Original briefings. Zero spin.
Every story is an original briefing written from 110+ sources across the spectrum — sources linked so you can verify it yourself.
Treasury Launches Quantum-Readiness Task Force as Banks Face 2030-2035 Encryption Deadlines

The Treasury Department isn't waiting around for a quantum computer to actually exist before making banks fix their encryption.
Treasury announced Monday it's standing up a Quantum-Readiness Task Force, pulling together government officials, banks, market infrastructure operators, and tech vendors to coordinate a shift away from cryptographic tools that a sufficiently powerful quantum computer could eventually crack, according to nextgov. The tools in question protect payment systems, financial records, and market transactions. Right now, no machine on Earth can break them.
The Threat Nobody Can See Yet, But Everyone's Planning For
Adversaries can steal encrypted data today and just sit on it, waiting for quantum computing to catch up. Security researchers call this "harvest now, decrypt later," according to nextgov. Your bank records encrypted this year could be exposed a decade from now if someone grabbed the encrypted file today and a cryptographically relevant quantum computer shows up later.
Deborah Guild, chair of the Financial Services Sector Coordinating Council and head of technology at PNC Financial Services Group, said in an interview: "Post-quantum cryptography readiness is no longer a future-proofing exercise, it is a present-day risk control." Guild said banks need to prioritize their most critical systems first while tracking dependencies across the entire financial ecosystem.
Guild runs technology at one of the country's largest regional banks, and her job is literally to worry about this stuff for a living.
The Standards Already Exist. The Question Is Execution.
This isn't a hypothetical framework Treasury is asking banks to wait for. The National Institute of Standards and Technology finalized three post-quantum cryptography standards in August 2024: FIPS 203, 204, and 205, according to Global Banking and Finance. ML-KEM handles key establishment. ML-DSA and SLH-DSA handle digital signatures. NIST says organizations should start applying these now, not wait for a countdown clock to hit zero.
The Bank for International Settlements says the critical first step is basic: figure out where your cryptography actually lives. Public-key cryptography is baked into digital certificates, APIs, software signing, identity systems, hardware security modules, and connections to market infrastructure, according to Global Banking and Finance. A bank that treats this as a simple network encryption upgrade will miss half its actual exposure.
Treasury's task force builds on a roadmap the G7 Cyber Expert Group released in January 2026, co-chaired by Treasury and the Bank of England, according to nextgov. That roadmap sets 2035 as a general target for the financial sector to complete its transition, though it explicitly calls that timeline nonbinding.
The Quantum Insider's reporting lays out the fuller regulatory calendar building around that target. NIST's transition framework, IR 8547, calls for deprecating RSA-2048 and ECC-256 by 2030 and disallowing them entirely after 2035, though those specific deadlines apply to federal agencies and organizations handling federal data. National Security Systems must support quantum-resistant cryptography in new acquisitions starting January 1, 2027, under CNSA 2.0. Software and firmware signing needs quantum-resistant signatures by 2030. The UK's National Cyber Security Centre has staked out its own phased targets: cryptographic discovery by 2028, high-priority system migration by 2031, full transition by 2035.
Treasury's move also follows President Trump's June 2026 executive order directing federal agencies and critical infrastructure sectors to speed up quantum-threat preparations, according to nextgov. The Office of Management and Budget has since told agencies to inventory their cryptographic systems and account for third-party software vendors.
What the Task Force Will Actually Do
Treasury says the group will split its work three ways: coordinating the financial sector's broader migration, assessing how ready technology vendors and other third parties actually are, and examining risks tied to digital assets and other emerging technology, according to nextgov. Treasury also wants the task force to push "cryptographic agility": the ability to swap out encryption methods quickly as standards and threats evolve, rather than getting locked into one system for another twenty years.
That agility point matters because the standards themselves are still moving. NIST continues to standardize additional algorithms beyond the three finalized in 2024, according to Global Banking and Finance, which is why the sector guidance leans toward flexible, bounded deployments rather than a single hard-wired solution across an entire bank's infrastructure.
None of this is coming with a hard federal deadline for private banks the way CNSA 2.0 binds national security systems. The G7's 2035 target is nonbinding by its own description. That leaves an open question worth watching: whether voluntary coordination through a task force is enough to get a fragmented financial sector, banks, vendors, clearinghouses, payment processors, actually inventoried and migrated on anything resembling that timeline, or whether Congress or federal regulators eventually convert the G7's guidance into an enforceable mandate.
Sources used for this briefing
This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.