Charlie Quant Lab
All research
Quantum readiness for finance

Change the locks.Before the clock runs out.

See which financial systems need new encryption first, and which official date each team should plan around.

The work is a relay.Each team must pass a tested system to the next stage without breaking payments or access.

FindLocate old encryption
RankPut critical systems first
TestCheck real traffic
ReplaceRetire the old route
2030first major deadline cluster
2035wider finish target in several plans
What this page does

It compares official migration dates, separates plans that cover different groups, and shows what a finance team should change first.

The useful date is not the quantum date.

Nobody knows exactly when a powerful quantum computer will arrive. Finance teams do know that replacing old encryption across suppliers can take years.

5official plans checked, each with a different scope
2030

The first deadline cluster

Australia targets completion, while the EU points its highest-risk uses toward the same year.

3

New standards are available

NIST published standards for secure connections and digital signatures. Testing can begin now.

6

Financial systems to inspect first

Customer connections, payments, software updates, stored records, hardware security and blockchain keys need separate plans.

G7

Finance has a common direction

The G7 plan lines up work across firms and suppliers. It is guidance, not a binding rule.

These words do not mean the same thing

GuidanceA recommended path. It is not automatically a law.
RoadmapA dated programme for a named group or country.
StandardA technical replacement that systems can use.

Do not compare the dates without comparing who they cover. A federal government timetable, security guidance for large organisations and a technical standards programme carry different force.

Five plans. One direction.

Find every affected system, change the most important ones first, then finish the rest. The dates and the covered groups differ.

Australia

National guidance
Who it covers

Government guidance for organisations

Recommended planning path
Official plan

Canada

Government roadmap
Who it covers

Federal government systems

Department schedule
Official plan

United Kingdom

Security guidance
Who it covers

Large organisations and critical infrastructure

Recommended security timetable
Official plan

European Union

Coordinated roadmap
Who it covers

Public bodies and critical infrastructure

Member-state target
Official plan

United States

Standards programme
Who it covers

Federal standards with wider industry use

Technical standards and deprecation plan
Official plan

What needs changing?

Quantum-safe encryption means new digital locks designed to resist future quantum computers. Open a system to see who must act first.

Customer connectionsThe secure connection used by websites, apps and outside services.
Who must move

Application, network and cloud teams

First useful action

List certificates, connection libraries and outside gateways.

Payment messagesThe signed instructions that tell money where to move.
Who must move

Payments, security and network partners

First useful action

Map every signer, certificate and outside network in the payment path.

Software updatesThe digital signature that proves new code is genuine.
Who must move

Engineering and software suppliers

First useful action

Find code-signing keys and ask when each build tool will support the new standards.

Stored recordsData that must remain private for years, even if it is copied today.
Who must move

Data, legal, security and cloud teams

First useful action

Start with records whose useful life is longer than the migration window.

Hardware securityMachines and cards that store keys and approve important actions.
Who must move

Security, procurement and hardware vendors

First useful action

Record model, support date, replacement date and supplier upgrade path.

Blockchain signing keysKeys that approve wallet, custody, validator and contract-admin actions.
Who must move

Custody, protocol and infrastructure teams

First useful action

Separate keys that can be rotated from contracts or addresses that cannot change easily.

A visible slice of value controlled by blockchain keys$305.2bntracked across 174 networks through 2026-09-19

This is an example, not the total exposure.

Blockchain signatures control wallets, custody approvals, validators and contract-admin actions. Those paths do not all change in the same way.

What the number cannot tell us: it does not show which keys are vulnerable, how long they remain in use, or which systems are hard to upgrade.

The new locks do different jobs.

Secure connections and digital signatures are separate tasks. One replacement cannot cover both.

FIPS 203

ML-KEM

Creates a shared secret for a secure connection.

NIST source
FIPS 204

ML-DSA

Signs data so a receiver can verify who sent it.

NIST source
FIPS 205

SLH-DSA

A second kind of digital signature built from hash functions.

NIST source

What can change in 90 days?

The first quarter is about making the work visible and stopping new systems from adding more old encryption.

Name an owner

Give one person authority

One executive needs the budget and power to coordinate the change.

Find the first 20

List critical systems

Record important keys, certificates, suppliers and the systems that use them.

Change buying rules

Ask suppliers for dates

New products should support approved quantum-safe upgrades.

Run one test

Learn what breaks

Move a non-critical connection through a new standard and record the result.

The main risk is waiting. Replacing old encryption will take years even if the exact quantum threat date remains unknown.

Read the official plans.

The checked date applies to the roadmap summary. Each link opens the organisation that published the plan.

The G7 published a common financial-sector roadmap. It is guidance, not a binding rule. Read the G7 plan.

Research by for Charlie Quant Lab ยท Updated