top of page

Post-Quantum Rules Tighten as Regulators Move From Advice to Deadlines

Post-Quantum Rules Tighten as Regulators Move From Advice to Deadlines

Financial regulators across three continents have shifted post-quantum cryptography from a research topic to a supervisory expectation within a matter of months, and the compliance clock is now visible even where hard mandates are not. A cross-jurisdiction pilot convened by the Responsible Fintech Institute with Safeheron, launched on 23 August 2026, is the latest signal that banks and their supervisors are testing quantum-safe infrastructure together rather than waiting for a cryptographically relevant quantum computer to arrive. The more consequential story for compliance and technology-risk teams is what sits behind that pilot: a fast-hardening set of supervisory expectations that increasingly attach dates to the transition.


What has actually changed for supervised institutions?


Until recently, most official guidance on quantum risk was advisory. That is no longer a safe assumption. On 7 July 2026, the European Central Bank issued letter SSM-2026-0301 to the chief executives of all 110 significant institutions it supervises, requiring each to submit a board-owned action plan on AI-enabled cyber threats to its Joint Supervisory Team by 31 October 2026. The letter is not itself a quantum instrument, and it introduces no new binding rules: the enforceable framework remains the Digital Operational Resilience Act.


What matters for quantum planning is the letter's closing paragraph, in which the ECB states that post-quantum migration must start now and pre-announces a separate letter dedicated to quantum computing. The same day, the European Systemic Risk Board issued a parallel warning on systemic cyber risk from frontier AI models.


The direction is consistent elsewhere. On 28 July 2026, the Monetary Authority of Singapore said it would issue formal supervisory expectations later in the year to guide institutions toward quantum-resilient cryptography, with the stated aim of sector-wide resilience before the end of the decade. That builds on MAS advisory TCRS/2024/01, which recommended cryptographic inventories, migration prioritisation and crypto-agility as guidance rather than mandate. Switzerland's FINMA, in Guidance 05/2026, has recommended post-quantum roadmaps by mid-2027.


Why is Hong Kong scoring its own banks?


The most concrete benchmark to date comes from the Hong Kong Monetary Authority, which on 27 July 2026 published its first Whitepaper on Quantum Preparedness of Hong Kong's Banking Sector alongside a Quantum Preparedness Index. The index scored the sector 2.3 out of 10, with sub-scores of 2.4 for awareness, 2.5 for planning, 1.8 for pilots and 2.3 for practical preparedness. Roughly half of surveyed banks had no formal migration plan, and 32% had not begun. For institutions that did have transition plans, the HKMA put the expected implementation timeframe at 5.6 years on average, which is the operative number behind the regulator's urgency.


The HKMA is targeting a score of 10 by 2030. That target sits under the Resilience pillar of its DART framework, introduced in November 2025 within the broader Fintech 2030 strategy and its Fintech Promotion Blueprint. Notably, the whitepaper frames post-quantum readiness as an extension of existing supervisory instruments rather than a separate regime, mapping it to the Supervisory Policy Manual module TM-G-1 on technology risk, the Cyber Resilience Assessment Framework and operational-resilience guidance under OR-2. Some 87% of surveyed banks ranked clear supervisory expectations and timelines among their top support priorities, a demand signal that helps explain why regulators are now attaching dates.


What are the migration deadlines banks are planning against?


A shared set of timelines is emerging across standards bodies and national authorities, even where enforcement differs. The US National Institute of Standards and Technology, in draft IR 8547, proposes deprecating quantum-vulnerable public-key cryptography after 2030 and disallowing it after 2035. The UK's National Cyber Security Centre has set phased targets of discovery by 2028, high-priority migration by 2031 and full transition by 2035. The EU's coordinated roadmap directs member states to begin migration by the end of 2026, secure high-risk use cases by 2030 and complete the transition by 2035, with a proposed NIS2 amendment that would make post-quantum planning an explicit obligation. A US executive order in June 2026 directed federal agencies to migrate high-value systems on a comparable horizon.


The intellectual foundation for much of this is BIS Paper No 158, Bank for International Settlements research published in July 2025, which cautions explicitly against treating the change as a simple algorithm swap. It frames the transition around cryptographic agility, defence in depth, hybrid models and phased migration, with a cryptographic inventory as the critical first step. BIS has also tested the mechanics: Project Leap Phase 2, completed in December 2025 with the Bank of Italy, Banque de France, Deutsche Bundesbank, Nexi-Colt and Swift, replaced traditional digital signatures with post-quantum cryptography in liquidity transfers on the Eurosystem's Target2 system and reported material performance differences that require further testing before live deployment.


How large is the risk being priced in?


The scale of the exposure is one reason supervisory patience is thinning. Analysis published by Citi Global Perspectives & Solutions in February 2026 estimated that a single-day quantum attack on a major US bank's payment access could cost the American economy up to $3.3 trillion, while assigning a probability of up to 34% that a cryptographically relevant quantum computer arrives by 2034. Whatever the precise odds, the migration itself is a multi-year programme, and the "harvest now, decrypt later" threat means data captured today can be decrypted once the hardware exists. That combination is why guidance is converging on a single instruction: begin the inventory now.


Where the cross-jurisdiction pilot fits


The RFI and Safeheron pilot, which brings in regulators including Abu Dhabi Global Market, the Gelephu Financial Services Office and the Malta Financial Services Authority alongside participating banks, sits within this supervisory shift rather than apart from it. Regulators are taking an observer role in the first phase and a governance role thereafter, and the initiative is intended to test quantum-resistant approaches under consistent conditions and to publish its findings. The technical and digital-asset specifics of that pilot fall outside the scope of this regulatory analysis. For readers, the signal is that supervisors are moving from position papers to controlled testing, and increasingly to dated expectations.


Why This Matters to FinanceX Readers


For compliance, technology-risk and treasury leaders, post-quantum cryptography has crossed from horizon-scanning into supervisory dialogue. The near-term deliverables are becoming predictable: a cryptographic inventory, a board-owned migration plan, named accountability, and vendor engagement on quantum-safe roadmaps.


Institutions supervised by the ECB already face an October 2026 action-plan deadline that pre-figures a dedicated quantum letter; those in Singapore, Hong Kong and Switzerland face converging expectations on similar horizons. The banks that treat cryptographic agility as an architectural requirement now, rather than a project to start once standards finalise, will spend the late 2020s executing rather than scrambling.


Given a multi-year average transition timeframe and 2030 to 2035 milestones across major jurisdictions, the practical question is no longer whether to plan, but whether an institution can evidence a credible plan when its supervisor asks.


 
 
bottom of page