Quaatso – Quantum Advanced Technologies & Solutions Quaatso Quantum Advanced Technologies & Solutions

What Quantum Computing Means for Banks and Payments

Finance depends on encryption for payments, trading and customer data. Here’s where the quantum risk sits and what regulators and central banks are doing.

By the Quaatso Team • • 2 min read
Share: 𝕏 in
Financial markets data on trading screens.

Few industries rely on public-key encryption as heavily as finance. That makes banks and payment firms some of the most exposed, and some of the most active, in preparing for quantum computers.

01

Where finance relies on public-key encryption

  • ◆Online and mobile banking: every session starts with a key exchange that today mostly uses elliptic curves.
  • ◆Payment cards: chip cards use RSA-based certificates to prove they are genuine.
  • ◆Interbank messaging: payment networks rely on digital certificates and signatures to prove which institution sent a message.
  • ◆Stored records: loan agreements, identity documents and account histories may need to stay confidential for decades.
02

The two main risks

Confidentiality: traffic recorded today, such as customer data or transaction details, could be decrypted later.

Integrity: once quantum computers can break signatures, attackers could forge transactions, certificates or software updates, unless systems have moved to post-quantum signatures by then.

03

What regulators and central banks are doing

  • ◆In September 2024, the G7 Cyber Expert Group, chaired by the US Treasury and the Bank of England, urged financial authorities and firms to understand quantum risks, assess them and develop a plan to mitigate them.
  • ◆The EU’s Digital Operational Resilience Act (DORA), which has applied since 17 January 2025, requires financial firms to manage ICT risk, including keeping their encryption controls up to date.
  • ◆The Bank for International Settlements ran Project Leap with central banks. Phase 1 (2023) protected payment messages between the Banque de France and Deutsche Bundesbank with hybrid post-quantum encryption; phase 2 (2025) tested post-quantum signatures in an operational payment system.
04

Why finance faces a hard migration

Banks run a mix of modern cloud systems and decades-old core platforms, depend on many third-party vendors, and must keep payments running around the clock. Card and payment standards involve many parties who must upgrade together. That is why regulators advise starting inventories and planning now, even with a 2030–2035 horizon.

05

Practical first steps for financial firms

  1. 1Build a cryptographic inventory, starting with customer-facing and payment systems.
  2. 2Ask key vendors for their post-quantum roadmaps and add requirements to contracts.
  3. 3Enable hybrid post-quantum key exchange on external connections where it is supported.
  4. 4Add quantum risk to board-level risk registers and DORA ICT risk frameworks.

task_altKey takeaways

  • check_circleFinance relies on public-key encryption for banking sessions, cards and interbank messages.
  • check_circleThe G7 Cyber Expert Group urged firms to start planning in 2024.
  • check_circleCentral banks have already tested post-quantum cryptography in payment systems.

Sources and further reading

Keep reading

Related articles

View all articlesarrow_forward

Not sure what this means for your organisation?

Book a free, no-obligation consultation. We’ll explain your quantum risks and options in plain language.

Book a Consultationarrow_forward
Quaatso – Quantum Advanced Technologies & Solutions Who We Are

Quaatso (Quantum Advanced Technologies & Solutions) is a quantum technology consultancy. We help organisations migrate to quantum-safe cryptography and put practical quantum computing to work on real business problems.