaging | Signatures and PKI on messages and channels | Performance-sensitive; coordinate with scheme operators |
| HSMs and key management | Key wrapping, PIN and card keys, signing | Vendor-controlled; record firmware versions and roadmaps |
| Customer and transaction archives | Encryption at rest, backups, key transport | Long retention drives harvest-now priority |
| Partner and fintech APIs | Mutual TLS, token signing | Third-party dependency; include in supplier requirements |
A practical sequence for a bank
- Build a CBOM for customer-facing channels, payment flows and HSM estates first (see How to build a QBOM).
- Record data retention periods from records-management policy and score assets (see Quantum risk assessment).
- Request CBOMs and PQC roadmaps from core banking, HSM, network and cloud suppliers (see PQC procurement requirements).
- Test hybrid key exchange on selected external channels and measure performance.
- Track progress by business service and report it to the board alongside other operational-resilience metrics.
How IntelliXBOM helps
IntelliXBOM correlates cryptographic assets with the software, HSM and network hardware and business services that depend on them, which suits a bank's mix of in-house and vendor systems. It validates supplier BOMs against required-field policies, keeps version history, and produces timestamped evidence mapped to framework controls, deployable on-premise or air-gapped. This article summarises public guidance and is not legal advice.
Frequently asked questions
Has RBI issued post-quantum requirements for banks?
As of September 2026, RBI has constituted the Q-SAFE expert committee, formed on 25 May 2026, to assess quantum risks, including through a CBOM evaluation, and to develop a roadmap for the financial sector. Watch for its report and any follow-up guidance.
What does the G7 roadmap recommend for banks?
It sets out six phases from awareness to validation and monitoring, starting with a comprehensive inventory of cryptographic assets, protocols and third-party dependencies. It suggests addressing the most critical systems around 2030 to 2032 and completing the transition by 2035.
Why is post-quantum migration harder for payment systems?
BIS Project Leap found significant performance differences between post-quantum and traditional algorithms in a live payment setting. Payment systems also involve many institutions, so changes must be coordinated across participants.
Sources
- Roadmap for the Transition to Post-Quantum Cryptography (DG CONNECT presentation, June 2025)European Commission, hosted by ENISAwww.enisa.europa.eu/media/56885
- Implementation of Quantum Safe Ecosystem in India: Report of the Task Force (February 2026)Department of Science & Technology, Government of Indiadst.gov.in/sites/default/files/Report_TaskForce_PQMigration_4Feb26%20(v1).pdf
- Advancing a Coordinated Roadmap for the Transition to Post-Quantum Cryptography in the Financial Sector (January 2026)G7 Cyber Expert Group, via U.S. Treasuryhome.treasury.gov/system/files/136/G7-CEG-Quantum-Roadmap.pdf
- Project Leap phase 2: quantum-proofing payment systems (December 2025)Bank for International Settlementswww.bis.org/publications/project-leap-phase-2-quantum-proofing-payment-systems
- RBI constitutes Expert Committee on Quantum Secure and Adaptive Financial Ecosystem (Q-SAFE) (25 May 2026)Reserve Bank of Indiarbi.org.in/Scripts/BS_PressReleaseDisplay.aspx?prid=62803
- Technical Guidelines on SBOM, QBOM & CBOM, AIBOM and HBOM, Version 2.0 (9 July 2025)CERT-In, Government of Indiawww.cert-in.org.in/PDF/TechnicalGuidelines-on-SBOM,QBOM&CBOM,AIBOM_and_HBOM_ver2.0.pdf
Sources checked in September 2026. Regulations and guidance change; always refer to the issuing body’s current publication. This content is for general information and is not legal advice.