🔐 Post-Quantum Cryptography
Post-quantum cryptography (PQC) is the field of cryptography focused on protecting digital systems against future attacks from sufficiently powerful quantum computers.
Unlike the broader QFS concept, post-quantum cryptography is a documented technical and standards-development field. It is already moving from research into implementation.
⚛️ Why Quantum Computers Matter to Cryptography
Modern financial and digital infrastructure relies heavily on public-key cryptography for authentication, key establishment and digital signatures.
A sufficiently capable cryptographically relevant quantum computer could threaten some widely used public-key cryptographic systems.
This creates a long-term security challenge for systems that may need to remain secure for many years.
🔑 What Is Post-Quantum Cryptography?
PQC uses cryptographic algorithms designed to resist attacks from both conventional computers and future quantum computers.
The important point is that PQC does not require a quantum computer to operate. Quantum-resistant algorithms can run on conventional computing infrastructure.
This makes PQC different from technologies such as quantum key distribution, which use quantum communication techniques.
📐 NIST Standards
On August 13, 2024, NIST finalized its first three Post-Quantum Cryptography standards:
- FIPS 203 — Module-Lattice-Based Key-Encapsulation Mechanism (ML-KEM).
- FIPS 204 — Module-Lattice-Based Digital Signature Standard (ML-DSA).
- FIPS 205 — Stateless Hash-Based Digital Signature Standard (SLH-DSA).
These standards cover key establishment and digital signatures and form the foundation of NIST's initial PQC standardization effort.
🧬 HQC
On March 11, 2025, NIST selected HQC for standardization as an additional post-quantum encryption algorithm.
HQC is intended to provide an additional encryption option and a backup to ML-KEM for general encryption.
The standardization process remains active, with NIST evaluating additional digital-signature candidates and developing further guidance.
🔄 The Migration to PQC
Moving to post-quantum cryptography is not simply a matter of installing a new algorithm.
Organizations need to identify where vulnerable cryptography is used across hardware, software, networks, services and stored data.
This process is commonly described as a cryptographic inventory followed by prioritization, testing, migration and validation.
NIST's migration work also emphasizes the importance of being able to replace cryptographic algorithms without redesigning an entire system.
🔄 Cryptographic Agility
Cryptographic agility means that a system can replace or adapt cryptographic algorithms while maintaining security and operational continuity.
This becomes increasingly important because cryptographic standards can evolve, vulnerabilities can be discovered and different systems may require different migration schedules.
NIST published guidance on cryptographic agility in December 2025 as part of its work supporting the transition to PQC.
🏦 Financial Infrastructure
Financial institutions are particularly exposed to the complexity of cryptographic migration because modern financial infrastructure depends on large numbers of interconnected systems.
These can include payment systems, banking platforms, custody infrastructure, digital identities, secure communications, market infrastructure and third-party services.
A transition therefore needs to consider interoperability, performance, operational resilience and dependencies beyond a single institution.
🏛️ Financial-Sector Quantum Readiness
The Bank for International Settlements has identified quantum readiness as a financial-sector issue and has recommended beginning preparations before cryptographically relevant quantum computers become available.
Its roadmap emphasizes cryptographic inventories, cryptographic agility, defence in depth, hybrid approaches and phased migration.
The BIS has also tested post-quantum cryptography in payment-system infrastructure through Project Leap Phase 2, demonstrating practical migration issues including compatibility, performance and interoperability.
💳 Payments and Settlement
Payment systems are an important part of the quantum transition because digital signatures and other cryptographic mechanisms protect transactions and communications.
Project Leap Phase 2 tested replacing traditional digital signatures with post-quantum cryptography while processing liquidity transfers.
The experiment demonstrated that quantum-safe migration involves changes across multiple components rather than a simple substitution of one algorithm.
💠 Digital Assets
Digital-asset infrastructure also depends on cryptographic algorithms, particularly for digital signatures, wallets, identity and transaction authorization.
The potential quantum threat therefore extends beyond traditional banks to exchanges, custody systems, blockchains and other digital-asset infrastructure.
Whether a particular blockchain or digital asset is quantum-resistant must be evaluated from its actual cryptographic design and migration capabilities rather than from its association with the QFS narrative.
🕰️ Harvest Now, Decrypt Later
One reason organizations are preparing before powerful quantum computers exist is the possibility of harvest-now, decrypt-later attacks.
An attacker may capture encrypted information today and attempt to decrypt it in the future if a sufficiently capable quantum computer becomes available.
This is particularly relevant for information that must remain confidential for many years.
🌐 PQC and the QFS Concept
Post-quantum cryptography is sometimes presented in QFS discussions as evidence that a Quantum Financial System is already being deployed.
The documented evidence supports a narrower conclusion: governments, standards organizations, financial institutions and technology providers are preparing for the potential security implications of quantum computing.
This is significant in its own right, but it does not establish that a global QFS exists or is operational.
📌 Current Status
PQC has moved beyond purely theoretical research. Standards have been finalized, additional algorithms are being standardized and organizations are beginning migration projects.
At the same time, the transition is a long-term infrastructure project. Financial systems need to account for compatibility, performance, governance, cryptographic inventory and the ability to adapt as standards evolve.
🔬 Sources and Further Research
NIST maintains the primary U.S. post-quantum cryptography standardization and migration resources. The BIS provides financial-sector research and practical quantum-readiness work.
See also Quantum Finance for financial applications of quantum computing and QFS Concept for the distinction between documented technology and QFS claims.
