Current thematic dossiers

Select a theme to view its dossier.

Quantum computing

This deep dive examines recent efforts by global and national authorities to build awareness of quantum computing risks and opportunities, advance post-quantum cryptography preparedness through migration roadmaps and emerging expectations, and assess experimental quantum-safe approaches.

Overview

Since the start of 2026, authorities and industry bodies have given the financial sector’s transition to quantum-resistant cryptography a clearer operational shape, marking a shift from awareness-raising towards operationalizing the roadmap to quantum resilience. At the same time, industry feedback continues to highlight practical constraints, including hidden cryptography, legacy infrastructure, long data-retention periods, vendor dependencies, evolving standards, and competing cyber-resilience priorities.

What's new

The European Supervisory Authorities identified non-EU dependencies, cyber and emerging technology threats, and private credit as key vulnerabilities, while assessing the EU financial system as resilient overall. They called for stronger crisis preparedness, monitoring and stress testing of external and private credit exposures, and early action on risks from artificial intelligence and quantum computing.

The Danish Financial Supervisory Authority has set a technology agenda through 2030 covering AI, quantum technology, tokenization and financial innovation. It will assess emerging risks, clarify existing requirements and consider expanding its FT Lab regulatory sandbox, with the aim of supporting innovation without adding unnecessary rules or weakening financial stability and customer protections.

The U.S. Department of the Treasury launched a public-private task force to accelerate the financial sector’s transition to post-quantum cryptography. Its work will focus on sector alignment, third-party readiness, digital asset risks and the operational resilience of critical financial infrastructure.

Deep dive

Global initiatives

At global level, publications issued since the start of 2026 have addressed both the organisation of post-quantum migration and the current state of industry preparedness. In January, the G7 Cyber Expert Group, which advises G7 finance ministers and central bank governors on cybersecurity matters, published a non-prescriptive roadmap for the financial sector's transition to post-quantum cryptography. The roadmap is intended to provide financial authorities, institutions, market infrastructures, critical service providers and technology vendors with a shared reference for migration planning and coordination, rather than establish regulatory requirements. It groups migration activities into six broad phases:

01

Awareness & Preparation

Development of executive awareness, strategy, and role definition

02

Discovery & Inventory

Mapping of cryptographic assets, dependencies, and capability gaps

03

Risk Assessment & Planning

Design of risk-based, tailored migration and governance plans

04

Migration Execution

Deployment of quantum-resistant solutions across prioritized functions

05

Migration Testing

Testing of migrated functions and ecosystem resilience exercises

06

Validation & Monitoring

Continuous validation, improvement, and incorporation of updated standards

The roadmap treats governance and risk management, management of external dependencies and stakeholder dialogue as continuing activities throughout the transition. It also provides an indicative planning horizon: 2035 is identified as a broad reference point for overall migration, while institutions may address their most critical systems during 2030?32. These dates are described as non-authoritative and subject to adjustment as the threat environment, standards and implementation experience evolve.

In May, the G7 Central Bank Quantum Technologies Working Group, co-chaired by the Banque de France and the Bank of Canada, published Preparing for Quantum Technologies: Key Considerations for Financial Sector Participants. The report provides a broader assessment of quantum-related security risks and potential financial applications. On cryptographic security, it describes post-quantum cryptography as a central component of the transition while noting that implementation involves more than replacing existing algorithms. Relevant considerations include larger keys and signatures, performance effects, integration with legacy systems, interoperability across institutions and the parallel operation of conventional and quantum-resistant systems during the migration period. It also examines complementary approaches, including distributed symmetric key exchange and quantum key distribution, and records their different maturity, infrastructure, scalability, cost and governance characteristics.

The industry perspective was set out in the World Federation of Exchange's (WFE) January report, Regulatory Signals and Industry Perspectives on Quantum Computing Preparedness. The WFE drew on regulatory developments and preliminary feedback from members of its Global Cybersecurity Working Group. Respondents generally regarded a cryptographically relevant quantum computer as a five-to-ten-year or longer-term prospect. Awareness was increasing, but deep technical preparedness remained limited, and firms continued to allocate greater attention and resources to more immediate concerns such as generative-AI threats, ransomware, cloud dependency and broader cyber-resilience requirements.

The WFE nevertheless recorded several forms of early preparation. Exchanges and clearing houses were monitoring regulatory and standard-setting developments, discussing quantum risk in governance forums, engaging technology suppliers and undertaking preliminary risk assessments. A smaller number were considering cryptographic inventories or incorporating quantum-safe criteria into procurement and vendor evaluation. The report also identified practical migration constraints: cryptography embedded across databases, application programming interfaces, messaging layers, file systems and legacy systems; long-lived infrastructure and data; reliance on cloud, software and market-data providers; uncertainty about algorithm maturity; and the cost of designing systems that can replace cryptographic algorithms without substantial redesign.

National initiatives

At the national level, authorities have begun incorporating post-quantum migration into sectoral roadmaps, supervisory engagement, and longer-term technology planning. In parallel, several authorities have launched sector-wide diagnostics and measurable readiness benchmarks to inform clearer short- and medium-term actions and expectations.

Asia • TaiwanPost-quantum migration reference guide

The Taiwan Financial Services Commission in June released a post-quantum cryptography migration reference guide for the financial industry to help financial institutions prepare for cyber risks linked to advances in quantum computing. The guide is a planning and preparedness tool and sets out a risk-based, phased approach covering governance, cryptographic inventories, crypto-agility, ecosystem coordination, risk prioritization, supply chain management, and testing and transition.

Asia • IndiaWorking group on technology roadmap

The Securities and Exchange Board of India established a working group to formulate short-term and long-term technology roadmaps for market infrastructure institutions, covering a five year and ten year horizon. Its mandate includes quantum-safe systems alongside artificial intelligence, cloud computing, tokenisation, RegTech and SupTech.

Asia • Hong KongQuantum Preparedness Index

In July, the Hong Kong Monetary Authority (HKMA) launched a dedicated Quantum Preparedness Index and companion whitepaper to assess the banking sector's maturity in adopting post-quantum cryptography and quantum computing. Under the inaugural Index it scored the banking sector 2.3 out of 10 across Awareness, Planning, Pilots and Practical Preparedness. HKMA aims to support full sectoral readiness by 2030 through a co-developed PQC toolkit, training and workshops, and industry engagement.

Europe • SwitzerlandFINMA guidance on quantum-safe migration

In July, the Swiss Financial Market Supervisory Authority (FINMA) published guidance on quantum computing following a survey of 60 financial institutions, which found that most remain at an early stage of the transition to quantum-safe encryption and only 8% have a specific migration roadmap. FINMA recommends that institutions establish a board-approved strategy and roadmap by mid-2027, supported by institution-specific risk analysis, comprehensive cryptographic inventories, prioritisation of critical data exposed to ?harvest now, decrypt later? risks, crypto-agility, and coordination with external service providers.

Europe • FrancePost-quantum preparation awareness

The French Prudential Supervision and Resolution Authority published a communication in April encouraging financial institutions to prepare for post-quantum migration. It identified internal awareness, inventories of cryptographic resources, assessment of the confidentiality lifespan of data, risk-based prioritisation, crypto-agility and hybrid arrangements as key components of institutional migration programmes.

Middle East • JordanSectoral roadmap for post-quantum migration

The Central Bank of Jordan issued a sectoral roadmap for the financial and banking sectors. It provides for the integration of quantum-related risks into institutional risk registers and governance arrangements, the development of internal capabilities, inventories of cryptographic assets and risk-based migration priorities. The roadmap also envisages pilot testing in virtual or non-production environments, change management arrangements to preserve service continuity and other coordination activities with private sector participants.

The Hong Kong Monetary Authority's Quantum Preparedness Index, initially announced in February as part of the Authority's release of Fintech Promotion Blueprint and subsequently released in July, offers one of the most granular illustration of the early stage of sectoral preparedness. The Index assesses banks across Awareness, Planning, Pilots and Practical Preparedness, with an overall sector score of 2.3 out of 10. Formal governance, dedicated funding, workforce training, quantum-risk assessments, cryptographic inventories, approved migration strategies, testing arrangements and progress monitoring remain limited across most institutions. The Authority notes that progress is also constrained by the lack of established assessment methodologies, the complexity of identifying cryptography across legacy systems, technical debt, uncertainty over standards and timelines, and dependence on vendors, financial market infrastructures and shared service providers.

Key sources