G7 presses finance sector on quantum-safe crypto shift

The G7 Cyber Expert Group has published a roadmap calling on financial institutions and national authorities to accelerate preparation for a transition to quantum-safe cryptography, warning that emerging quantum computers could eventually render today’s public-key algorithms obsolete.[9][13][15]

Released in mid-January 2026 by cyber authorities and central banks across the G7, the statement outlines key considerations for banks, regulators and vendors as they plan the migration to post-quantum cryptographic solutions in a coordinated, timely way.[9][12][13] The roadmap is explicitly non-binding and does not set regulatory expectations, but is aimed at informing senior leaders about activities that can reduce future quantum risk and support supervisory dialogue.[12][15] Signatories include the U.S. Department of the Treasury, the Bank of England, and other G7 finance ministries and central banks that jointly oversee cyber resilience in the financial sector.[9][13][14]

The G7 guidance closely tracks technical progress at the U.S. National Institute of Standards and Technology (NIST), which finalized its first three post-quantum cryptography standards in August 2024 as FIPS 203 (ML-KEM), FIPS 204 (ML-DSA) and FIPS 205 (SLH-DSA).[3][8][11] Under NIST’s transition plan, quantum-vulnerable algorithms such as RSA and elliptic-curve cryptography will be deprecated from federal standards by around 2035, with high-risk systems expected to migrate earlier.[8][4] The G7 roadmap recommends that critical financial systems and high-value assets complete their transition to quantum-safe cryptography between 2030 and 2032, with non-critical environments following by roughly 2035.[13][1]

Authorities frame the issue through the lens of “harvest now, decrypt later” attacks, in which adversaries record encrypted traffic today with the expectation that future quantum capabilities will allow retrospective decryption of sensitive data.[2][5] Long-lived data such as financial records, payment messages and authentication logs are particularly exposed, because they must remain confidential for decades even as cryptographic primitives age.[2][10] Standards bodies including ETSI and national cybersecurity agencies in Europe have warned that organizations should start inventorying classical cryptography and planning quantum-safe replacements well before large-scale quantum computers become practical.[2][5][10]

The new G7 statement urges boards and senior executives to treat post-quantum migration as a strategic program, including designating accountable leadership, securing dedicated funding and setting multi-year roadmaps.[1][9] It calls on financial entities to map where cryptography is used across networks and applications, prioritize systems with the highest systemic impact or data sensitivity, and engage closely with vendors to understand when quantum-safe options will be available in commercial products.[1][12][13] Supervisory authorities are encouraged to develop their own expectations and assessment approaches, including how they will evaluate firms’ quantum-risk management and migration planning.[12][15]

For defenders, the roadmap underscores that there is no single CVE or immediate exploit driving the push toward quantum-safe cryptography, but rather a long-term structural risk to the confidentiality guarantees of widely deployed public-key systems.[2][8] Security teams in banks and market infrastructures are being advised to start with cryptographic asset inventories, threat modelling around long-lived data, and pilot deployments of NIST-selected algorithms in non-critical environments.[1][3][8] While specific regulatory mandates have yet to be issued, the G7’s coordinated messaging signals that supervisors are likely to expect tangible progress on post-quantum migration throughout the 2030s, even as standards and implementations mature.[9][12][13]

References

  1. G7 Cybersecurity Working Group Statement on preparing …
  2. [PDF] Quantum Safe Cryptography and Security – ETSI
  3. NIST Post-Quantum Cryptography Timeline: 2016-2026
  4. Workshops and Timeline – Post-Quantum Cryptography
  5. [PDF] Quantum-safe cryptography – BSI
  6. Post-Quantum Cryptography (PQC)
  7. G7 Cyber Expert Group Releases Roadmap for …
  8. ETSI TC CYBER Quantum-Safe Cryptography Update
  9. NIST Post-Quantum Cryptography Timeline
  10. G7 CEG quantum roadmap
  11. The G7 Cyber Expert Group publishes the roadmap for …
  12. G7 Cyber Expert Group Statement on Advancing a …
  13. Advancing a Coordinated Roadmap for the Transition to …

Comments

No comments yet. Why don’t you start the discussion?

Leave a Reply