Post-Quantum Readiness — Cross-Border Payments

The quantum clock is already running on payments crypto

What a quantum computer breaks, what survives, and the order to fix it — mapped across a payments cryptographic estate.

Verified 2026-06
Basis NIST FIPS 203/204/205
Scope Readiness framework — not an operational tracker
Harvest Now,
Decrypt Later
if data_secrecy_years > years_to_quantum  →  already_exposed
payment records = long-lived · high-value · recorded in transit today
Traffic encrypted under RSA/ECC today is decryptable once a quantum computer exists. The capture is the attack.
01
Cryptographic Dependency Map
Toggle the quantum algorithm. Shor breaks the asymmetric crypto that authenticates and secures payments; Grover only weakens symmetric crypto, which larger keys defeat. Select any component for its migration target.
BrokenWeakenedSafe
02
Phased Migration Roadmap
Against the NIST horizon (IR 8547, US-federal guidance) — RSA/ECC deprecated 2030, disallowed 2035. A directional planning reference for commercial payments, not yet an OSFI mandate for Canadian banks. Crypto-agility comes first: you cannot migrate what you cannot inventory or swap.
03
The Target-State Standards
Use the FIPS designations in policy and procurement — not the competition names (Kyber / Dilithium / SPHINCS+).
StandardRoleReplacesStatus · 2026-06
Scope matters. CNSA 2.0 mandates Category-5 (ML-KEM-1024 + ML-DSA-87) for US national-security systems — not commercial banks. A payments environment commonly adopts Category-3 (ML-KEM-768 / ML-DSA-65) per risk appetite, reserving Category-5 for the highest-sensitivity, longest-lived assets.