The U.S. Department of the Treasury has launched a public-private task force to prepare banks, payment systems, financial-market operators, technology providers and digital-asset companies for a future in which quantum computers could defeat widely used encryption.
Announced on 24 August 2026, the Quantum-Readiness Task Force is intended to accelerate the financial sector’s transition to post-quantum cryptography while reducing the operational risks created by replacing security technology embedded throughout the financial system.
The initiative follows President Donald Trump’s June 2026 executive order directing federal agencies to accelerate their own migrations to cryptographic standards designed to resist attacks from both conventional and quantum computers.
Treasury’s task force will organize its work around three areas:
- Sector Alignment and Post-Quantum Cryptography Transition.
- Third-Party and Vendor Readiness.
- Digital Assets and Emerging Technology Risk.
The task force does not mean that sufficiently powerful quantum computers can break the financial system’s encryption today. The concern is that financial institutions cannot wait for that capability to arrive before beginning one of the largest and most complicated security migrations in modern computing.
Quantum Computing Could Break Foundational Security Controls
Modern financial services depend on cryptography to protect the confidentiality, integrity and authenticity of data.
Encryption protects information moving between consumers, banks, payment processors, clearing systems and cloud platforms. Digital signatures help confirm that software updates, transactions, instructions and electronic documents came from a trusted source and were not altered.
Much of this infrastructure depends on public-key cryptographic algorithms that are considered secure against present-day conventional computers. A sufficiently capable quantum computer could solve certain mathematical problems far more efficiently, undermining some of the algorithms used for key establishment and digital signatures.
The potential effects extend far beyond someone reading an encrypted message. Compromised cryptography could allow an attacker to:
- Decrypt sensitive financial communications.
- Impersonate customers, institutions or trusted systems.
- Forge or manipulate digitally signed instructions.
- Undermine software-update and code-signing protections.
- Interfere with identity and authentication systems.
- Compromise certificates used to establish secure connections.
- Target digital assets controlled through cryptographic keys.
- Challenge confidence in payment and settlement infrastructure.
The financial sector cannot tolerate uncertainty about whether an instruction, transaction or software package is authentic. Cryptographic integrity is therefore not merely a technical safeguard. It is part of the trust architecture supporting the economy.
The Risk Begins Before a Cryptographically Relevant Quantum Computer Exists
Treasury’s initiative also addresses the possibility that adversaries are collecting encrypted information now with the intention of decrypting it later.
This strategy is commonly known as “harvest now, decrypt later.” An attacker does not need immediate access to a sufficiently advanced quantum computer. The attacker can intercept information, preserve it and wait for decryption technology to improve.
The risk is greatest when information has a long useful life. Financial data that could remain sensitive for years may include:
- Customer identity and account information.
- Long-term investment and wealth records.
- Payment and transaction histories.
- Corporate financing and acquisition information.
- Regulatory and supervisory communications.
- Anti-money laundering investigations.
- Risk models and proprietary trading strategies.
- Authentication credentials and identity records.
- Government financial intelligence.
- Information concerning critical financial infrastructure.
The relevant deadline is not simply the day a quantum computer becomes capable of breaking current encryption. Financial institutions must also consider how long their information needs protection and how many years their migration will require.
Why the Financial Sector Requires a Coordinated Transition
A single company can replace an internal application on its own schedule. The financial system does not operate that way.
Banks exchange information with payment networks, clearinghouses, custodians, broker-dealers, insurers, market-data providers, regulators, cloud platforms and thousands of technology vendors. A cryptographic change made by one institution can affect whether another institution can receive, validate or process its information.
If participants adopt incompatible implementations or transition at materially different times, security improvements could create outages, rejected transactions or failures in authentication.
The migration must therefore satisfy several goals simultaneously:
- Old and new systems must continue communicating during the transition.
- Institutions must avoid creating gaps in encryption or authentication.
- Critical financial services must remain available.
- New implementations must be tested for security and performance.
- Vendors must deliver compatible upgrades on usable timelines.
- Domestic changes must work with international financial networks.
- Smaller institutions must not be left without affordable migration options.
This coordination problem helps explain why Treasury is creating a sector-wide task force rather than leaving every institution to develop its approach independently.
Workstream One: Aligning the Sector’s Post-Quantum Transition
The first workstream will focus on sector alignment and the transition to post-quantum cryptography.
Financial institutions vary significantly in size, technical maturity and systemic importance. A global bank operating its own infrastructure faces different challenges from a community bank dependent on a core-processing vendor. A securities exchange, payment network or clearing organization may need to coordinate changes with hundreds or thousands of participants.
Sector alignment does not necessarily mean that every organization will follow the same migration schedule. It means that institutions need shared expectations concerning standards, priorities, testing, interoperability and critical dependencies.
A risk-based transition is likely to prioritize systems according to factors such as:
- The sensitivity and useful life of the protected information.
- The importance of the system to financial stability.
- The type of cryptography being used.
- The difficulty of replacing the technology.
- The number of connected institutions and service providers.
- The consequences of an outage or implementation failure.
- The availability of tested post-quantum alternatives.
Lower-risk systems may provide useful pilot environments before organizations migrate infrastructure responsible for essential payments, settlement or customer authentication.
Workstream Two: Vendors May Determine the Speed of Migration
The second workstream addresses third-party and vendor readiness, one of the most significant obstacles facing the financial sector.
Most financial institutions do not develop every cryptographic component they use. Encryption may be built into cloud services, networking equipment, operating systems, databases, mobile applications, payment terminals, identity platforms, security appliances and vendor-controlled software.
An institution may identify a vulnerable algorithm but remain unable to replace it until the relevant provider releases a supported update.
The problem is particularly important for smaller banks and credit unions. These institutions may outsource much of their core technology and possess limited authority to modify it. Their migration schedule could be dictated by a relatively small group of major service providers.
Vendor-readiness reviews should address questions such as:
- Which cryptographic algorithms does each product use?
- Where are keys created, stored, rotated and revoked?
- Will the existing product support NIST-approved post-quantum standards?
- When will the upgrade become generally available?
- Will customers need new hardware or licensing?
- Can the product support both conventional and post-quantum algorithms during migration?
- How will the vendor test interoperability and performance?
- What happens if a legacy product reaches end of life before migration?
- Will the vendor provide a cryptographic bill of materials?
- Which subcontractors and upstream components create additional dependencies?
Post-quantum readiness is likely to become an increasingly important part of technology procurement, contract negotiations, vendor assessments and operational-resilience reviews.
Workstream Three: Digital Assets Present Distinctive Risks
Treasury’s third workstream will examine digital assets and emerging technology risk.
Cryptographic keys are fundamental to the ownership, transfer and control of many digital assets. If the cryptographic assumptions supporting a blockchain, wallet, smart contract or custody system become vulnerable, the consequences could include unauthorized transactions or disputes over the integrity of the underlying network.
Digital-asset migration can be more complicated than updating software controlled by a single institution. Decentralized networks may require coordination among developers, validators, miners, exchanges, custodians and asset holders.
Participants may disagree over which standard to adopt or how quickly to implement it. Inactive wallets may contain assets controlled by users who cannot be reached. Legacy addresses may remain exposed. A transition could require moving assets, changing signature mechanisms or modifying network rules.
Organizations involved with digital assets should consider:
- Which signature algorithms protect wallets and transactions.
- Whether public keys become visible before or after a transaction.
- How assets would be moved to quantum-resistant addresses.
- Whether hardware wallets can receive secure upgrades.
- How custodians will authenticate migration requests.
- What happens to abandoned or inaccessible wallets.
- Whether smart contracts depend on vulnerable signature schemes.
- How network participants will coordinate protocol changes.
- Whether migration could create opportunities for fraud or social engineering.
The digital-asset workstream recognizes that quantum readiness is not solely a banking problem. It may affect any financial product whose ownership or integrity depends directly on cryptographic proof.
The Task Force Builds on New Federal Deadlines
President Trump’s Executive Order 14412 established a more concrete federal transition program.
The order directs agencies to appoint post-quantum migration leads, review high-value assets and high-impact systems, and develop prioritized migration plans.
For covered federal systems, the order establishes targets to:
- Transition key-establishment functions to post-quantum cryptography by 31 December 2030.
- Transition digital-signature functions by 31 December 2031.
The order also calls for a NIST migration pilot, accelerated validation of cryptographic modules, public guidance describing minimum elements for a cryptographic bill of materials and proposed federal procurement requirements for covered contractors.
These deadlines apply to specified federal systems rather than automatically imposing the same dates on the entire private financial sector. Nevertheless, federal purchasing rules and critical-infrastructure expectations can influence the broader market.
Technology providers may build post-quantum support into standard products rather than maintaining separate federal and commercial versions. Financial institutions may also use the federal dates when setting internal priorities or negotiating vendor roadmaps.
The G7 Roadmap Points Toward a 2035 Transition
Treasury’s task force also builds on the G7 Cyber Expert Group’s January 2026 roadmap for post-quantum migration in the financial sector.
The roadmap does not establish binding regulatory requirements. It describes a risk-based sequence involving assessment, planning, piloting, migration, testing and continuing validation.
The G7 identified 2035 as a general planning target for completing the broader transition to quantum-resistant cryptography, while suggesting that the most critical systems may require attention during the 2030-to-2032 period.
Those dates are not predictions of when a cryptographically relevant quantum computer will become available. They reflect the long lead time required to identify cryptographic dependencies, upgrade products, coordinate institutions and test critical infrastructure safely.
Migration schedules will need to change as quantum capabilities, technical standards and security research develop.
NIST Standards Give Organizations a Place to Begin
The transition is possible because NIST finalized its first three principal post-quantum cryptography standards in 2024:
- FIPS 203, based on ML-KEM, for establishing shared secret keys.
- FIPS 204, based on ML-DSA, as a primary digital-signature standard.
- FIPS 205, based on SLH-DSA, as an alternative digital-signature standard using a different mathematical approach.
NIST has stated that these standards can be put into use now. Their publication moved post-quantum planning from a theoretical discussion toward practical implementation.
Adopting an approved algorithm is not the same as completing a secure migration. Organizations must incorporate the algorithm into protocols, products and workflows without introducing implementation errors or unacceptable performance problems.
New key sizes, signature sizes and computational demands may affect network traffic, storage, hardware and transaction-processing times. Systems built around assumptions from older algorithms may require significant architectural changes.
A Cryptographic Inventory Is the Starting Point
Financial organizations cannot replace cryptography they cannot locate.
Encryption and digital signatures are often embedded deep within infrastructure. A single institution may use thousands of certificates, keys, libraries, protocols and security modules across internally developed systems and third-party products.
A cryptographic inventory should identify:
- The algorithm and protocol being used.
- The application, device or service using it.
- The purpose the cryptography performs.
- The data and business process it protects.
- The system owner and responsible vendor.
- The relevant keys, certificates and expiration dates.
- Whether the component can be upgraded.
- The criticality of the underlying service.
- The required period of confidentiality.
- Connections with external institutions and providers.
This inventory should become a maintained governance resource, not a one-time spreadsheet. New applications, certificates, cloud services and vendor products can continually introduce cryptographic dependencies.
The federal executive order’s planned guidance for a cryptographic bill of materials could help automate this process by creating a more consistent way to describe the cryptographic components contained in hardware and software.
Cryptographic Agility May Matter as Much as the First Upgrade
Treasury has identified cryptographic agility as a central objective of the task force.
Cryptographic agility is the ability to replace algorithms, keys, certificates or cryptographic components without rebuilding an entire system.
That capability matters because the post-quantum transition will not necessarily be the last major cryptographic migration. Researchers may identify weaknesses in an algorithm, implementation or supporting protocol. Standards may evolve as testing continues.
An organization that hard-codes a single post-quantum algorithm throughout its applications could reproduce the same rigidity now making the current migration difficult.
Agile systems should allow authorized teams to change cryptographic configurations, support multiple approved algorithms during transitional periods and respond rapidly when a vulnerability is discovered.
The Migration Itself Can Create Operational Risk
Post-quantum cryptography is intended to reduce future cyber risk, but an improperly managed transition can create immediate problems.
Changing foundational security controls may cause:
- Systems to reject valid certificates or signatures.
- Connected institutions to lose interoperability.
- Applications to experience increased latency.
- Hardware to exceed processing or storage capacity.
- Monitoring tools to misinterpret new protocols.
- Backups or archives to become inaccessible.
- Security teams to maintain vulnerable legacy configurations longer than intended.
- Temporary hybrid environments to be configured incorrectly.
Financial institutions will need testing environments that accurately reproduce real-world transaction volumes and technical dependencies. Migration plans should include rollback procedures, incident response, business-continuity testing and clear decision authority.
A rushed transition could threaten availability. A delayed transition could preserve known long-term exposure. The task force’s objective is to help the sector navigate between those risks.
Quantum Readiness Is Also a Data-Governance Responsibility
Post-quantum preparation should not be limited to cryptography teams.
Privacy, legal and compliance professionals can help identify which information requires long-term protection and which contractual or regulatory obligations could be affected by migration.
Organizations should connect cryptographic inventories with data inventories and retention schedules. A company that does not know where sensitive information is stored, how long it remains valuable or which vendors receive it cannot prioritize quantum risk effectively.
Relevant questions include:
- Which categories of information must remain confidential beyond 2030 or 2035?
- Where is that information transmitted, stored and backed up?
- Which service providers control the relevant encryption?
- Do contracts require vendors to support updated security standards?
- Could archived encrypted data already be vulnerable to collection?
- Can unnecessary historical information be securely deleted?
- How will migration affect access controls and identity verification?
- What evidence will demonstrate that the transition was properly governed?
Data minimization and defensible deletion can reduce the amount of long-lived information that must be protected. Information an organization no longer needs cannot become a future decryption target if it has been securely destroyed.
What Financial Organizations Should Do Now
The Treasury announcement does not create an immediate private-sector mandate, but it provides a clear signal that quantum readiness is becoming part of mainstream financial-sector resilience.
Organizations should begin taking practical steps:
- Assign executive and technical responsibility for post-quantum planning.
- Build and maintain an inventory of cryptographic assets.
- Identify information that must remain confidential for many years.
- Prioritize critical payments, identity, authentication and market systems.
- Ask vendors for specific post-quantum product roadmaps.
- Include upgrade rights and cryptographic disclosures in new contracts.
- Assess legacy technology that cannot support modern algorithms.
- Test NIST-approved standards in controlled, lower-risk environments.
- Design applications for cryptographic agility.
- Coordinate migration plans with counterparties and infrastructure providers.
- Integrate post-quantum scenarios into operational-resilience exercises.
- Document risk decisions, testing results and unresolved dependencies.
Quantum Readiness Is Becoming a Present-Day Control
Treasury’s task force reflects a significant change in how the government and financial industry are treating quantum risk.
The question is no longer whether organizations should eventually prepare. The focus is shifting toward how institutions can inventory cryptography, prioritize critical systems, coordinate vendors and complete the transition without disrupting essential financial services.
No one can identify the exact date on which a quantum computer will become capable of defeating widely deployed public-key cryptography. Financial institutions do know that replacing foundational security mechanisms across a global and heavily interconnected system will take years.
The organizations best positioned for that transition will not necessarily be those that attempt to replace everything immediately. They will be the institutions that understand their cryptographic dependencies, know which data and systems matter most, demand credible plans from vendors and build the technical agility to respond as standards and threats evolve.
Treasury’s Quantum-Readiness Task Force is designed to turn those individual preparations into a coordinated financial-sector strategy. Its success will depend on whether the initiative produces measurable progress before quantum risk moves from a long-term warning to an immediate security problem.