Post-quantum readiness in banking jumps from 28% to 94% in five months
Post-quantum cryptography · Measured Apr–Sep 2026
An independent scan of TLS endpoints across eight sectors found banking's post-quantum cryptography readiness jumped from 28% in April to 94% by early September 2026 — the largest improvement of any sector measured, though a more conservative like-for-like cohort of 293 hosts moved from 50.2% to 86.0%.
Why it matters — It shows the industry can move fast once PQC migration is prioritised — useful context for NZ banks and RBNZ as 'harvest now, decrypt later' risk keeps pushing quantum-safe migration up the agenda, even without a hard local deadline yet.
[UPDATE] US Treasury launches Quantum-Readiness Task Force targeting bank vendors
Post-quantum cryptography · Launched 24 Aug 2026
The US Treasury has launched a public-private Quantum-Readiness Task Force with three workstreams — sector alignment on post-quantum cryptography transition, third-party and vendor readiness, and digital-asset risk — built on the G7 Cyber Expert Group's PQC roadmap. It targets the same vendor-supply-chain gap the Bank of England flagged in late August.
Why it matters — The US and UK are now converging on third-party PQC readiness as the next regulatory pressure point, just as NIST's FIPS 140-2 sunset (21 September) forces a hard cut-off on legacy cryptographic modules — NZ banks should confirm their core-banking and payments vendors have a stated PQC migration timeline.
Quantum deadline pressure builds as FIPS 140-2 sunset hits 21 September and Bank of England presses lenders on third-party PQC readiness
Post-quantum cryptography · FIPS 140-2 sunset 21 Sep 2026
All remaining FIPS 140-2 validated cryptographic modules move to "Historical" status on 21 September 2026, meaning only FIPS 140-3 validated modules may be used for new US procurement from that date; separately, the Bank of England told firms in July to seek assurance on how material third-party suppliers are preparing for post-quantum safety.
Why it matters — NZ banks relying on US-sourced HSMs, payment terminals or cloud cryptographic modules should confirm vendor FIPS 140-3 compliance now — a procurement and vendor-risk question, not just one for security architects.
Crypto4A achieves world-first FIPS 140-3 Level 3 validation for a quantum-safe HSM
Post-quantum cryptography · Validation announced 20 Aug 2026
Crypto4A Technologies' QASM hardware security module has become the first to achieve FIPS 140-3 Level 3 validation while supporting the full set of NIST-standardised post-quantum cryptography algorithms.
Why it matters — A validated, certified quantum-safe HSM gives banks a concrete procurement option for post-quantum migration planning, rather than relying solely on software-level PQC pilots.
Sunday, 9 August 2026
Emerging risks & trendsmedium
HKMA sets out quantum preparedness expectations for Hong Kong banks
Post-quantum cryptography · 27 July 2026
The Hong Kong Monetary Authority has published supervisory guidance on the banking sector's quantum preparedness, building on the Quantum Preparedness Index it introduced in February 2026 to score institutions' readiness to migrate away from quantum-vulnerable encryption.
Why it matters — HKMA is one of the first prudential regulators to formally score banks on quantum readiness rather than just publish guidance — a model RBNZ and APRA are likely to study as they think through their own post-quantum timelines.
SWIFT sets a 2027 target and 15-month window for post-quantum migration
Post-quantum cryptography · Reported 7 August 2026
SWIFT is expected to make its SwiftNet network post-quantum-cryptography-enabled by 2027, giving participating institutions a 15-month window to complete migration — one of the more concrete banking-sector deadlines yet in the broader scramble to get ahead of quantum-capable decryption.
Why it matters — Every NZ bank connected to SWIFT inherits this migration deadline by extension; treasury and infrastructure teams should be scoping dependencies now rather than waiting for a formal mandate.
AT&T and Palo Alto Networks launch quantum-resilient network security fabric aimed at 'harvest now, decrypt later' threats
Post-quantum cryptography · Published 16 Jul 2026
AT&T Business and Palo Alto Networks have launched a jointly built quantum-resilient secure network service that combines hybrid post-quantum cryptography with automatic algorithm updates, explicitly targeting attackers who harvest encrypted traffic today to decrypt once quantum computers mature, and framed partly as a compliance play for sectors facing tightening resilience rules such as banking.
Why it matters — Signals post-quantum protection is moving from bespoke bank-by-bank pilots into off-the-shelf telco/security-vendor products, giving smaller institutions — including NZ banks without in-house quantum programmes — a more accessible path to crypto-agility ahead of global migration deadlines.
AI-accelerated quantum timeline prompts fresh RBNZ, ANZ and NCSC crypto-agility warnings in NZ
Post-quantum cryptography · Jul 2026
Local commentary warns AI is pulling forward the point at which quantum computers could break common encryption, from a long-assumed 2035 to potentially as early as 2029; RBNZ, ANZ and the National Cyber Security Centre say they are inventorying cryptographic assets to become 'crypto agile' ahead of migration.
Why it matters — This is a domestic checkpoint on a trend dominating overseas headlines (Microsoft's and the US government's pulled-forward PQC deadlines): NZ banks, RBNZ and NCSC are signalling the same 'harvest now, decrypt later' exposure applies locally. Boards should ask whether their own cryptographic-asset inventory and PQC migration roadmap are as advanced as ANZ's.
Trump executive order pulls forward US post-quantum migration deadlines to 2030-31
Post-quantum cryptography · Executive order signed 22 June 2026
A new executive order requires US federal agencies to move high-value and high-impact systems to post-quantum cryptographic keys by end-2030 and to post-quantum digital signatures by end-2031, years earlier than the 2035 horizon previously assumed, with matching procurement rules imposed on contractors.
Why it matters — NZ banks and payment providers connected to US correspondent banks, card networks or cloud and security vendors bound by the new federal procurement rules will likely feel migration pressure flow through commercial contracts well before local regulators mandate anything.