For a decade, the quantum threat to encryption was framed as a question of physics: when will someone build a machine large enough to break RSA and elliptic-curve cryptography? In 2026 that framing changed. Regulators in Australia, Singapore, Hong Kong, the UAE, the UK, the EU and the United States have published migration dates, and those dates now arrive before most experts expect the machine to exist.

For banks, payment providers and critical infrastructure operators in Asia-Pacific, that turns post-quantum cryptography from a research topic into a compliance programme with milestones. This article sets out the regulatory clock as it stands in September 2026, what has changed in the standards, and a five-phase roadmap that holds up under supervisory review.

Why the deadline is set by regulators, not physicists

Two facts explain the urgency. The first is harvest now, decrypt later: an adversary can record encrypted traffic today and decrypt it when a capable machine exists, so any data that must stay confidential into the 2030s is already exposed. The second is that the estimates keep moving closer.

  • The Global Risk Institute’s Quantum Threat Timeline Report 2025, published in March 2026, put the probability of a cryptographically relevant quantum computer within ten years at 28% to 49%, the highest in the series.
  • In May 2025, a Google researcher estimated that RSA-2048 could be factored with fewer than one million noisy qubits in under a week, down from about 20 million qubits in 2019.
  • In March 2026, Google Quantum AI estimated that 256-bit elliptic-curve cryptography could fall to fewer than 500,000 physical qubits, and Google set 2029 as the deadline for its own migration.

The lesson for a board is not that Q-Day is imminent. It is that migrating a bank’s cryptography takes most of a decade, and the time left is roughly the same length.

The Asia-Pacific regulatory clock

A glowing timeline arc over a dark city skyline with milestone markers from 2026 to 2035
Across the region, the working deadline for critical systems has settled at 2030 to 2031.
JurisdictionInstrumentKey dates
AustraliaASD guidance on planning for post-quantum cryptography and the ISMRefined transition plan by end of 2026; critical systems transition started by end of 2028; stop using traditional asymmetric cryptography by end of 2030
Singapore (financial sector)MAS advisory (February 2024); supervisory expectations announced July 2026Formal expectations due later in 2026; stated aim of quantum resilience before the end of the decade
Singapore (critical information infrastructure)CSA Quantum-Safe Migration Handbook (July 2026)Migration plan by 31 March 2027; new systems quantum-safe from 1 January 2028; migration complete by 31 December 2031 (guidance language)
Hong KongHKMA Quantum Preparedness Index and whitepaper (July 2026)First sector score 2.3 out of 10, against the readiness HKMA expects by 2030
United Arab EmiratesNational Encryption Policy (November 2025)Government entities to have approved post-quantum transition plans, submitted in 2026
IndiaDST task force report (February 2026)Proposed full post-quantum protection for critical information infrastructure by about December 2029 (advisory)
New ZealandNZISM section on preparation for post-quantum cryptographyAgencies to track developments and keep an inventory of long-lived sensitive data
Saudi ArabiaNCA Essential Cybersecurity Controls and national cryptographic standardsNo published post-quantum migration deadline found as at September 2026

Global bodies point the same way. The G7 Cyber Expert Group roadmap of January 2026 places migration of critical financial systems in 2030 to 2032. The EU expects high-risk use cases to be migrated by the end of 2030, the UK NCSC asks for highest-priority migrations by 2031, and the US federal government has told agencies to mitigate as much quantum risk as feasible by 31 December 2030.

What changed in the standards

The migration target is now well defined. NIST approved three post-quantum standards on 13 August 2024: FIPS 203 (ML-KEM) for key establishment, and FIPS 204 (ML-DSA) and FIPS 205 (SLH-DSA) for digital signatures. In March 2025 NIST selected HQC as a backup key encapsulation mechanism. FIPS 206 (FN-DSA, based on Falcon) is still pending as a final standard. The NIST post-quantum project page tracks each step.

NIST’s draft transition guidance, IR 8547, proposes that quantum-vulnerable algorithms at current security levels such as RSA-2048 and P-256 be deprecated after 2030 and disallowed after 2035. It is still a draft, but regulators are already aligning to it.

On the internet, hybrid key exchange has moved fastest. Cloudflare reported that more than 65% of human traffic to its network was post-quantum encrypted by April 2026, using the hybrid X25519 plus ML-KEM-768 exchange. The weak link is the other end: at the end of 2025, only about 3.7% of origin servers supported it. For a bank, that gap is the difference between a browser session that is protected and a back-end integration that is not.

A five-phase roadmap that survives supervisory review

  1. Discover. Build a cryptographic inventory, ideally as a Cryptography Bill of Materials (CBOM) in the CycloneDX format, covering applications, libraries, protocols, certificates, keys, HSMs and the third parties that hold your keys. Automate it with software composition analysis and network scanning, because a spreadsheet inventory is out of date the day it is finished.
  2. Prioritise. Rank systems using Mosca’s inequality: if the years your data must stay confidential, plus the years migration will take, exceed the years until a capable quantum computer, the risk is already unacceptable. Payment data, identity data, long-term contracts and critical infrastructure control traffic usually rise to the top.
  3. Pilot hybrid. Test hybrid key exchange on selected external and internal TLS connections, measure performance, and confirm your HSMs, load balancers and monitoring tools cope with larger keys and handshakes.
  4. Migrate key establishment first, then signatures. Key exchange protects against harvest-now, decrypt-later today, so it goes first. Signatures, including code signing, certificates and document signing, follow in a second wave once vendor support matures.
  5. Prove it. Track progress with metrics a supervisor can test, and design for crypto-agility, so the next algorithm change is a configuration change rather than another decade of rework.

Where banks and operators get stuck

  • Hardware security modules. As of early 2026, industry reporting indicated that no HSM had completed a FIPS 140-3 Level 3 validation with post-quantum algorithms inside the validated boundary. Check the current validation list before committing to a hardware refresh date.
  • Certificates. The CA/Browser Forum has cut maximum public TLS certificate lifetimes to 200 days from 15 March 2026, 100 days from March 2027 and 47 days from March 2029. Automated certificate management is now a prerequisite for any algorithm change.
  • Long-lived signatures. Firmware in field devices, smart meters, payment terminals and operational technology may need to verify signatures for 15 years or more. These devices need a plan now, even if migration comes later.
  • Third parties. Core banking providers, card schemes, cloud platforms and managed security providers each hold part of your cryptography. Without their roadmaps in writing, your own roadmap is a guess.

What to put in front of the board

A secure vault door made of layered glass lattice panels glowing blue, representing lattice-based cryptography
Post-quantum algorithms such as ML-KEM are built on lattice mathematics rather than factoring.

Boards do not need the mathematics. They need five facts each quarter, which we recommend as the minimum post-quantum reporting pack:

  • coverage of the cryptographic inventory, and whether it is automated;
  • the share of critical systems using post-quantum or hybrid key establishment;
  • the number of systems that cannot migrate, with a replacement date for each;
  • the share of critical vendors with a written post-quantum roadmap;
  • the next regulatory date that applies to the organisation, and whether the plan meets it.

The governance model matters as much as the metrics. The US federal migration memo assigns accountability to the CIO and CISO, requires the CFO to reflect post-quantum needs in budget requests, and names a migration program manager. That division of responsibility transfers well to a bank or operator in any jurisdiction.

Related reading

Frequently asked questions

When do Australian organisations need to stop using RSA and elliptic-curve cryptography?

ASD’s guidance is to stop using traditional asymmetric cryptography by the end of 2030, with a refined transition plan by the end of 2026 and transition of critical systems started by the end of 2028.

Which post-quantum algorithms should we plan for?

NIST’s FIPS 203 (ML-KEM) for key establishment and FIPS 204 (ML-DSA) and FIPS 205 (SLH-DSA) for signatures. FIPS 206 (FN-DSA) is still pending as a final standard.

Is hybrid cryptography enough?

Hybrid key exchange, which combines a classical and a post-quantum algorithm, is the common transition step and protects against harvest-now, decrypt-later. Regulators treat it as a stage in migration, not the end state.

Do Singapore’s 2031 dates bind every organisation?

The CSA handbook targets critical information infrastructure owners and uses guidance language. MAS has announced separate supervisory expectations for financial institutions, due later in 2026.

How Security Solution Consultants can help

Security Solution Consultants runs post-quantum readiness programmes for banks, payment providers and critical infrastructure operators across Australia, New Zealand, Singapore, Malaysia and the Gulf. We build the cryptographic inventory, rank systems by data lifetime and business impact, pressure-test vendor roadmaps, and turn ASD, MAS, CSA and HKMA expectations into a dated plan your board can approve and your regulator can review.

Our security compliance and PCI DSS advisory teams cover the payment side, and GRCLens tracks the inventory, risks and milestones as one programme. For the metrics and governance model in more depth, read running post-quantum readiness as a GRC programme on GRCLens, then talk to us about a readiness assessment.