Post-quantum cryptography mandatory for financial institutions by 2030–2034
In brief
- G7 published phased migration roadmap in January 2026, full execution by 2034.
- US Executive Order 14412 mandates federal agencies adopt NIST standards by December 2030–2031.
- FINMA requires Swiss supervised institutions to have board-approved PQC strategies by mid-2027.
- Fewer than 8% of financial institutions have formal post-quantum cryptography roadmaps.
- Bitcoin and Ethereum rely on elliptic curve cryptography vulnerable to quantum computers.
Regulatory mandates take shape
The G7 Cyber Expert Group published a roadmap in January 2026 laying out a phased migration plan for post-quantum cryptography in the financial sector. The timeline breaks into three stages: planning from 2025 to 2027, risk assessments through 2029, and full execution by 2034.
In the US, Executive Order 14412, issued on June 22, 2026, mandates that federal agencies migrate to NIST post-quantum cryptography standards. The deadlines are specific: key establishment algorithms must be in place by December 31, 2030, and digital signature algorithms by December 31, 2031.
Switzerland moved in parallel. FINMA, the country's financial regulator, published Guidance 05/2026 in July 2026 requiring all supervised institutions to have board-approved post-quantum cryptography strategies by mid-2027. The US Treasury established a Quantum-Readiness Task Force in August 2026 to coordinate the transition across the financial sector.
The cryptographic foundation
NIST finalized its core post-quantum cryptography standards, designated FIPS 203, 204, and 205, in August 2024. These standards are built on algorithms like ML-KEM for key encapsulation and ML-DSA for digital signatures. The shift addresses a concrete threat: quantum computers, once sufficiently powerful, will render current encryption obsolete.
The urgency stems partly from the "harvest now, decrypt later" attack vector. Adversaries can intercept encrypted data today and store it, then decrypt it once quantum computing capability arrives. This isn't theoretical—it's why regulators are moving now, even though large-scale quantum computers remain years away.
Yet readiness is sparse. According to a Swiss survey, fewer than 8% of financial institutions currently have a formal post-quantum cryptography roadmap in place. The gap between mandate and implementation is substantial.
The blockchain blind spot
Here's the critical gap: most major blockchain protocols, including Bitcoin and Ethereum, rely on elliptic curve cryptography for transaction signing and wallet security. Elliptic curve cryptography is precisely the type of cryptography that quantum computers are expected to break using Shor's algorithm.
This creates a peculiar asymmetry: traditional finance has clear deadlines and regulatory oversight. Blockchain networks, which hold trillions in value, face no comparable mandate and no coordinated migration plan. The quantum threat doesn't distinguish between banking systems and decentralized ledgers—but the regulatory response does.


