READ. SCROLL. LISTEN.

Original briefings. Zero spin.

Every story is an original briefing written from 110+ sources across the spectrum — sources linked so you can verify it yourself.

← Back to headlines

Banks Face Hard Deadlines to Rip Out Encryption Before Quantum Computers Can Break It

Banks Face Hard Deadlines to Rip Out Encryption Before Quantum Computers Can Break It
Starting this year, the US, Swiss, and G7 regulators have set binding deadlines requiring banks to swap out today's encryption for quantum-resistant algorithms, with US agencies required to finish key-exchange upgrades by 2030. Fewer than 8% of Swiss institutions have a formal plan, and the mandates say almost nothing about cryptocurrency, which runs on the same math that quantum computers could eventually break.

The federal government just turned a physics problem into a compliance deadline, and banks are behind.

Starting this year, financial institutions in the US, Switzerland, and across the G7 are on the clock to replace the encryption that protects nearly every online transaction. The reason: quantum computers, once powerful enough, will be able to crack the RSA and elliptic-curve cryptography (ECC) that secures banking, TLS web traffic, and government systems.

The Deadlines, Laid Out

President Trump signed Executive Order 14412 on June 22, 2026, mandating that federal agencies migrate to post-quantum cryptography (PQC) standards set by the National Institute of Standards and Technology, according to Cybersecurity Dive and Quantum Computing Report. The order sets specific dates: key establishment algorithms in place by December 31, 2030, and digital signature algorithms by December 31, 2031. It also directs the Federal Acquisition Regulatory Council to require government contractors to comply, tying quantum-safe encryption to the ability to do business with Washington at all, according to a company commentary distributed through GlobeNewswire and carried by Investing News Network and Markets Insider.

The G7 Cyber Expert Group published its own roadmap in January 2026, breaking the migration into three phases: planning from 2025 to 2027, risk assessments through 2029, and full execution by 2034, per Crypto Briefing.

Switzerland's financial regulator, FINMA, went further on its own turf. Guidance 05/2026, published in July 2026, requires every supervised institution to have a board-approved PQC strategy by mid-2027, Crypto Briefing reported. A Swiss survey found fewer than 8% of institutions currently have one.

In August 2026, Treasury Secretary Scott Bessent and Assistant Secretary for Financial Institutions Luke Pettit stood up a Quantum-Readiness Task Force, described by Cybersecurity Dive as a public-private effort with three workstreams: getting financial firms aligned on the transition, confirming vendors can actually deliver the new algorithms, and evaluating what quantum computing means for cryptocurrency and digital assets. The General Services Administration is running a parallel track under OMB Memorandum M-26-15, rebuilding federal identity and facility-access systems for crypto-agility, and is hosting a Post-Quantum Cryptography Summit scheduled for September 16, 2026, according to Quantum Computing Report.

The Actual Technology

The math being replaced, factoring large numbers and computing discrete logarithms, is what makes RSA and ECC secure against ordinary computers. Prof. Dennis-Kenji Kipker, writing in Forbes, explains that Shor's algorithm, run on a sufficiently powerful quantum computer, would break both outright. PQC swaps in different math: lattice problems, hash-based signatures, and code-based schemes that stay hard even for quantum machines.

NIST finalized its first three PQC standards, FIPS 203, 204, and 205, back in August 2024. ML-KEM handles key exchange; ML-DSA and SLH-DSA cover digital signatures. Kipker notes NIST already has a fourth algorithm, HQC, in reserve as a hedge in case the lattice-based schemes turn out to have weaknesses. Kipker also flags a common confusion: PQC is not quantum key distribution. QKD requires dedicated fiber and only works point-to-point over limited distances, making it impractical for national payment rails. PQC runs on ordinary hardware and slots into existing protocols like TLS, meaning it's a software and certificate migration, not a hardware overhaul.

Why the Rush

Adversaries can capture encrypted traffic today, sit on it, and decrypt it once a capable quantum computer exists, according to Cybersecurity Dive and the Investing News Network commentary. Loan agreements, customer files, and regulatory archives with decades-long confidentiality windows are exposed right now, even though the machine that could crack them doesn't exist yet.

How soon that machine arrives is genuinely disputed. Cybersecurity Dive reports cryptography experts giving a range of five to ten years. A more aggressive timeline comes from Arqit Quantum CEO Andy Leaver, in a shareholder communication filed with the SEC, who said Google, IBM, and Cloudflare have moved their own migration targets up to 2029, and that IonQ has accelerated its roadmap toward a quantum computer capable of challenging RSA-2048 into the 2028-to-2029 window. Arqit sells PQC products, so it has a direct commercial stake in that timeline being taken seriously, and Leaver's estimate should be read alongside the more conservative five-to-ten-year range cited by independent cybersecurity reporting.

The Gap Nobody Is Closing Yet

Crypto Briefing points out something the regulations themselves skip over: none of the G7 roadmap, the executive order, or FINMA's guidance explicitly addresses cryptographic vulnerabilities in blockchain networks or cryptocurrencies, even though most major blockchain protocols rely on the same ECC math that's on the chopping block. The Treasury task force's third workstream is supposed to study exactly that, but as of now there's no binding deadline attached to digital assets the way there is for traditional bank infrastructure.

There's a fair concern buried in the compliance math too. If fewer than 8% of Swiss institutions have a formal roadmap with a mid-2027 deadline bearing down, and US federal deadlines hit in 2030 and 2031, smaller banks and credit unions with thin IT budgets are going to be scrambling against the same clock as the megabanks with dedicated cybersecurity teams. Nobody in these regulatory announcements has detailed what compliance costs smaller institutions, or whether regulators plan any relief for community banks that can't move at Wall Street's pace.

Separately, Treasury has had its hands full this month on an unrelated front. Bessent announced on September 9 that the department's financial crimes unit had flagged roughly $17.5 billion in suspicious activity tied to healthcare fraud, drawn from over 5,700 Bank Secrecy Act reports filed by 471 financial institutions between March 2025 and February 2026, according to the Epoch Times. California, Puerto Rico, Florida, New York, and Minnesota topped the list of flagged providers. This lands on the same desk at the same agency in the same week as the quantum-readiness push.

The open question for the financial sector: whether the 2030 and 2031 federal deadlines, and FINMA's mid-2027 target, are realistic given how few institutions have even started planning. GSA's summit on September 16 is the next checkpoint where regulators and industry will have to show their hand.

Sources used for this briefing

This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.

center
ForbesWhy Post-Quantum Cryptography Is Important For Financial Institutions
center
Crypto BriefingPost-quantum cryptography becomes mandatory for financial institutions
center-left
markets.businessinsiderThe Quantum Deadline Moved Up. Most Firms Cannot Find Their Own Keys.
right
Epoch TimesTreasury Uncovers $17.5 Billion in Suspected Healthcare Fraud
unknown
Quantum Computing ReportGSA and Treasury Launch Dual-Agency Post-Quantum Cryptography Initiatives for U.S. Federal & Financial Infrastructure
unknown
Cybersecurity DiveTreasury to help financial firms transition to quantum-resistant encryption
unknown
Investing NewsThe Quantum Deadline Moved Up. Most Firms Cannot Find Their Own Keys.