How does quantum computing threaten financial cryptography?

Quantum computers powerful enough to break RSA-2048 do not yet exist, but adversaries are already collecting encrypted financial data for future decryption. NIST finalized post-quantum cryptography standards in August 2024. Migration timelines for the financial sector typically run five to seven years, making early adoption material today rather than a future concern.

The short answer

The financial system relies on cryptographic primitives — RSA, elliptic curve cryptography, AES — that protect data in transit and at rest. RSA and ECC depend on the hardness of integer factorization and discrete logarithm problems for classical computers. Shor’s algorithm, formulated in 1994, demonstrates that a sufficiently large quantum computer could solve these problems efficiently, breaking the underlying security.

The relevant practical question is not whether quantum will happen but when, and what the migration cost will be. Current quantum computers are decades short of the qubit count and error rates needed to break production cryptography. But the threat does not require capability today; it requires capability before encrypted data loses sensitivity.

NIST’s August 2024 publication of three finalized post-quantum standards marked the formal transition from research to deployment. The financial sector is now beginning multi-year migration projects.

New to financial cryptography? Financial education hub

What the data shows

Quantum computing progress is measurable but uneven, and the financial sector’s response is just beginning to leave a documented trail.

Key figures (NIST, IBM Quantum roadmap, BIS Innovation Hub Project Leap, 2024-2025):

  • NIST published three post-quantum cryptography standards in August 2024: ML-KEM (key encapsulation), ML-DSA (digital signatures) and SLH-DSA (hash-based signatures)
  • Current largest quantum computers operate in the hundreds to low thousands of physical qubits; estimates suggest several million high-quality logical qubits would be needed to break RSA-2048
  • The BIS Innovation Hub launched Project Leap in 2022 to test quantum-safe payment systems, expanding through 2024-2025
  • The US Office of Management and Budget required federal agencies to inventory quantum-vulnerable cryptography by 2023, with migration roadmaps progressing through the late 2020s
  • Financial sector estimates of full cryptographic migration timelines typically range from five to seven years for major institutions

The exception that nuances the headline: capability forecasts have been wrong in both directions. Quantum supremacy on specific narrow tasks arrived earlier than some expected; cryptographically relevant quantum capability has consistently slipped beyond predicted dates. Planning under deep uncertainty is the operational reality.

Dataset: Financial conditions index

Why it happens — the macro mechanism

The quantum-cryptography risk operates through three channels with different time horizons.

Channel 1 — Harvest now, decrypt later. The most underdiscussed mechanism is that the threat is operational today even without working quantum computers. Adversaries can collect encrypted financial communications, customer data and historical transactions, store them, and decrypt later when capability arrives. The attack timeline is asymmetric: the harvest happens in the present, the decryption can wait years. Data with long-lived sensitivity (medical records, biometric authentication, long-tenor financial contracts) is most exposed.

Channel 2 — Migration complexity in entrenched systems. Financial cryptography is embedded in core banking systems, payment networks, key management infrastructure, hardware security modules and embedded devices that may operate for decades. Replacing RSA with ML-KEM is not a configuration change; it requires updates across the cryptographic stack, vendor coordination and extensive testing. The five-to-seven-year timeline reflects the systemic depth of the problem, not engineering laziness.

Channel 3 — Standards migration risk. Even after NIST publication, real deployment depends on standardization in ISO, IETF, EMV and similar bodies, plus implementation in HSM products and TLS libraries. A premature migration to candidate algorithms that are subsequently broken — as happened to SIKE in 2022 — would force a second migration. The financial sector’s caution reflects this two-step risk.

Synthesis by regime: in the pre-2016 phase, post-quantum cryptography was an academic interest; in the 2016-2024 phase, NIST’s standardization process structured the global response while quantum hardware advanced steadily but unspectacularly; the post-2024 regime, marked by published standards and active migration projects, is the first where institutional deployment becomes the bottleneck rather than algorithmic uncertainty.

Quantum cryptography risk is a future event with a present cost: the data you protect today must survive the decryption capability of tomorrow.

Framework: Financial innovation and systemic risk

What it means for different economic actors

Banks and infrastructure providers face cryptographic inventory and migration mandates from supervisors. The Fed, ECB and Bank of England have begun coordinated guidance, and the EU’s Digital Operational Resilience Act includes provisions relevant to cryptographic resilience.

Vendors of HSM, payment terminals and core banking systems are integrating post-quantum algorithms into product roadmaps. The competitive pressure is significant: an institution choosing a vendor today is locking in cryptographic foundations for years.

Data subjects have limited direct visibility into the migration but bear the latent risk. Personal financial information encrypted today with classical cryptography is potentially decryptable in the future if intercepted now.

A common error is dismissing quantum cryptographic risk as speculative. The harvest-now-decrypt-later pattern makes the present cost real, even if the decryption capability remains years away.

Practical observation

What the data suggests for understanding quantum cryptographic risk:

  • Question to ask yourself: Which sensitive financial data, if intercepted today and decrypted in ten years, would still cause harm — and what is the migration plan for that data?
  • Data to monitor: NIST and BIS Innovation Hub publications on post-quantum cryptography deployment, and supervisory guidance from major central banks (level matters for direction; rate of change for urgency)
  • Historical parallel: The 1990s migration from DES to AES took roughly a decade and was driven by classical cryptanalysis advances rather than a hardware threat; the post-quantum migration is structurally larger because it touches public-key infrastructure, not just symmetric encryption
  • What the literature documents: NIST Special Publication 800-208 series, the BIS Project Leap reports, and the ENISA post-quantum cryptography integration guidance provide the most authoritative reference framework

This is descriptive information to help you frame your own analysis. Eco3min does not provide investment advice.

Go deeper

Frequently asked questions

How long until quantum computers break RSA-2048?

Estimates vary widely. Optimistic projections suggest the late 2030s; conservative views push toward the 2040s or later. The metric of interest is not raw qubit count but logical qubits with sufficiently low error rates, which is the bottleneck rather than fabrication. The financial sector treats the threat as serious enough to migrate now because of the harvest-now-decrypt-later attack vector and the long migration timeline, regardless of which specific year capability arrives.

Are NIST’s post-quantum standards definitively secure?

Cryptographic security is conditional, not absolute. The published standards (ML-KEM, ML-DSA, SLH-DSA) survived years of cryptanalysis during the NIST process and rest on lattice-based problems believed to be quantum-resistant. The 2022 SIKE attack — which broke a separate post-quantum candidate after years of public scrutiny — illustrates that confidence is empirical and never absolute. NIST plans to standardize additional algorithms specifically to provide diversification against any single mathematical assumption being broken.

What is the cost of post-quantum migration for a major bank?

Public estimates are limited because institutions disclose cautiously. Indirect indicators suggest budgets in the tens to low hundreds of millions for major banks over the migration period, covering inventory, vendor coordination, application updates, hardware refresh and testing. The figure is dwarfed by ongoing cybersecurity spending generally but represents a significant discrete project that competes with other resilience investments.

Last updated — 30 July 2026

Disclaimer – Financial Information: The analyses, commentary, and content published on eco3min.fr are provided for informational and educational purposes only. They do not constitute investment advice or a solicitation to buy or sell financial instruments. Past performance is not indicative of future results. All investment decisions involve risk and are the sole responsibility of the reader.