Why Financial Services Must Act
Financial institutions rely on public-key cryptography for every significant transaction, communication, and record. TLS secures connections between customers, banks, and financial networks. PKI authenticates counterparties. Digital signatures authorize transactions and attest to document integrity. HSMs protect the private keys that underpin all of these mechanisms.
The harvest-now-decrypt-later threat is acute for financial services. Adversaries monitoring financial networks today can archive encrypted traffic, including transaction data, settlement records, and interbank communications, with the intent to decrypt it when quantum hardware becomes available. The value of this archived data does not diminish over time for some categories of records.
HNDL Risk in Financial Data
Financial transaction archives are a particular concern. Regulatory requirements mandate that financial records be retained for years or decades. A transaction archive that must be held for ten years faces a significant HNDL exposure window. If adversaries are already collecting this data, migration of archival encryption to post-quantum algorithms is urgent.
High-value interbank communications are another priority. SWIFT messages, correspondent banking communications, and settlement instructions that are collected and archived today could reveal counterparty relationships, transaction patterns, and strategic positions if decrypted in the future.
Less time-sensitive financial data, such as payment authorization messages that are retained for only a few months, has lower HNDL exposure. These systems can be scheduled in later migration phases after the highest-risk archival systems are addressed.
Key Systems to Migrate
Migration in financial services must cover a broad set of cryptographic systems. TLS for all customer-facing and interbank connections is an immediate priority. Certificate infrastructure for authenticating servers, users, and devices must be updated to support ML-DSA certificates. HSMs used for key management, signing, and transaction authorization must be upgraded or replaced.
Payment card processing systems depend on cryptographic algorithms for PIN encryption, transaction authentication, and key management. These systems operate under PCI DSS requirements and must maintain compliance throughout any migration. Migration planning must be coordinated with payment network requirements.
Interbank and financial messaging networks present coordination challenges. A single institution cannot unilaterally update to post-quantum algorithms for interbank communications if its counterparties do not yet support them. Industry-wide coordination through financial sector working groups is typically required.
Regulatory Context
Financial regulators are increasingly attentive to post-quantum risk. The Financial Stability Board (FSB) has highlighted quantum risk as an emerging cyber threat to financial stability. National regulators in multiple jurisdictions have published guidance encouraging financial institutions to begin cryptographic inventory and migration planning.
Firms operating in the European Union should monitor guidance from ENISA and national financial supervisors regarding post-quantum requirements under DORA (Digital Operational Resilience Act) and related cybersecurity frameworks. US firms should monitor guidance from FFIEC, OCC, and the Federal Reserve.
While no universal regulatory deadline for PQC migration in financial services has been established by any regulator, the direction is clear and early movers will be better positioned for compliance when requirements are formalized.
Vendor and Counterparty Coordination
Financial services firms depend heavily on third-party technology providers: core banking platforms, payment processors, HSM vendors, cloud providers, and financial messaging network operators. Migration cannot be complete while these providers still use quantum-vulnerable algorithms in services the firm depends on.
Vendor due diligence should include post-quantum readiness as a standard procurement criterion. Existing vendor contracts should be reviewed to determine whether security update obligations extend to algorithm migration. Where vendor roadmaps are unclear, firms should engage vendors directly and document their responses.
Implementation Approach
The recommended starting point is a cryptographic inventory that identifies all systems processing, transmitting, or storing sensitive financial data with long retention periods. These systems go to the top of the migration priority list.
Hybrid TLS deployment on internet-facing and interbank connections provides immediate HNDL protection for new traffic. Certificate migration to ML-DSA follows as the CA ecosystem develops the necessary profiles and tooling. HSM upgrades and payment network integration require the longest lead times and should be planned earliest.

