Post-quantum roadmap for Latin American banks to 2030

We checked what Colombia's SFC, Mexico's CNBV and Banxico, Chile's CMF and the Banco Central do Brasil have published on post-quantum cryptography. The short version is very little, which is why banks in the region need their own dated plan.

Latin America · Published September 23, 2026 · 7 min read

As of September 2026, none of the four financial supervisors we checked in Latin America (Colombia’s Superintendencia Financiera, Mexico’s CNBV and Banco de México, Chile’s CMF and the Banco Central do Brasil) has published a post-quantum cryptography rule, deadline or formal guidance. For a bank in the region, that means the timetable will be set by others: the G7 financial roadmap, correspondent banks, card networks and technology vendors. This guide lays out what each regulator has and hasn’t said, why waiting for them is a poor strategy, and a year-by-year roadmap to 2030 that a bank can adapt.

What have Latin American financial regulators said about post-quantum cryptography?

Very little, and nothing binding. We searched each regulator’s publications and the regional press in Spanish, Portuguese and English in September 2026, and read the documents that seemed relevant. The table shows what we found in each country and what we did not.

Country Regulator What we found What we did not find
Colombia Superintendencia Financiera (SFC) Cybersecurity requirements in Chapter V of Title IV, Part I of the Circular Básica Jurídica, introduced by Circular Externa 007 of 2018 and amended since. The versions we read do not mention quantum computing. Industry body CINTEL formed a post-quantum sector working group in June 2026. Any SFC circular, letter or guidance on post-quantum cryptography
Mexico CNBV and Banco de México Banxico’s Cybersecurity Strategy 2024 to 2027. A text search of the published document found no mention of quantum computing or cryptography. On 22 September 2026 the Mexican Internet Association (AIMX) created the Consejo Consultivo Quantum Safe México to advise authorities and companies. Any CNBV or Banxico rule, circular or public statement on post-quantum cryptography
Chile Comisión para el Mercado Financiero (CMF) Chile’s national quantum technologies strategy for 2025 to 2035, launched on 17 December 2025, lists secure communications and cybersecurity among its focus areas. Any CMF publication on quantum or post-quantum risk
Brazil Banco Central do Brasil (BCB) A 2022 study with Brazil Quantum, Microsoft and Fenasbac on post-quantum signatures for Pix. In March 2026 Carlos André de Melo Alves, a coordinator in the BCB’s financial system regulation department, said the bank is studying the subject. Any BCB resolution, public consultation or deadline

Two caveats. First, absence from our searches is not proof of absence: supervisors sometimes address topics in private letters to supervised entities, and we can only report what is public. Second, you may see vendor websites claiming a specific SFC circular already requires post-quantum preparation, or that the BCB “will require” it by a certain year. We found no official text supporting either claim, and one Brazilian analysis making the 2028 prediction states plainly that the BCB has no resolution yet.

Why should a bank move before its regulator does?

Because the risk and the timetable both come from outside the country. Three forces are already at work.

The first is data lifetime. Mortgages, pension records and customer identity data have to stay confidential for decades. Under “harvest now, decrypt later,” traffic recorded today can be decrypted once a large enough quantum computer exists, so a bank’s exposure depends on how long its data must stay secret, not on when the regulator writes a circular. Our piece on harvest now, decrypt later explains the mechanics.

The second is counterparties. The G7 Cyber Expert Group’s statement of 13 January 2026 is written for banks, market infrastructures and supervisors in G7 economies. It proposes 2035 as the overall target for the financial sector and suggests addressing the most critical systems around 2030 to 2032. A Colombian or Peruvian bank with a correspondent in New York or Madrid will feel those dates through interface changes and due diligence questionnaires long before anything arrives from Bogotá or Lima.

The third is the gap between awareness and action. IBM Institute for Business Value data reported in June 2026 found that 63% of Colombian executives expect security to become a board-level priority by 2030, but only 33% are preparing their organizations with quantum-resistant cryptography. Across Latin America, 71% of organizations named the shortage of specialized skills as a major obstacle. Skills take the longest to build, which is another reason to start now.

Why is post-quantum migration harder for banks?

Because banks run a lot of cryptography that is slow to change and shared with other institutions. Hardware security modules protect PINs, card keys and signing keys, and moving them to post-quantum algorithms usually needs new firmware or new hardware. ATMs and card terminals stay in the field for many years. Core banking platforms are often vendor products the bank cannot modify. Payment rails such as Pix, SPEI or ACH networks need every participant to move in coordination.

Performance matters too. The 2022 Pix study found that the post-quantum signature algorithm it tested, Picnic, was “still incompatible with the current demands of Pix” in capacity and processing time. Picnic was not among the algorithms NIST later standardized, and the standard ML-DSA signatures (FIPS 204) perform differently, but the lesson holds: test on your own volumes before committing. The BIS Innovation Hub’s Project Leap reached a similar conclusion in Europe. Its second phase, completed in December 2025 with the Bank of Italy, the Banque de France, the Deutsche Bundesbank, Nexi-Colt and Swift, replaced traditional signatures with quantum-resistant ones in an operational payment system and reported “significantly higher processing time.”

New infrastructure is also being built right now. Colombia’s open finance rules (SFC Circular Externa 004 of 2024), Brazil’s Open Finance and new real-time payment services all create APIs and certificates that will still be running in 2035. Designing them for crypto-agility today costs much less than retrofitting them later.

A post-quantum roadmap to 2030 for a Latin American bank

The roadmap below follows the phases of the G7 statement (awareness, discovery and inventory, risk assessment and planning, migration execution, testing, validation) and puts dates on them so that critical key exchange is done by 2030. Adjust the pace to your size and vendor dependence; the order matters more than the exact quarter.

When Phase What gets done
Q4 2026 Awareness and governance Board briefing, a named executive owner, a budget line for the inventory; vendor questionnaire sent to core banking, HSM, card, channel and cloud providers
H1 2027 Discovery and inventory Cryptographic inventory of payments, customer channels, interbank links, card issuing and HSMs; each item ranked by data lifetime and difficulty of change
H2 2027 Risk assessment and planning Migration plan approved; post-quantum and crypto-agility clauses in procurement and renewals; test lab running hybrid TLS with ML-KEM
2028 First migrations and pilots Hybrid key exchange on external channels and APIs (mobile app, open finance, partner integrations); HSM firmware or hardware upgrades scheduled; internal PKI plan for post-quantum certificates
2029 Priority migrations Key exchange on links carrying long-lived data (data center interconnects, backups, interbank connections where counterparties are ready); signatures in internal systems begin
2030 Critical key exchange complete Key establishment on critical systems migrated, in line with the US federal and EU dates; signatures on critical systems on track for the G7’s 2030 to 2032 window; remaining systems scheduled for 2035

A few notes on the plan. Hybrid key exchange, which combines a classical algorithm with ML-KEM, is the practical first step for most channels because browsers, operating systems and OpenSSH already support it. Signatures come later for most banks because they touch PKI, HSMs and counterparties. And the inventory has to be maintained throughout; our guide to building a cryptographic inventory (CBOM) covers how.

For the full list of international dates this plan borrows from, see our post-quantum migration deadlines tracker.

What should the board ask?

Five questions tell a board whether the bank is on track, and each has a factual answer:

  1. Who owns post-quantum migration, and is there a budget for this year?
  2. Do we have an inventory of where our critical systems use public-key cryptography, and when was it last updated?
  3. Which of our vendors have given us a dated post-quantum roadmap, and which have not?
  4. Which data do we hold that must stay confidential beyond 2035, and how is it protected in transit today?
  5. What will we tell a correspondent bank or a supervisor who asks for our plan next year?

If the answers are “nobody,” “no,” “we don’t know,” “we haven’t classified it” and “we’d have to put something together,” the bank is at the start of the roadmap, and its first two rows are where to begin.

This sequence is how our post-quantum cryptography migration service is organized, from inventory through pilots, and the quantum readiness assessment is a shorter way to answer the board’s five questions. More on the sector is on our banking and finance page.

Sources

  1. G7 Cyber Expert Group, Statement on a coordinated roadmap for the transition to PQC in the financial sector, January 2026
  2. Finsiders Brasil, BC estuda regulação para IA e criptografia quântica, 26 March 2026
  3. Microsoft News Center Brasil, Banco Central, Brazil Quantum and Microsoft explore post-quantum cryptography for Pix, 11 May 2022
  4. Banco de México, Estrategia de Ciberseguridad del Banco de México 2024 to 2027
  5. Expansión, México crea consejo para anticipar riesgos del cómputo cuántico, 22 September 2026
  6. CINTEL, Criptografía postcuántica, Colombia crea la primera mesa sectorial, June 2026
  7. Infobae, Colombia ante la computación cuántica (IBM Institute for Business Value data), 3 June 2026
  8. Bank for International Settlements, Project Leap
  9. Superintendencia Financiera de Colombia, Part I, Title IV, Chapter V, minimum requirements for information security and cybersecurity

Questions we get about this

Has Colombia's Superintendencia Financiera issued rules on post-quantum cryptography?

Not that we could find as of September 2026. The SFC's cybersecurity requirements sit in Chapter V of Title IV, Part I of its Circular Básica Jurídica, and the versions we reviewed do not mention quantum computing. Colombian industry groups such as CINTEL have started a sector working group, but no supervisory deadline exists.

Do Latin American banks have a deadline to migrate to post-quantum cryptography?

No regulator in Colombia, Mexico, Chile or Brazil has set one. The closest reference for the sector is the G7 Cyber Expert Group roadmap of January 2026, which is non-binding and suggests 2035 overall and around 2030 to 2032 for the most critical systems. Banks connected to G7 counterparties will likely be asked to follow similar dates.

What should a bank do first for post-quantum readiness?

Name an owner, brief the board and build a cryptographic inventory of critical systems, starting with payments, customer channels and interbank links. At the same time, send a short questionnaire to core banking, HSM and payment vendors asking for dated post-quantum roadmaps. Everything else in the plan depends on those two inputs.

Has the Banco Central do Brasil said anything about post-quantum cryptography?

It took part in a 2022 study with Brazil Quantum, Microsoft and Fenasbac on post-quantum signatures for Pix, which found the algorithm tested was not yet compatible with Pix's processing demands. In March 2026 a coordinator in its financial regulation department said publicly that the bank is studying the subject. We found no rule or consultation.

Keep reading

Get in before the queue forms

We are taking a short list of companies for our first readiness assessments and post-quantum migrations. Tell us what you are working on and we will get back to you within two business days.

Write to us