The first deadline cluster
Australia targets completion, while the EU points its highest-risk uses toward the same year.
See which financial systems need new encryption first, and which official date each team should plan around.
The work is a relay.Each team must pass a tested system to the next stage without breaking payments or access.
It compares official migration dates, separates plans that cover different groups, and shows what a finance team should change first.
Nobody knows exactly when a powerful quantum computer will arrive. Finance teams do know that replacing old encryption across suppliers can take years.
5official plans checked, each with a different scopeAustralia targets completion, while the EU points its highest-risk uses toward the same year.
NIST published standards for secure connections and digital signatures. Testing can begin now.
Customer connections, payments, software updates, stored records, hardware security and blockchain keys need separate plans.
The G7 plan lines up work across firms and suppliers. It is guidance, not a binding rule.
Do not compare the dates without comparing who they cover. A federal government timetable, security guidance for large organisations and a technical standards programme carry different force.
Find every affected system, change the most important ones first, then finish the rest. The dates and the covered groups differ.
Government guidance for organisations
Recommended planning pathNext: Have a detailed transition plan by the end of 2026.
Later: Start critical systems by 2028 and complete the transition by 2030.
Federal government systems
Department scheduleNext: The first departmental plans were due in April 2026, followed by annual progress reports.
Later: High-priority systems by 2031; remaining systems by 2035.
Large organisations and critical infrastructure
Recommended security timetableNext: Find every affected system and complete the first migration plan by 2028.
Later: Protect the highest-priority systems by 2031; complete migration by 2035.
Public bodies and critical infrastructure
Member-state targetNext: Move the highest-risk uses first, no later than 2030.
Later: The coordinated roadmap points the wider transition toward 2035.
Federal standards with wider industry use
Technical standards and deprecation planNext: Move high-risk systems earlier and begin using the new NIST standards now.
Later: Quantum-vulnerable algorithms are set to leave NIST standards by 2035.
Quantum-safe encryption means new digital locks designed to resist future quantum computers. Open a system to see who must act first.
Application, network and cloud teams
List certificates, connection libraries and outside gateways.
Payments, security and network partners
Map every signer, certificate and outside network in the payment path.
Engineering and software suppliers
Find code-signing keys and ask when each build tool will support the new standards.
Data, legal, security and cloud teams
Start with records whose useful life is longer than the migration window.
Security, procurement and hardware vendors
Record model, support date, replacement date and supplier upgrade path.
Custody, protocol and infrastructure teams
Separate keys that can be rotated from contracts or addresses that cannot change easily.
Blockchain signatures control wallets, custody approvals, validators and contract-admin actions. Those paths do not all change in the same way.
Secure connections and digital signatures are separate tasks. One replacement cannot cover both.
Creates a shared secret for a secure connection.
NIST sourceSigns data so a receiver can verify who sent it.
NIST sourceA second kind of digital signature built from hash functions.
NIST sourceThe first quarter is about making the work visible and stopping new systems from adding more old encryption.
One executive needs the budget and power to coordinate the change.
Record important keys, certificates, suppliers and the systems that use them.
New products should support approved quantum-safe upgrades.
Move a non-critical connection through a new standard and record the result.
The main risk is waiting. Replacing old encryption will take years even if the exact quantum threat date remains unknown.
The checked date applies to the roadmap summary. Each link opens the organisation that published the plan.
The G7 published a common financial-sector roadmap. It is guidance, not a binding rule. Read the G7 plan.
Research by Ananda Banerjee for Charlie Quant Lab ยท Updated