The US Department of the Treasury on August 24, 2026, launched a Quantum-Readiness Task Force to coordinate the financial sector’s transition to post-quantum cryptography. That is the family of algorithms designed to withstand a large-scale quantum computer, a machine that could break the public-key schemes banks and payment networks rely on today.
The task force follows Executive Order 14412, signed in June 2026, which tightens adoption deadlines for federal agencies and starts a process to require post-quantum cryptography from government contractors. It also builds on the G7 Cyber Expert Group’s roadmap for the transition. Its members include government agencies, banks, financial market infrastructures, and technology providers.
Three workstreams, one of them aimed at vendors
| Workstream | Purpose |
|---|---|
| Sector Alignment & PQC Transition | Align financial institutions on a common migration method and sequence |
| Third-Party & Vendor Readiness | Make sure technology vendors can deliver the new algorithms in their products |
| Digital Assets and Emerging Technology Risk | Assess the exposure of digital assets and emerging technologies |
“Post-quantum cryptography readiness is no longer a future-proofing exercise—it is a present-day risk control,” said Deborah Guild, chair of the Financial Services Sector Coordinating Council and head of technology at PNC Financial Services Group. The Treasury describes a risk-based approach built on identifying critical dependencies, improving cryptographic agility, promoting interoperability, and strengthening operational resilience.
Public-key signatures are the weak link in payments
A single payment relies on several families of cryptography, and they are not equally exposed. Public-key algorithms based on integer factorization or elliptic curves fall to Shor’s algorithm running on a large enough quantum machine. Symmetric algorithms hold up better. Grover’s algorithm roughly halves their effective key length, which a longer key offsets.
| Primitive | Use in payments | Exposure |
|---|---|---|
| RSA, elliptic curves | EMV chip authentication, scheme certificates, gateway TLS sessions | Broken by Shor’s algorithm |
| AES, 3DES | PIN block encryption, zone keys between hardware security modules, card data protection | Weakened by Grover, offset by longer keys |
| SHA-2, HMAC | Hashing and integrity protection of authorization messages | Smaller security margin, not broken |
Crypto agility means more than picking an algorithm
Cryptographic agility, the Treasury’s term, is the ability to swap an algorithm without rewriting the application that calls it. In most production payment systems, the algorithm is baked into message formats, hardware security module configurations, and existing certifications. Changing the signature scheme means reworking the specification, the hardware, and the certification, on three timelines that don’t line up.
The second workstream targets what institutions find hardest to manage: their reliance on third parties. A card issuer doesn’t control the cryptography used by its processor or its card manufacturer, or the roadmap of its HSM vendor. “The transition requires organizations to prioritize critical systems and processes, manage dependencies across the financial ecosystem, and address implementation challenges,” Guild said.
Guidance, not rules
The task force has no binding authority. It will produce shared benchmarks, not an enforceable standard. For US institutions, the hard requirements will come from the executive order and from the rules imposed on government contractors. For European firms, the G7 Cyber Expert Group roadmap is the closest reference point. Either way, the first job is to inventory cryptographic dependencies, whatever algorithms are chosen in the end.