Cybersecurity · Last updated

Post-Quantum Cryptography for Financial Firms

Quantum computers cannot break today's encryption yet, but data taken now can be read later. NIST standards, NCSC milestones and a migration plan.

Nerdster Team

No quantum computer can break your encryption today. Your RSA and elliptic curve keys are safe this morning, and they will be safe next year.

So why are we writing to you about post-quantum cryptography now? Because the data you send today can be copied today and decrypted later. If your client records, deal files, and research stay sensitive for a decade, then the clock that matters started some time ago.

This is a planning problem rather than an emergency, and the firms who treat it as planning will spend far less than the ones who leave it. Here is what to weigh up, and what to start.

Why harvest-now-decrypt-later makes this urgent

Adversaries with patience and storage are already intercepting encrypted traffic and keeping it. They cannot read it yet. They expect to.

Look at your own data and ask how long each type stays sensitive:

  • Client personal data stays sensitive for the life of the relationship and beyond. GDPR does not expire.
  • Trading strategies and proprietary research hold commercial value for five to ten years.
  • M&A communications and deal files stay sensitive long after completion.
  • Regulatory correspondence can matter indefinitely.

Now overlay the timeline. If a cryptographically relevant quantum computer arrives in ten to fifteen years — within the range of credible expert estimates — then anything captured today with a longer sensitivity window is already exposed. You just will not know about it for a while.

The National Cyber Security Centre published migration timelines for exactly this reason in March 2025, with three milestones:

  • By 2028 — define your migration goals, carry out a full discovery exercise and build an initial migration plan
  • By 2031 — carry out your early, highest-priority migration activities and refine the plan into a thorough roadmap
  • By 2035 — complete migration to post-quantum cryptography across all your systems, services and products

Read 2035 as a deadline with three parliaments in it, not a distant curiosity. The NCSC aims these timelines mainly at large organisations, critical national infrastructure and firms with bespoke IT. For smaller firms running standard products, it expects migration to be more straightforward, arriving as vendors update their services — which is why the vendor conversations below matter so much.

The NIST post-quantum standards

Post-quantum cryptography means algorithms that hold up against both classical and quantum attack. In August 2024 the US National Institute of Standards and Technology published its first three:

  • ML-KEM (FIPS 203) — from CRYSTALS-Kyber, for key encapsulation, which is how encrypted connections get established
  • ML-DSA (FIPS 204) — from CRYSTALS-Dilithium, for digital signatures
  • SLH-DSA (FIPS 205) — from SPHINCS+, a hash-based signature scheme

A fourth, FN-DSA, based on FALCON, is still being finalised as FIPS 206. And in March 2025 NIST selected HQC as a backup to ML-KEM, built on different mathematics, with a final standard expected in 2027.

They are designed as drop-in replacements. In practice, dropping them in means testing and validating across every system you own, which is why you start early rather than fast.

A post-quantum cryptography migration in six moves

These are the considerations we work through with a financial services firm before moving to post-quantum cryptography. Take them as best practices for adopting PQC in a running business, in the order that costs you least.

1. Find every place you use cryptography

You cannot migrate what you cannot see. Catalogue where cryptography does work for you:

  • Data in transit — TLS for web, email, APIs, VPN tunnels, and service-to-service traffic
  • Data at rest — disk, database, backup, and archive encryption
  • Authentication — certificates, code signing, secure boot
  • Third parties — the cryptographic dependencies in your links to prime brokers, fund administrators, market data providers, and cloud platforms

The inventory tells you the size of the job, and it usually finds two or three systems nobody had on the list.

2. Rank your data by how long it stays sensitive

Not everything needs the same urgency. Sort it:

  • High — sensitive for 10+ years: client PII, proprietary strategies, regulatory records
  • Medium — three to ten years: financial reports, internal communications, operational data
  • Low — short windows: published information, marketing material

This is what turns an overwhelming migration into a sequenced one.

3. Ask your vendors for their PQC roadmap

Most of the heavy work will be done for you, by Microsoft, your VPN vendor, your backup provider, and your trading platform. Your job is to know when. Ask each of them:

  • What is your post-quantum migration roadmap?
  • Which products support PQC algorithms today?
  • When will it reach the versions we run?
  • What will we have to change on our side?

The ecosystem is already moving. Chrome turned on hybrid post-quantum key exchange by default on desktop in version 124, and moved to the standardised ML-KEM in version 131. Signal has protected messaging with PQC since 2023. Microsoft brought ML-KEM and ML-DSA to Windows 11 and Windows Server 2025 in its November 2025 updates. Vendor timelines still vary widely, which is exactly why you ask rather than assume.

4. Build in the ability to swap algorithms later

Crypto-agility means changing cryptographic algorithms without rebuilding everything around them. In practice:

  • Keep cryptographic parameters out of your application code
  • Use libraries and frameworks that negotiate algorithms rather than fixing them
  • Run certificate management that can handle PQC certificate formats
  • Test hybrid configurations that use classical and PQC algorithms together

Test for size as well as compatibility. Post-quantum keys, ciphertexts and signatures are considerably larger than today’s elliptic-curve equivalents, and larger handshakes are where network kit tends to trip. When Chrome 124 switched hybrid key exchange on, some servers and middleboxes that did not implement TLS correctly broke connections because they could not handle the bigger opening message. Check your firewalls, proxies and inspection appliances before your vendors flip the switch for you.

This is worth doing whatever quantum computing does next. It also protects you if a weakness turns up in a classical algorithm, and it gives you clean ISO 27001 evidence for your cryptographic controls.

5. Track what your regulators are signalling on quantum risk

Financial authorities are signalling direction rather than setting hard UK rules, but the direction is consistent:

  • The NCSC wants discovery and an initial plan done by 2028, highest-priority migration by 2031 and everything migrated by 2035
  • The G7 Cyber Expert Group, which advises G7 finance ministers and central bank governors, published a roadmap for the financial sector in January 2026 that points to 2035 overall and 2030–32 for the most critical systems — while stating plainly that it does not set guidance or regulatory expectations
  • The FCA’s Cyber Coordination Group insights, published in April 2026, describe PQC migration as important and recommend prioritising it with a risk-based approach, built on good cryptographic hygiene; the FCA frames these as insights, not new expectations
  • Under DORA, the ICT risk management technical standards require an EU financial entity’s encryption policy to provide for updating its cryptographic technology as cryptanalysis develops, and name threats from quantum advancements — relevant if you are in scope or serve EU financial entities
  • The ECB told the CEOs of the significant banks it supervises in July 2026 that adoption of post-quantum cryptography “must start now and necessitates sustained, strategic investment over time”, and said it will address quantum risk in a separate letter

Expectations will firm up as the standards mature and vendor support broadens. Being able to show a plan is most of the answer.

6. Protect your most sensitive data today

For the data most likely to be harvested now and read later, act before the migration:

  • Use the strongest encryption available today, AES-256 for symmetric
  • Turn on hybrid TLS where your platforms support it
  • Delete what you do not need to keep, so there is less to harvest
  • Review network security, so interception is harder in the first place

A realistic post-quantum migration timeline

For a typical London financial services firm, a sensible sequence built around the NCSC’s milestones looks like this:

Now to 2028 — Complete your cryptographic inventory. Classify data by sensitivity. Start vendor conversations and add PQC readiness to your procurement requirements. Apply crypto-agility principles to anything you build new.

2028–2031 — Test PQC-enabled products and configurations outside production, then move your highest-priority systems, the ones carrying long-lived sensitive data, to hybrid classical-plus-PQC configurations.

2031–2035 — Move the remaining systems as vendor support matures, and retire the quantum-vulnerable algorithms.

That aligns with NCSC guidance and allows for the reality that interoperability testing always takes longer than the plan says.

Start your migration to post-quantum cryptography

We help London financial services firms work through the post-quantum transition at a pace that matches their risk: the cryptographic inventory, the vendor conversations, and the crypto-agile architecture that makes the eventual switch routine. It is practical cybersecurity work, not a research project.

If you want to know where your firm stands on quantum readiness, book a free IT assessment with Nerdster. You will come away with a clear picture of your position and a roadmap you can actually follow.


Sources: NCSC, “Timelines for migration to post-quantum cryptography” (March 2025), ncsc.gov.uk; NIST, FIPS 203, 204 and 205 (August 2024) and “NIST selects HQC as fifth algorithm for post-quantum encryption” (March 2025), nist.gov; G7 Cyber Expert Group, “Advancing a Coordinated Roadmap for the Transition to Post-Quantum Cryptography in the Financial Sector” (January 2026); FCA, “Cyber Coordination Group insights 2025” (April 2026), fca.org.uk; Commission Delegated Regulation (EU) 2024/1774, Article 6, eur-lex.europa.eu; ECB Banking Supervision, letter to significant institutions on AI-enabled cybersecurity threats (7 July 2026); Microsoft Security blog, “Post-quantum cryptography APIs now generally available on Microsoft platforms” (November 2025). Checked 23 September 2026.

quantumcryptographyfinancial servicesPQC

Related insights

Talk to our team about your IT

Tell us what you need. Our London team replies within 2 hours during business hours.

We respond within 2 hours during business days. Your data is handled per our privacy policy.

Contact details

IT assessment

A review of your IT, your security posture and your compliance readiness, free of charge.

  • 30-minute consultation call
  • Infrastructure & security review
  • Compliance gap analysis
  • Custom recommendations report