
G7 Cyber Expert Group advances coordinated roadmap for transition to post-quantum cryptography in the financial sector
Live Updates
The G7 Cyber Expert Group (CEG), which is led by the U.S. Department of the Treasury and the Bank of England, has issued a detailed roadmap to guide the financial sector through a coordinated transition to post-quantum cryptography. Quantum cryptography uses the principles of quantum mechanics to secure information, offering protection against threats posed by powerful quantum computers. It represents the next generation of encryption designed to safeguard sensitive data in an evolving technological landscape.
This roadmap addresses the growing threat that quantum computing poses to current cryptographic protocols protecting financial systems and sensitive data.
Quantum computing promises powerful new capabilities but also threatens to break widely used cryptographic algorithms such as RSA and elliptic curve cryptography (ECC). These algorithms currently secure financial transactions, communications, and data storage.
The roadmap highlights the need for adopting post-quantum cryptography – algorithms designed to resist quantum attacks to protect the financial sector from this emerging risk.
“The introduction of quantum computers that can break our encryption tools presents a significant risk to the safety and soundness of our financial ecosystem. This is something we must address together, and the roadmap guidance will be an important reference for organizations to consider as they prepare their systems and data to be quantum resilient,” quoted G7 CEG Co-Chairs, U.S. Treasury’s Deputy Assistant Secretary for Cybersecurity and Critical Infrastructure Protection Cory Wilson and the Bank of England’s Executive Director for Supervisory Risk Duncan Mackinnon.
Purpose and scope of the roadmap
The roadmap serves as a strategic guide for financial institutions, regulators, technology providers, and other stakeholders. It does not impose regulatory mandates but offers guidance on i) coordinating migration efforts across organisations and jurisdictions ii) managing risks and maintaining operational continuity during the transition iii) encouraging collaboration among industry participants, regulators, and standard-setting bodies.
The approach is flexible and risk-based, recognising the diversity of financial entities and their unique risk profiles.
Key Considerations for transitioning to post-quantum cryptography
The roadmap highlights critical activities financial organisations should undertake.
Governance and executive oversight. Embedding post-quantum cryptography into existing cybersecurity and risk management frameworks is essential. Executive leadership must prioritise migration efforts, allocate resources, and align activities with organisational goals.
Comprehensive discovery and inventory. Organisations must identify all cryptographic assets, including hardware, software, communication protocols, and third-party dependencies. This inventory forms the basis for prioritising migration and managing legacy systems.
Risk assessment and migration planning. Tailored migration strategies should focus on critical systems and sensitive data. The roadmap focuses on cryptographic agility (the ability to update algorithms flexibly) as a key enabler for adapting to evolving quantum threats and standards.
Migration execution and testing. Transitioning to quantum-resistant algorithms should be progressive and carefully validated to maintain compatibility and operational continuity. Rigorous testing ensures security and reliability.

On-going coopration and monitoring. Collaboration across industries and jurisdictions is important for sharing knowledge, ensuring interoperability, and managing supply chain risks. It minimises fragmentation.
What is the timeline?
While the exact timeline for the arrival of cryptographically relevant quantum computers remains uncertain. However, experts suggest that the financial industry should aim to complete its transition to new security measures between 2030 and 2032.
This timeframe aligns with guidance from various national authorities and international standards organisations.
The roadmap encourages early and sustained action to avoid last-minute, rushed migrations that could compromise security or operational stability.
Broader implications for the financial sector
The transition to post-quantum cryptography impacts several areas including regulatory compliance, vendor management, risk management, and digital transformation.

The G7 Cyber Expert Group’s roadmap provides a framework for the financial sector’s transition to quantum-resistant cryptography. A coordinated, risk-based, and flexible approach is essential to protect financial systems against emerging quantum threats.
The migration to post-quantum cryptography can be complex and iterative rather than a linear process. Organisations need to incorporate flexibility, continuous monitoring, and adaptive risk management into their transition plans.