Quantum compliance is the governance work of finding every place a firm depends on public-key cryptography that a quantum computer could one day break, and preparing to replace it in an order a supervisor could follow.
What quantum compliance means
Quantum compliance is not a regulatory term, and we are not aware of any rulebook that uses it. Nor are we aware of any United States financial regulator that has set a date by which a private firm must complete its migration. It is the name Taft uses for a set of duties that already exist, applied to a risk that is still taking shape: the public-key algorithms that protect a firm’s data in transit, its signatures, its certificates and its stored records are expected to fail against a sufficiently large quantum computer. That machine does not exist today. The standards to prepare for it do.
The technical target is set by NIST. NIST published FIPS 203, FIPS 204 and FIPS 205 on August 13, 2024. NIST followed with a draft of report 8547 on November 12, 2024. The report describes NIST’s expected approach to transitioning from quantum-vulnerable cryptographic algorithms to post-quantum digital signature algorithms and key-establishment schemes. NIST has kept the documents moving since, with planning notes and errata posted through 2025 and 2026, which is covered below.
For a compliance officer, the useful framing is this: the cryptography question has been answered by NIST, and the inventory, vendor, governance and evidence questions are open. Those are the questions a firm can start answering before anyone requires it to.
Quantum compliance is an inventory problem before it is a cryptography problem.
The standards that define the target
There are three standards and one draft transition report a firm should know by name.
FIPS 203 specifies a key-encapsulation mechanism called ML-KEM. A key-encapsulation mechanism is a set of algorithms that two parties can use to establish a shared secret key over a public channel, and that shared secret can then be used with symmetric-key algorithms for encryption and authentication. The security of ML-KEM rests on the computational difficulty of the Module Learning with Errors problem. NIST states that ML-KEM “is believed to be secure, even against adversaries who possess a quantum computer.” FIPS 203 specifies three parameter sets, ML-KEM-512, ML-KEM-768 and ML-KEM-1024, in order of increasing security strength and decreasing performance.
FIPS 204 specifies ML-DSA, a set of algorithms for generating and verifying digital signatures. Digital signatures detect unauthorized modifications to data and authenticate the identity of the signatory. A recipient can also use a signature as evidence to a third party that the claimed signatory generated it, a property known as non-repudiation. NIST states that ML-DSA is believed to be secure even against adversaries in possession of a large-scale quantum computer.
FIPS 205 specifies SLH-DSA, a stateless hash-based digital signature algorithm. SLH-DSA is based on SPHINCS+, which NIST selected for standardization in its Post-Quantum Cryptography Standardization process. It is a second signature option built on different mathematics, which matters for firms that prefer not to depend on a single family of assumptions.
| Standard | What it specifies | Where a firm is likely to use it |
|---|---|---|
| FIPS 203 | ML-KEM, a key-encapsulation mechanism with three parameter sets | establishing session keys and protecting data in transit |
| FIPS 204 | ML-DSA, a lattice-based digital signature scheme | signing, authentication, certificates and non-repudiation |
| FIPS 205 | SLH-DSA, a stateless hash-based digital signature scheme | signing where a hash-based alternative is preferred |
| draft report 8547 | NIST’s expected approach to the transition away from quantum-vulnerable algorithms | planning the order and timing of migration |
The standards are living documents, and the dates on them keep moving. NIST has posted a planning note on FIPS 203 identifying an issue to be corrected in a future update or revision. The FIPS 203 planning note is dated 11/17/2025. A planning note on FIPS 204 dated 07/31/2026 points to a list of several minor issues that will be corrected in a future update or revision. NIST has also made an FAQ for the PQC FIPS available. On the draft transition report, NIST noted on 01/21/2025 that the public comments received are now available. A firm’s cryptographic policy should therefore reference the standards by number and require the current version, not a copy frozen at the date of adoption.
Who is asking, and who is not yet
In the United States, the direction comes from NIST
In the United States the direction comes from NIST, whose draft transition report proposes two dates: it would deprecate the weaker quantum-vulnerable public-key algorithms, those at 112 bits of security strength, after 2030 and disallow them after 2035. NIST frames the overall goal as achieving widespread PQC adoption by 2035. The report also says migration timelines may vary based on the specific use case or application.
Those proposed dates are not a private-sector deadline. The transition rules describe the use of cryptography by Federal Government agencies to protect controlled unclassified information. NIST itself describes its cryptography standards as guidance on mechanisms essential for securing sensitive information across both federal and nonfederal systems. In our view that is why the dates are already shaping private roadmaps: the suppliers that serve federal systems serve banks too, and they build to NIST.
In parallel, the technology and the market are moving on their own clock, and nobody knows how fast. Private firms may see quantum-safe requirements from counterparties, card schemes, cloud providers and insurers well before those dates. The dates are a planning horizon, not a forecast.
Regulators elsewhere are moving faster
The Swiss supervisor FINMA has published guidance on quantum computing after surveying 60 Swiss financial institutions between November 2025 and January 2026. FINMA’s view is that numerous institutions need to act within their risk management process to keep meeting the requirements on operational risks and resilience. The measures it lists are a strategy and roadmap for quantum-safe encryption, a risk analysis specific to the institution, a cryptographic inventory, protecting critical data against “harvest now, decrypt later” attacks, bringing external service providers into the work, and moving to crypto-agility.
In Hong Kong, the HKMA announced on 27 July 2026 a Whitepaper on Quantum Preparedness of Hong Kong’s Banking Sector together with a first Quantum Preparedness Index. The initial index score is 2.3 on a 10-point scale. The HKMA aims to bring the sector to full readiness, a score of 10, by 2030.
In the European Union, the coordinated implementation roadmap is the first deliverable of the NIS Cooperation Group work stream on post-quantum cryptography, and it is aimed at the Member States. Firms are not its addressees. It recommends that all Member States initiate a national PQC transition strategy by the end of 2026. It says high-risk use cases should be transitioned to PQC no later than the end of 2030. By 2035, the transition should be completed for as many systems as practically feasible. Those are instructions to governments, but they are likely to inform how EU supervisors frame their expectations of the firms they oversee.
Our view
Given how regulations tend to develop and reach firms, we expect the quantum question to arrive through existing requirements rather than through a new rulebook: information security, operational resilience and third-party risk management. Regulators have already begun to invoke those duties in this context: FINMA framed its quantum guidance as a matter of meeting operational risk and resilience requirements, and the same requirements already apply to United States firms under the rules they hold licenses under. A firm that already holds a cryptographic inventory and a vendor register will find the questions easy when they come. Firms with international reach, especially in territories where the regulators are at the front of the game, the Swiss, Hong Kong and European Union supervisors among them, may expect to be asked sooner, and may need to be in compliance sooner than their purely domestic peers.
Boards may ask sooner than regulators. A director who reads that NIST has published post-quantum standards will reasonably want to know whether the firm has thought about it, who would own the work and roughly what it would cost. The compliance officer should have a considered answer, even if that answer is a monitoring position rather than a program.
The G7 has sent the signal
In January 2026 the G7 Cyber Expert Group published a statement on advancing a coordinated roadmap for the transition to post-quantum cryptography in the financial sector. The statement says of itself that it does not set guidance or regulatory expectations. It still tells you where the finance ministries and central banks of the largest economies want their financial sectors to go. It notes that guidance from several jurisdictions and standards bodies often points to 2035 as the overall target date for migration, whether for governmental systems, private sector systems, or both. It suggests prioritizing the most critical systems, for example by addressing them in 2030-32. And it records that many national authorities have issued guidance over the past year, and that some participants in the financial ecosystem have started building migration plans and deploying quantum-resistant algorithms.
What has not changed
Existing cryptographic obligations still apply. A firm that migrates to ML-KEM and lets its key management, access control or logging lapse has not improved its position. Post-quantum algorithms are a change of algorithm, not a change of control framework, and every policy that governs key generation, storage, rotation and destruction continues to govern the replacement algorithms.
What a prepared firm will be able to show
A firm that can show the following will be in a position to answer a supervisor’s questions with evidence when they come, rather than starting from nothing.
- A named executive owner for post-quantum readiness, recorded in the governance framework and reporting to a board committee.
- A cryptographic inventory that lists every system, protocol, certificate, key store and vendor product that uses public-key algorithms, with the algorithm and key length for each.
- A data classification that flags records whose confidentiality must survive for years, because data captured today could be decrypted once a capable machine exists.
- A vendor register showing which suppliers have published a post-quantum roadmap, which have committed to dates and which have not answered.
- A written cryptographic policy that names FIPS 203, FIPS 204 and FIPS 205 as the target algorithms and requires the current version of each.
- A migration plan sequenced by exposure, with dates, budgets, owners and a reporting line to the board.
- Evidence filed where an examiner could find it: committee minutes, inventory extracts, vendor correspondence and test results.
How to prepare, in order
The steps below are one defensible order. None of them requires a regulator to have asked first, and each produces a document that will be ready when one does.
-
Give the topic an owner and a mandate. The owner should sit at executive level and be able to ask for budget when the time comes. Write the mandate down and have the board or its risk committee note it; without it the inventory never finishes.
-
Build the inventory. Start with the systems the firm runs itself, then move to vendor products and outsourced services. For each entry record where public-key cryptography is used, which algorithm, which key length, who owns the system and how long the data it protects must remain confidential. Automated discovery tools help, but the inventory is only complete when a human has confirmed the gaps.
-
Order the work by exposure. Long-lived confidential data and externally facing key establishment usually come first, because an attacker who records traffic today could decrypt it later. Internal signatures with short validity periods usually come later. Document the rationale for the prioritization: it creates an evidence trail that can support future supervisory or audit review.
-
Put the question to vendors in writing. Ask each supplier which of its products will support ML-KEM, ML-DSA or SLH-DSA, by when, and how the firm will be told. Record the answers, and record the silences. A supplier with no roadmap is a third-party risk observation in its own right, and it belongs in the vendor risk register.
-
Trial before you migrate. When the firm is ready to move, run the replacement algorithms in a controlled environment, measure the performance and compatibility effects, and document the results. The choice of ML-KEM parameter set is a trade between security strength and performance, and the firm should be able to explain why it chose what it chose.
-
Report and keep the evidence. Put post-quantum readiness on the risk committee’s agenda at a sensible interval, report progress, keep the minutes, and update the policy when NIST updates the standards.
Questions people ask
Is there a deadline? Not one a private financial firm in the United States can cite from the sources available. NIST’s proposed 2030 and 2035 dates describe the federal transition, and the European, Swiss and Hong Kong timelines above are addressed to governments and supervised institutions in those jurisdictions. That is not a reason to ignore the topic. It is a reason to set the firm’s own considered position and be able to explain it.
Will our regulator examine this now? In the United States, not on the evidence in this guide: we are not aware of any federal or state financial regulator that has published a post-quantum examination expectation for private firms. Swiss, Hong Kong and European Union supervisors have begun to say what they expect. Our view on how and when the questions will reach firms is set out above.
Do we need to replace symmetric encryption and hashing? The three standards discussed here address key establishment and digital signatures. Symmetric algorithms and hashes are outside their scope. A firm should still review key lengths as part of its ordinary cryptographic hygiene, but the migration effort belongs to the public-key dependencies.
Can our vendors do this for us? They can do much of the technical work, and for outsourced systems they must. They cannot own the firm’s inventory, its risk acceptance or its board reporting. If supervisors take the topic up, they are likely to hold the firm responsible for knowing what its vendors have and have not done.
Is this legal advice? No. Taft is a compliance firm, not a law firm. Where the question is what a specific rule requires of a specific firm, take legal advice.
Where Taft stands
Most firms do not need a migration program yet, but they do need to know where they stand. Taft’s Quantum Readiness Check is built for exactly that: it maps where your firm depends on quantum-vulnerable cryptography, identifies the vendors and the data with the most exposure, and produces a report you can act on and put in front of a board. In our Innovation Lab we have been testing approaches to quantum-safe banking and to the regulatory requirements that are likely to follow. The quantum compliance page has the details.
Questions
Is there a regulatory deadline for post-quantum migration?
Not one a private financial firm in the United States can cite. NIST's draft transition report proposes deprecating the weaker quantum-vulnerable algorithms, those at 112 bits of security strength, after 2030 and disallowing them after 2035, but those rules describe cryptography used by Federal Government agencies. A firm should set its own considered position and be able to explain it.
Will our regulator examine this now?
In the United States, not on the evidence in this guide; we are not aware of any federal or state regulator that has published an expectation. Swiss, Hong Kong and European Union supervisors have begun to say what they expect. The topic is likely to arrive through existing information security, operational resilience and third-party risk duties as the technology develops.
What did the G7 say in January 2026?
The G7 Cyber Expert Group published a statement on a coordinated roadmap for the financial sector's transition to post-quantum cryptography. It says it does not set guidance or regulatory expectations, notes that guidance often points to 2035 as an overall target date, and suggests addressing the most critical systems in 2030-32.
Which NIST standards define the post-quantum target?
FIPS 203 specifies ML-KEM for key establishment, FIPS 204 specifies ML-DSA for digital signatures, and FIPS 205 specifies SLH-DSA, a stateless hash-based signature scheme. NIST published all three on August 13, 2024, and has posted planning notes and errata since.
Can our vendors handle post-quantum migration for us?
Vendors can do much of the technical work, and for outsourced systems they must. They cannot own the firm's inventory, its risk acceptance or its board reporting, and if supervisors take the topic up they are likely to hold the firm responsible for knowing what its vendors have done.
Sources
- Federal Information Processing Standard (FIPS) 203, Module-Lattice-Based Key-Encapsulation Mechanism Standard, NIST
- Federal Information Processing Standard (FIPS) 204, Module-Lattice-Based Digital Signature Standard, NIST
- Federal Information Processing Standard (FIPS) 205, Stateless Hash-Based Digital Signature Standard, NIST
- NIST Internal or Interagency Report (NISTIR) 8547 (Draft), Transition to Post-Quantum Cryptography Standards, NIST
- NIST IR 8547 (initial public draft), Transition to Post-Quantum Cryptography Standards, NIST
- FINMA guidance on quantum computing (Guidance 05/2026), FINMA
- HKMA launches quantum preparedness whitepaper and index to support banking sector’s readiness for quantum era, HKMA
- A Coordinated Implementation Roadmap for the Transition to Post-Quantum Cryptography (EU NIS Cooperation Group), European Union
- G7 Cyber Expert Group statement: Advancing a Coordinated Roadmap for the Transition to Post-Quantum Cryptography in the Financial Sector, G7 Cyber Expert Group, via U.S. Department of the Treasury
Taft does not provide legal advice. Content is for informational purposes only and subject to regulatory guidance.