Skip to content

Leadership1 publisher3 min readPublished

NIST sets 2030 and 2035 retirement dates for quantum-vulnerable algorithms, raising stakes for banks

Post-quantum standards were finalised in August 2024, and NIST means to phase out most quantum-vulnerable algorithms by 2035. For banks the harder problem is finding every place RSA and ECC are written into application code.

The Board Room · Leadership desk

Illustration accompanying NIST sets 2030 and 2035 retirement dates for quantum-vulnerable algorithms, raising stakes for banks

What happened

  • NIST finalised the first three post-quantum standards in August 2024, covering ML-KEM for key exchange and ML-DSA and SLH-DSA for digital signatures.
  • CISA, the NSA and NIST jointly urge critical-infrastructure operators, financial services included, to build a cryptographic inventory now, warning that adversaries may already be harvesting data.
  • Post-quantum cryptography runs on classical hardware and slots into TLS and IPsec, so no institution has to own quantum technology to deploy it.

Compiled by The Board RoomSomething wrong?How this is made

Why it matters

  • exposure Every loan agreement and regulatory archive that crossed a network under RSA is already collectable, so the deadline for long-retention records runs backwards from the day the data moved.
  • constraint NIST holding HQC in reserve tells a CIO the first migration is not the last one, so a re-keying that leaves algorithms hard-coded buys a single swap and no ability to do the next.
  • decision A board that wants to answer quantum risk with capex can buy quantum key distribution, and it will get point-to-point fibre links that cannot serve payment rails; the honest spend is engineering time.
  • contradiction The column is headlined as a mandate on financial institutions, yet the dated obligations it musters belong to national security systems and to a standards calendar. That leaves bank timing to retention law and internal budget.

The expensive part of this program sits inside applications. Systems that call cryptography through centrally managed libraries can swap one algorithm for another as findings arrive; systems with the algorithm written into them are the hardest to move [9]. "Legacy applications often bury cryptographic parameters deep in source code, turning a configuration change into a rewrite," Kipker wrote [10]. He called that the most underestimated part of the work, drawing on assessments he has run at several institutions [11]. The column gives no figure for how many bank systems fall on either side of that line.

Anyone can check the dates. Counted from the column's publication in September 2026 [19], NIST's retirement of the weakest quantum-vulnerable algorithms after 2030 is about four years out, and the 2035 phase-out of most others about nine [20]. Counted from the August 2024 standards instead, the window runs about eleven years [21]. FS-ISAC, which represents financial institutions and infrastructure globally, has warned about "crypto-procrastination," arguing that treating quantum as a distant risk could leave organisations scrambling to complete a transition that will take years [17].

Nothing in this record fines a bank. The dated mandate is CNSA 2.0, and it addresses national security systems, telling them to move off RSA, Diffie-Hellman and elliptic-curve cryptography [15]. The joint guidance from CISA, the NSA and NIST urges an inventory and a road map [16]. What binds earlier than any supervisor is retention. Under harvest-now-decrypt-later, a loan agreement or regulatory archive that has to stay confidential for a decade is exposed from the moment it crosses a network, whether or not a capable machine exists yet [12].

The source gets most practical on sequencing. A hybrid handshake pairs a classical algorithm with a post-quantum one, and the connection holds as long as either of them holds [13]. TLS 1.3 carries this in production, Google turned it on by default in Chrome in 2020, and major cloud providers did the same [14]. Kipker wrote that institutions do not need full market maturity before piloting hybrid deployments on their most exposed interfaces [25]. External TLS can start while the inventory is unfinished. Kipker put the harder work in the decades-old, interdependent stacks behind payments, core banking and long-lived customer records [24][1].

The record here is one column by a named expert, published under the Forbes Technology Council banner [2], headlined as a claim that post-quantum cryptography is becoming mandatory for financial institutions [23]. The dated obligations it cites belong to national security systems and to NIST's own deprecation calendar, and no banking supervisor's deadline appears in it [22]. The standards clock and the harvest-now exposure are documented; what the column does not give is the cost of re-keying inside any one institution.

What to watch

  • A dated instruction from a banking supervisor, as distinct from NIST or the NSA, would convert the standards calendar into a compliance deadline.
  • A published weakness in lattice-based schemes would move HQC from hedge to substitute and reopen algorithm choices already made.
  • The specific dates on which CNSA 2.0 becomes mandatory, which the column leaves as "the coming years".
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories