Cityscape of business area of Copenhagen with winding bicycle bridge

Quantum Cryptography series

PQC Migration in Financial Services: A roadmap for Crypto Agility


A practical roadmap for financial institutions to prepare for quantum-era security and build resilience through crypto agility.


In brief:

  • Financial institutions need a phased plan that links governance, risk and engineering decisions from the outset.
  • A clear view of cryptographic assets, sensitive data and supplier dependencies helps organizations focus effort where it matters most.
  • Early pilots and staged execution can reduce disruption while building long-term resilience for the quantum era.

In recent years, organizations such as AIVD, TNO, CWI, the European Commission, FS-ISAC and BIS have published detailed roadmaps urging critical infrastructure sectors to act on the upcoming quantum threat. While existing documents provide valuable strategic guidance, this analysis aims to serve as a practical complement by translating those principles into actionable steps tailored for financial environments.

One of the most important concepts in this transition is crypto agility. Crypto agility is essential for long-term resilience in the quantum era. Post-quantum algorithms are still evolving, and it is expected that organizations may need to transition more than once as standards mature. Rather than treating PQC migration as a one-time project, institutions should design architectures and processes that enable rapid algorithm replacement without disrupting operations. This is the essence of crypto agility. This approach ensures flexibility to adapt to future cryptographic changes, reduces operational risk, and safeguards sensitive data against emerging threats.

Building on our previous article on quantum risk, this article outlines the key steps financial institutions can take to prepare for post-quantum cryptography (PQC) migration and long-term crypto agility. It highlights how these steps align with global standards and leading practices, helping organizations navigate the transition securely and efficiently. The next sections break down this transformation into four practical steps: Mobilize, Diagnose, Strategize and Execute.

Young man standing in a futuristic corridor with blue neon lights
1

Chapter 1

How do you mobilize your organization for post-quantum change?

Set ownership, align teams and build the governance needed to begin the transition.

Preparing for the quantum era begins with mobilizing the organization around a clear, strategic objective. It requires alignment across leadership, management, and operations on what postquantum cryptography (PQC) means for the business. Financial institutions must define clear strategic objectives for their post-quantum cryptography transition, map internal and external stakeholders who will be part of the journey, and appoint an executive lead to drive the program.

Mobilization also benefits from a clear objective: give the program a simple identity, explain the “why” in business terms, and keep communications regular and plainspoken. When engineers, risk teams, and business leaders hear a consistent message, PQC becomes part of everyday planning rather than a side initiative, and resistance drops.

Appointing an executive lead is critical because PQC migration is not just a technical upgrade, it is an enterprise-wide transformation that spans IT, security, risk, compliance, legal, procurement, and business operations. Without executive sponsorship, these functions often remain siloed. Executive leadership also signals to regulators, vendors, and internal stakeholders that PQC migration is a strategic priority rather than an optional technical initiative, strengthening governance and accountability from the start.

Build a cross-functional team

  • Cybersecurity: Leads the technical assessment of current cryptographic controls, identifies vulnerable algorithms, defines security requirements, and ensures the migration aligns with threat models and industry standards.
  • IT / Infrastructure & Architecture: Evaluates system dependencies, manages upgrades to protocols, applications, and hardware, and ensures that PQC and hybrid solutions can be integrated without disrupting business operations.
  • Legal: Reviews the regulatory and contractual implications of cryptographic changes, updates agreements with third‑party providers, and ensures that data protection obligations are met during and after the transition.
  • Compliance & Risk Management: Ensures alignment with regulatory expectations, supports risk assessments based on data sensitivity and longevity, and embeds PQC controls into existing governance and audit processes.
  • Vendor Management / Procurement: Coordinates with external vendors, requests PQC readiness attestations, manages upgrade timelines, and ensures that critical suppliers meet the organization’s cryptographic requirements.

Together, these roles provide the technical depth, governance oversight, and operational coordination needed for a secure and efficient PQC transition. No single team can cover the full scope alone - crypto agility demands collaboration across the entire organization.


✓ How to take action now:

  • Define clear business objectives and ownership for the PQC program.
  • Appoint an executive sponsor and establish governance for decision-making and accountability.
  • Build a cross-functional team across cybersecurity, IT, risk, compliance, legal, and procurement.
  • Identify key internal and external stakeholders and define their roles in the transition.
  • Launch a communication plan that explains the business case for PQC and keeps stakeholders aligned.


View from a glass office window overlooking a brightly lit city skyline at night.
2

Chapter 2

How do you diagnose your cryptographic landscape?

Map assets, data and third-party dependencies to understand where quantum risk sits.

Build a cryptographic inventory

Using structured approaches such as a Cryptographic Bill of Materials (CBOM) helps bring clarity and consistency to this process. Similar to a software bill of materials, a CBOM provides a standardized way to document every cryptographic element within a system, including where it resides, how it is used, and which dependencies or third‑party components rely on it. This structure eliminates guesswork and ensures that teams across the organization apply a common language and format when cataloging cryptographic assets. This is crucial for complex, distributed financial environments.

Use CBOM and automated discovery

Automated discovery tools can significantly strengthen the inventory process by scanning systems to identify outdated or vulnerable algorithms, undocumented cryptographic functions, and hidden dependencies that manual processes often overlook. These tools also help surface high‑risk areas, such as legacy protocols or long‑lived keys, that should be prioritized during migration.

 

To create a meaningful and actionable inventory, organizations must also understand their broader system landscape, including connections to third‑party vendors, cloud services, and external platforms. Cryptography rarely stops at organizational boundaries, and gaps in supplier visibility can undermine an otherwise strong migration plan. Many institutions choose to begin by mapping their most critical business functions and systems first, ensuring that essential processes and long‑lived sensitive data are addressed early in the transition.

 

Classify data by sensitivity and longevity

Next comes data classification. Classify information by sensitivity and longevity, since long‑lived confidential data is a prime risk of “harvest now, decrypt later.” Map those classifications into the systems that use and produce the data, so the picture is grounded in reality, rather than policy. That mapping becomes the backbone of a practical roadmap for post‑quantum measures since it will serve as one of the primary measures used for prioritization.

Assess third-party dependencies

In addition, it is key to identify supply chain dependencies with all external vendors, service providers, and third-party platforms that interact with the organization’s systems and handle operations vulnerable to quantum attacks. Security is only as strong as the weakest link: even if your organization is compliant, a non-compliant software vendor can compromise your data, within or beyond your control. Key dependencies include cloud providers, payment processors, and core banking software vendors. Each introduces risk tied to their cryptographic readiness.  Organizations should assess vendor PQC compliance, request proof of migration efforts, and formalize requirements in contracts with clear deadlines for compliance.

Complete the diagnosis by mapping quantum-related risks, evaluating each algorithm and vendor dependency based on its vulnerability, potential business impact, and the effort required for migration. Align these insights with resource and budget planning to ensure realistic timelines. Establish cryptographic maturity baselines and benchmark against industry best practices to clarify readiness. With all this information obtained in this step, the organization can now plan a secure, efficient migration.


✓ How to take action now:

  • Deploy automated cryptographic scanning tools to generate a comprehensive CBOM report for all critical systems.
  • Develop a prioritized list of critical business functions and associated cryptographic dependencies, including third-parties.
  • Implement a data classification framework that includes longevity criteria and link classifications to cryptographic assets.
  • Conduct vendor PQC readiness assessments and update contracts to include migration milestones and penalties for non-compliance.
  • Develop a risk matrix scoring cryptographic components and vendors by vulnerability and business impact to be updated quarterly.

Young man using a smartphone while standing in a city street with tall buildings
3

Chapter 3

How do you strategize your post-quantum migration path?

Prioritize systems, choose the right scenario and sequence migration with care.

The formula:
X+Y<Z

This means:
The time your data needs to stay secure (X) plus the time it takes to migrate (Y) must be less than the time before quantum computers can break encryption (Z).

Use timing logic to prioritize

Institutions should combine this approach with risk assessments and maturity evaluations to identify systems and data that require early attention. This helps focus efforts where they have the greatest impact, reduces migration risks, and supports a balanced response to urgent security requirements.

Choose the right migration scenario

As part of your migration strategy, an important decision is to choose among several migration scenarios: whether to start with hybrid cryptography, move directly to full post quantum cryptography (PQC), or even explore Quantum Key Distribution (QKD). Hybrid cryptography uses both a traditional algorithm (like RSA or ECC) and a quantum safe algorithm simultaneously. This approach acts as a practical interim step by providing layered security: traditional cryptographic algorithms continue to protect against classical threats, while quantum-safe algorithms add protection against future quantum-enabled attacks. Full PQC replaces classical algorithms entirely with quantum safe alternatives but depends on ecosystem readiness to avoid operational or compatibility challenges. Quantum Key Distribution (QKD) represents a longer-term cryptographic approach that organizations may wish to monitor as the technology matures. It uses quantum physics to distribute encryption keys securely and requires specialized hardware and point-to-point connectivity, limiting its current applicability to a small number of high-value use cases.

Why hybrid can be a practical first step

In practice, hybrid cryptography means that keys from the classical algorithm and the PQC algorithm are combined so that both would need to be broken for the system to fail. Because PQC algorithms are still relatively new, there is a small possibility that weaknesses could be discovered in them over time. If that happens, the classical algorithm still provides protection against today’s threats. Hybrid cryptography therefore offers a balanced way to start the transition.

This approach helps mitigate “harvest now, decrypt later” risks, ensuring sensitive data remains secure even if classical encryption is broken in the future. Standards bodies like NIST and FS-ISAC recommend hybrid solutions for pilots and phased rollouts to support interoperability and reduce migration risk. However, it should be noted that hybrid configurations add complexity, computational overhead, hardware performance challenges on legacy systems, and potential downgrade vulnerabilities.

Where full PQC and QKD fit

Full PQC replaces classical cryptography end‑to‑end with quantum‑safe algorithms across protocols, applications, PKI/key management, and hardware, eliminating reliance on vulnerable primitives and offering long‑term protection against quantum attacks. However, moving everything to full PQC immediately is not usually advisable today. The ecosystem is not always ready in lockstep: many partners, suppliers, market infrastructures, and many customer platforms do not yet support PQC, and some profiles and enterprise‑grade implementations (e.g., TLS/X.509 variants, code‑signing, S/MIME) are still maturing. As a result, full PQC is best viewed as the destination, not the immediate starting point.

The final migration scenario, quantum Key Distribution (QKD), represents a fundamentally different approach to securing communications by using the principles of quantum physics to exchange encryption keys. Unlike PQC algorithms, which run on classical infrastructure, QKD requires dedicated hardware, such as quantumcapable fiber links or satellite connections, and provides security guarantees rooted in the laws of physics: any attempt to intercept the key exchange disturbs the quantum states and becomes detectable. While QKD offers very strong theoretical security, it is not a universal replacement for PQC. QKD only solves key distribution, not encryption itself; it is expensive to deploy at scale; it requires pointtopoint connections; and it does not integrate easily into cloudbased or highly distributed architectures. For most financial institutions, QKD is therefore best suited to niche, highvalue use cases, such as protecting highly sensitive interdatacenter links or communication between a limited number of fixed sites, rather than broad enterprise adoption. As standards and hardware mature, QKD may play a complementary role alongside PQC, but it is not a mainstream migration path for the wider cryptographic ecosystem today.

In summary, the strategy phase translates inventory insights into concrete decisions about when and how to migrate. By assessing how long data must remain secure, how long migration will take, and using conservative assumptions about quantum‑breaking timelines, institutions can identify which systems require early action. From there, organizations choose the most appropriate migration scenario: starting with hybrid cryptography for broad compatibility, planning full PQC as ecosystem readiness improves, or considering QKD for specialized, high‑value communication links. These choices create a clear, risk‑based path forward. With these strategic decisions in place, the final step is execution: turning plans into controlled, phased upgrades that bring the organization safely into the post‑quantum era.


✓ How to take action now:

  • Evaluate and select the appropriate migration scenario (hybrid cryptography, full PQC, or QKD) based on system criticality, vendor ecosystem readiness and operational constraints.
  • Develop a phased migration roadmap that includes pilot projects, interoperability testing, and decision gates to manage risk and validate each stage before full rollout.
  • Engage with key vendors and partners early to align on migration timelines, interoperability requirements and support for hybrid or PQC algorithms.
  • Define success criteria and key performance indicators (KPIs) for each migration phase to monitor progress and effectiveness.
  • Plan resource allocation and budget forecasts aligned with prioritized systems and migration phases to ensure adequate funding and staffing.

Close-up view of a quantum computer processor
4

Chapter 4

How do you execute a post-quantum migration with control and agility?

Turn strategy into phased delivery through upgrades, training and governance.

Upgrade infrastructure and hardware

Execution involves upgrading cryptographic components across multiple layers of the enterprise in a structured and transparent way, in both hardware and software components. Due to the new algorithm’s computational demands, hardware upgrades or acceleration are often necessary to maintain performance and scale. PQC algorithms require more computational power and memory, particularly for key generation and signature verification. CPU cores, memory, and storage need to be upgraded or added to handle the increased load. Hardware upgrades are especially needed when using a hybrid solution, which doubles the load, or in high-volume environment, such as banking APIs or large data centers. Dedicated hardware components, such as HSMs, TPMs and self‑encrypting drives, serve as the root of trust for encryption, key management and signing. As organisations require larger keys, stronger signatures and faster processing, these devices must be upgraded to deliver higher performance and lower latency to handle the increased computational and storage demands.

Prepare software and engineering teams

Moving to full PQC or hybrid cryptography requires major software engineering changes. Any system that uses public‑key cryptography will need updates, ranging from cryptographic libraries and protocol stacks (such as TLS and IPsec) to PKI/Certificate Authorities, certificate formats, and code‑signing pipelines.

However, before planning cutovers, organizations should assess whether they have the skills and capacity to execute: do teams understand PQC algorithms and hybrid modes, certificate/profile changes, handshake behavior, and performance trade‑offs? Is there experience with HSM integrations, PKI refactoring, and large‑scale rollout automation? Based on that assessment, define a capability plan: upskill existing engineers (targeted training and hands‑on pilots), augment with specialists (crypto engineering, PKI, network/security protocol experts), and standardize development practices (test harnesses for interoperability and performance, secure configuration baselines, and automated compliance checks). Organizations should treat this as an engineering program with clear ownership, environments for safe experimentation, and repeatable pipelines, so updates can be delivered reliably across diverse platforms and services.

Embed Monitoring, Governance, and Third-Party Management

TDuring the execution phase, continuous monitoring, training, and periodic risk assessments are essential to keep migration efforts aligned with evolving threats and standards. Progress should be visible and controlled, with phased deployment across systems and vendors, supported by pilots, proof-of-concepts, interoperability testing, and clearly defined decision points.

The migration should be embedded within existing risk and change management frameworks, enabling business, IT, and external vendors to work together with clear responsibilities and rollback procedures. Vendor management requires particular attention. Organizations should assess the PQC readiness of their suppliers, include migration requirements in contractual agreements, and use CBOM analyses to identify hidden dependencies.

Close coordination with regulators and auditors helps ensure that timelines, reporting, and control measures remain aligned with applicable requirements. At the same time, lessons learned from pilots and implementations should be incorporated into updated plans and risk assessments. This creates a controlled and agile execution approach that strengthens long-term cryptographic agility while meeting today's regulatory expectations.


✓ How to take action now:

  • Develop a detailed capability gap analysis and training roadmap.
  • Schedule monthly cross-functional risk review meetings including vendor management, legal, and IT to track third-party compliance and address issues proactively.
  • Implement a vendor PQC compliance scorecard and require quarterly reporting from critical suppliers.

Quantum risk isn’t theoretical; it’s a timing issue

To achieve quantum readiness, organizations must set a clear path from awareness to action, grounded in crypto agility and practical change. The approach must be simple, interoperable across vendors and regulators, and focused on protecting long lived financial data according to risk classification and prioritization.

First, mobilize by setting a shared purpose, appointing an executive lead, and bringing a cross functional team together around a plain spoken narrative. Second, diagnose by building a cryptographic inventory, classifying data by sensitivity and longevity, mapping supply chain dependencies, and establishing risk and maturity baselines. Third, strategize by using timing logic to prioritize high impact areas, aligning plans with vendors and regulators, and introducing hybrid PQC in pilots. Finally, execute through phased rollout, continuous monitoring and training, and integration with enterprise risk and change management, keeping classical and PQC running side by side until the ecosystem is ready.

Quantum readiness is about crypto agility and safeguarding trust over time. With a clear path, shared ownership, and steady cadence, complex transformations can be devised into manageable steps that strengthen organizational resilience. Institutions that move early, learn openly, and adapt with purpose will be ready when it matters, and will carry confidence forward with clients, markets, and regulators.

Contributors: Ruurd Boomsma, Max Fukkink, Tim Leerdam, Taco Filippo and Khamid Mukhamedov


Related articles

Is the financial sector ready for the transition towards post-quantum cryptography?

Explore how advancing quantum computing poses risks to the Dutch financial sector's cryptography and the urgent need for post-quantum solutions.

What if disruption isn't the challenge, but the chance?

Transform your business and thrive in the NAVI world of nonlinear, accelerated, volatile and interconnected change. Discover how.

How to secure your organization against emerging quantum risks

Discover how quantum computing threatens traditional encryption and learn proactive strategies to safeguard your organization with EY's expert solutions.



Summary

Post-quantum cryptography is becoming an urgent priority as regulators call on financial institutions to prepare for quantum risk. This article translates strategic guidance into a practical approach centered on crypto agility, enabling organizations to adapt as standards evolve. It outlines four key steps: mobilize teams and governance, diagnose the cryptographic landscape, define a migration strategy using risk and timing, and execute through phased delivery. Together, these steps help institutions move from awareness to action and build long-term resilience in the quantum era.


About this article