• Home
  • Blog
  • Q&A
  • Quantum Experts Forum
  • Glossary
  • Contact Us
  • More
    • Home
    • Blog
    • Q&A
    • Quantum Experts Forum
    • Glossary
    • Contact Us

  • Home
  • Blog
  • Q&A
  • Quantum Experts Forum
  • Glossary
  • Contact Us

This Week's Expert Blog Post

Quantum Risk Is Global. Why Isn’t Financial Regulation?

August 24, 2026 

 

I was recently asked if financial regulators, such as the international Financial Stability Board (FSB), the European Central Bank (ECB), the U.S. Securities and Exchange Commission (SEC), or the UK Financial Conduct Authority (FCA), are coordinating on quantum-resistant security measures for the finance industry.  


The question caught me off-guard as it is such an obvious and innocent question to ask, and the short answer being “no” may well raise some eyebrows in Wall Street boardrooms.  


Finance is one of the first industries to benefit from quantum technologies. The 2026 McKinsey quantum technology monitor puts the value of use cases for optimization, risk modeling, and cryptography security in 2035 somewhere between $400B up to $600B. This represents a 3 - 4.5 % potential positive impact for financial firms.  


Finance is also the top target for bad actors. Direct and indirect cases of quantum-assisted fraud and other cybercrimes, such as breaking key exchange and decrypting captured traffic,and  forging signatures, certificates, or blockchain wallet keys, could result in heavy losses, loss of trust, even bankruptcies. 


The two relevant, commercially mature technologies for securing financial assets and transactions are QKD and PQC. Because Quantum Key Distribution - QKD - requires expensive, dedicated point-to-point fiber optic cables, PQC - Post Quantum Cryptography - remains the practical choice. Companies are looking to migrate towards PQC but are facing a patchwork of requirements.  


So, if the situation is so dire, why aren’t these regulatory bodies hurling out industry-wide policies and recommendations? The answer is, as we say here in France “c'est compliqué” - it’s complicated. 

First, there’s the lack of unified global standards. While NIST (National Institute of Standards and Technology) finalized its first PQC standards already back in 2024, these remain U.S. focused. The NIST standards serve as a foundation for others to build upon, being the current ‘de-facto’ reference point. However, as other standards bodies - including ISO/IEC and IETF - are just catching up, there is no single, binding ‘de-jure’ international standard for PQC.  


Cybersecurity agencies such as ETSI, ENISA, or UK’s NCSC have published PQC roadmaps and phased adoption timelines, but these remain voluntary and non-binding. 


Second, the lack of jointly approved global standards means the regulators are scrambling. If quantum researchers and business leaders haven’t agreed on common terminologies, or defined the reference frameworks, architectures, interfaces and best practices, how would regulators be able to take action?  


There are specific, regional approaches, such as the the SEC’s Post-Quantum Financial Infrastructure Framework citing PQC case studies, the ECB’s enforcement of quantum risk management and cryptographic migration via the Digital Operational Resilience Act (DORA), aligning with NIST standards, and the FCA referencing UK National Cyber Security Centre (NCSC) guidance. None of these regulators have yet issued mandatory PQC migration rules for their regulated entities. 

While standards’ bodies and regulators scramble to guide the finance industry in its preparation towards PQC, the quantum industry steps in to offer support. Industry consortia such as QED-C and QuIC host working groups, publish white papers, and webinars on PQC migration, and the 2026 Year of Quantum Security initiative raises awareness on the path from classical, to hybrid, to PQC algorithms. 


Regulators aren’t completely resting on their laurels, either. The ‘harvest now, decrypt later’ threat drives regulators to encourage proactive migration, even without formal mandates. There is some emerging alignment around referencing NIST’s PQC standards and ETSI/ENISA guidelines, suggesting a de facto convergence around these frameworks. 


If the quantum industry is concerned about financial institutions self-regulating based on a patchwork of expectations, it might be a good strategy to work on the root cause and contribute to global standards. You may even end up declaring your IP as an essential patent to a global standard in the process. 


By Petra Soderling 

Brought to you by HKA

Powered by GoDaddy

This website uses cookies.

We use cookies to analyze website traffic and optimize your website experience. By accepting our use of cookies, your data will be aggregated with all other user data.

Accept