← Back to News
Regulation

Treasury launches task force for finance’s post-quantum migration

The Treasury’s new Quantum-Readiness Task Force will coordinate the financial sector’s move to post-quantum cryptography, including vendor readiness. Payments are exposed first, through public-key signatures and long-lived hardware.

The US Department of the Treasury on August 24, 2026, launched a Quantum-Readiness Task Force to coordinate the financial sector’s transition to post-quantum cryptography. That is the family of algorithms designed to withstand a large-scale quantum computer, a machine that could break the public-key schemes banks and payment networks rely on today.

The task force follows Executive Order 14412, signed in June 2026, which tightens adoption deadlines for federal agencies and starts a process to require post-quantum cryptography from government contractors. It also builds on the G7 Cyber Expert Group’s roadmap for the transition. Its members include government agencies, banks, financial market infrastructures, and technology providers.

Three workstreams, one of them aimed at vendors

WorkstreamPurpose
Sector Alignment & PQC TransitionAlign financial institutions on a common migration method and sequence
Third-Party & Vendor ReadinessMake sure technology vendors can deliver the new algorithms in their products
Digital Assets and Emerging Technology RiskAssess the exposure of digital assets and emerging technologies
The three workstreams announced by the Treasury

“Post-quantum cryptography readiness is no longer a future-proofing exercise—it is a present-day risk control,” said Deborah Guild, chair of the Financial Services Sector Coordinating Council and head of technology at PNC Financial Services Group. The Treasury describes a risk-based approach built on identifying critical dependencies, improving cryptographic agility, promoting interoperability, and strengthening operational resilience.

Public-key signatures are the weak link in payments

A single payment relies on several families of cryptography, and they are not equally exposed. Public-key algorithms based on integer factorization or elliptic curves fall to Shor’s algorithm running on a large enough quantum machine. Symmetric algorithms hold up better. Grover’s algorithm roughly halves their effective key length, which a longer key offsets.

PrimitiveUse in paymentsExposure
RSA, elliptic curvesEMV chip authentication, scheme certificates, gateway TLS sessionsBroken by Shor’s algorithm
AES, 3DESPIN block encryption, zone keys between hardware security modules, card data protectionWeakened by Grover, offset by longer keys
SHA-2, HMACHashing and integrity protection of authorization messagesSmaller security margin, not broken
How exposed the cryptography in the payment chain is
🔑
Harvest now, decrypt later
Traffic encrypted today with a public-key algorithm can be intercepted and stored, then decrypted once a capable machine exists. That pulls the deadline forward for any data that stays sensitive for more than a few years: cardholder identity, account numbers, and transaction histories.
Server racks in a data center
Payment keys live in hardware security modules that are replaced on cycles measured in years.

Crypto agility means more than picking an algorithm

Cryptographic agility, the Treasury’s term, is the ability to swap an algorithm without rewriting the application that calls it. In most production payment systems, the algorithm is baked into message formats, hardware security module configurations, and existing certifications. Changing the signature scheme means reworking the specification, the hardware, and the certification, on three timelines that don’t line up.

The second workstream targets what institutions find hardest to manage: their reliance on third parties. A card issuer doesn’t control the cryptography used by its processor or its card manufacturer, or the roadmap of its HSM vendor. “The transition requires organizations to prioritize critical systems and processes, manage dependencies across the financial ecosystem, and address implementation challenges,” Guild said.

3
workstreams in the task force
US Department of the Treasury, August 24, 2026
14412
the June 2026 executive order behind the initiative
The Quantum Insider, August 2026
5 to 10 years
common expert estimate for a machine able to break current encryption
Banking Dive, August 2026
⚠️
Hardware lifecycles set the timetable
Cards are reissued roughly every three years. POS terminals and hardware security modules stay in service much longer, and certifying them takes years. The migration will be planned around hardware refresh cycles, not software releases.

Guidance, not rules

The task force has no binding authority. It will produce shared benchmarks, not an enforceable standard. For US institutions, the hard requirements will come from the executive order and from the rules imposed on government contractors. For European firms, the G7 Cyber Expert Group roadmap is the closest reference point. Either way, the first job is to inventory cryptographic dependencies, whatever algorithms are chosen in the end.

Provenance

Published August 29, 2026

5 sources, 5 distinct domains

↗ US Department of the Treasury, “Treasury Announces the Quantum-Readiness Task Force,” August 24, 2026 · home.treasury.gov↗ Banking Dive, “Treasury to help financial firms transition to quantum-resistant encryption” · bankingdive.com↗ Cybersecurity Dive, “Treasury to help financial firms transition to quantum-resistant encryption” · cybersecuritydive.com↗ The Quantum Insider, “U.S. Treasury Announces the Quantum-Readiness Task Force,” August 24, 2026 · thequantuminsider.com↗ ABA Banking Journal, “Treasury announces Quantum-Readiness Task Force,” August 2026 · bankingjournal.aba.com
← All news