Quantum computers threaten the RSA and ECC encryption underneath nearly every financial transaction. Citi Bank already sounded the alarm in its 2026 Quantum Threat report, where it warned that organizations with long-term data confidentiality requirements should begin implementing established post-quantum cryptography (PQC) standards now.
And this isn’t a problem that’s five or 10 years away. The threat is already here, and it’s known as “harvest now, decrypt later” (HNDL). Attackers steal encrypted financial data today and wait for the hardware to catch up. Financial institutions hold transaction, account, and other sensitive records for years. And some information must remain protected far longer than its minimum regulatory retention period. Quantum computing timelines keep shrinking. The math doesn’t work.
The exposure runs through your entire identity infrastructure. Wire transfers depend on keys that, once recovered, let attackers forge payment instructions. Banking APIs authenticate partners with certificates that an adversary could mint at will. E-signatures rely on cryptography that, once broken, make forged executive authorizations indistinguishable from genuine ones. Client certificates grant direct administrative access the moment their keys are recovered. Every one of these systems assumes RSA and ECC hold, and a cryptographically relevant quantum computer (CRQC) retires that assumption. Even 34 high-quality qubits can trigger export controls, a sign of how seriously governments are taking quantum capability. But qubit count alone doesn’t equal quantum advantage.
The same aging cryptography sits inside mainframes deployed decades ago, HSMs bought under old procurement cycles, and payment switches nobody wants to touch because they still work. That’s why this isn’t as simple as swapping out a single crypto library and calling it done.
The Financial Systems Quantum Puts at Risk
Some systems carry more exposure than others. Payment processing networks, clearing houses, and point-of-sale infrastructure move money constantly, all through encryption built on the same aging assumptions. Interbank messaging protocols, including SWIFT and ISO 20022, carry transaction instructions between institutions that have to trust each other’s cryptography completely.
Core databases hold customer PII, account data, and years of trade history, exactly the kind of long-lived data HNDL attackers target. Tokenized assets, digital currencies, and smart contract architectures add a newer layer of exposure on top of the old one. None of these systems were built with an end date on their encryption in mind. But quantum computing gives them one.
The Clock’s Already Running
Financial institutions don’t get to wait for a perfect standard or a cryptographically relevant quantum computer before this becomes a business problem. NIST finalized its post-quantum cryptography standards in 2024, and that baseline is now the reference point examiners work from. In June 2026, the White House signed Executive Order 14412, moving the federal government’s own migration deadlines up to 2030 for key establishment and 2031 for digital signatures.
Financial institutions aren’t federal agencies, but they tend to fall in line once defense and government mandates set the pace. Central banks and cross-border bodies are moving in parallel: the Bank for International Settlements, the SEC, and the EU’s Digital Operational Resilience Act (DORA) framework are all building post-quantum expectations into their guidance. Institutions that wait risk having quantum readiness show up as an audit finding before it ever makes it onto the roadmap.
SWIFT’s Customer Security Controls Framework (CSCF) shows how wide the gap still is. CSCF v2026, the version institutions are attesting against right now, carries no post-quantum requirement. What it does require, under Control 2.4, is that data moving between the SWIFT secure zone and back-office systems use secure, industry-accepted protocols with a minimum security level of 112 bits for symmetric keys, 2048 bits for RSA, or 256 bits for Elliptic Curves. That control moved from advisory to mandatory this cycle. Separately, fourteen other controls now extend to customer client connectors, the APIs, middleware, and file-transfer clients that reach SWIFT indirectly, pulling a much wider set of endpoints into mandatory scope. In other words, today’s compliance floor still depends on cryptography that won’t hold up in the quantum era. Passing your CSP attestation and being quantum-ready are not the same test.
The timing is what makes this urgent rather than ironic. SWIFT is phasing Control 2.4 in, with bridging servers and new data flows in scope first and legacy direct exchanges following in a later cycle. Any institution re-architecting back-office connectivity over the next two years is making cryptographic decisions that will still be running past the federal government’s 2030 deadline. Building crypto-agility into that work now costs a fraction of revisiting it in 2029.
SWIFT itself isn’t standing still. It worked with the BIS Innovation Hub Eurosystem Centre, Banca d’Italia, Banque de France, the Deutsche Bundesbank, and Nexi-Colt on Project Leap Phase 2, which replaced traditional digital signatures with post-quantum ones in central bank liquidity transfers and published results in December 2025. The BIS reported findings on performance, interoperability, and cryptographic agility, and was blunt that the challenges “go beyond technical aspects and include awareness, resource allocation, competence development, inventory, pilots, governance and more.” Read that alongside CSCF v2026 and the signal is clear: the people who run the rails are already testing PQC while the compliance frameworks still specify RSA. Waiting for the framework to tell you to move means starting years behind them.
A Migration Plan, Not a Rip-and-Replace
None of this requires ripping out your core banking systems. Start with assessment: build a cross-functional task force across IT, risk, compliance, and treasury, and inventory where cryptography actually lives across mainframes, HSMs, and payment switches.That means building both a Cryptographic Bill of Materials (CBOM) to understand where cryptography is used and a Quantum Bill of Materials (QBOM) to identify which systems are most exposed and should move first. ZeroTier’s Quantum Signals hub covers these steps and other practical guidance for building a PQC migration strategy. From there, mitigate what’s most exposed first.
Maximize classical key lengths on customer-facing systems like online banking portals and open banking APIs to buy time immediately. Deploy FIPS-compliant PQC on the payment rails most exposed to harvest now and forge now attacks, then work inward toward the core.
Long-term, the goal is crypto-agility: infrastructure that can adapt as NIST, (Digital Operational Resilience Act) DORA, and central bank requirements evolve instead of forcing another rebuild every time the standards change. That’s where ZeroTier Quantum fits in. Built as an end-to-end quantum-secure networking platform, it gives financial institutions a software-defined way to bring post-quantum protection across existing infrastructure without waiting for every underlying system to be replaced. Software overlays can bring post-quantum protection to legacy mainframes without a full rip-and-replace, helping institutions start securing data in transit now while building toward a broader PQC migration.
It’s also worth asking your core banking, payment, and cloud HSM vendors for modular PQC roadmaps now, before you’re negotiating from a weaker position. That question alone separates vendors who’ve planned for this from those who haven’t.
Migration cycles for financial infrastructure run five to 10 years. Waiting for fault-tolerant quantum hardware to arrive before you start means starting too late. ZeroTier Quantum gives institutions a way to begin that transition now with security and performance designed to be measured, proven, and compared, plus the flexibility to deploy and configure protection across existing environments without waiting for the rest of the infrastructure stack to catch up. The task force and the crypto audit can begin today.
Contact sales to learn more about bringing quantum-secure networking into your financial platform.