As of September 2026, none of the four financial supervisors we checked in Latin America (Colombia’s Superintendencia Financiera, Mexico’s CNBV and Banco de México, Chile’s CMF and the Banco Central do Brasil) has published a post-quantum cryptography rule, deadline or formal guidance. For a bank in the region, that means the timetable will be set by others: the G7 financial roadmap, correspondent banks, card networks and technology vendors. This guide lays out what each regulator has and hasn’t said, why waiting for them is a poor strategy, and a year-by-year roadmap to 2030 that a bank can adapt.
What have Latin American financial regulators said about post-quantum cryptography?
Very little, and nothing binding. We searched each regulator’s publications and the regional press in Spanish, Portuguese and English in September 2026, and read the documents that seemed relevant. The table shows what we found in each country and what we did not.
| Country | Regulator | What we found | What we did not find |
|---|---|---|---|
| Colombia | Superintendencia Financiera (SFC) | Cybersecurity requirements in Chapter V of Title IV, Part I of the Circular Básica Jurídica, introduced by Circular Externa 007 of 2018 and amended since. The versions we read do not mention quantum computing. Industry body CINTEL formed a post-quantum sector working group in June 2026. | Any SFC circular, letter or guidance on post-quantum cryptography |
| Mexico | CNBV and Banco de México | Banxico’s Cybersecurity Strategy 2024 to 2027. A text search of the published document found no mention of quantum computing or cryptography. On 22 September 2026 the Mexican Internet Association (AIMX) created the Consejo Consultivo Quantum Safe México to advise authorities and companies. | Any CNBV or Banxico rule, circular or public statement on post-quantum cryptography |
| Chile | Comisión para el Mercado Financiero (CMF) | Chile’s national quantum technologies strategy for 2025 to 2035, launched on 17 December 2025, lists secure communications and cybersecurity among its focus areas. | Any CMF publication on quantum or post-quantum risk |
| Brazil | Banco Central do Brasil (BCB) | A 2022 study with Brazil Quantum, Microsoft and Fenasbac on post-quantum signatures for Pix. In March 2026 Carlos André de Melo Alves, a coordinator in the BCB’s financial system regulation department, said the bank is studying the subject. | Any BCB resolution, public consultation or deadline |
Two caveats. First, absence from our searches is not proof of absence: supervisors sometimes address topics in private letters to supervised entities, and we can only report what is public. Second, you may see vendor websites claiming a specific SFC circular already requires post-quantum preparation, or that the BCB “will require” it by a certain year. We found no official text supporting either claim, and one Brazilian analysis making the 2028 prediction states plainly that the BCB has no resolution yet.
Why should a bank move before its regulator does?
Because the risk and the timetable both come from outside the country. Three forces are already at work.
The first is data lifetime. Mortgages, pension records and customer identity data have to stay confidential for decades. Under “harvest now, decrypt later,” traffic recorded today can be decrypted once a large enough quantum computer exists, so a bank’s exposure depends on how long its data must stay secret, not on when the regulator writes a circular. Our piece on harvest now, decrypt later explains the mechanics.
The second is counterparties. The G7 Cyber Expert Group’s statement of 13 January 2026 is written for banks, market infrastructures and supervisors in G7 economies. It proposes 2035 as the overall target for the financial sector and suggests addressing the most critical systems around 2030 to 2032. A Colombian or Peruvian bank with a correspondent in New York or Madrid will feel those dates through interface changes and due diligence questionnaires long before anything arrives from Bogotá or Lima.
The third is the gap between awareness and action. IBM Institute for Business Value data reported in June 2026 found that 63% of Colombian executives expect security to become a board-level priority by 2030, but only 33% are preparing their organizations with quantum-resistant cryptography. Across Latin America, 71% of organizations named the shortage of specialized skills as a major obstacle. Skills take the longest to build, which is another reason to start now.
Why is post-quantum migration harder for banks?
Because banks run a lot of cryptography that is slow to change and shared with other institutions. Hardware security modules protect PINs, card keys and signing keys, and moving them to post-quantum algorithms usually needs new firmware or new hardware. ATMs and card terminals stay in the field for many years. Core banking platforms are often vendor products the bank cannot modify. Payment rails such as Pix, SPEI or ACH networks need every participant to move in coordination.
Performance matters too. The 2022 Pix study found that the post-quantum signature algorithm it tested, Picnic, was “still incompatible with the current demands of Pix” in capacity and processing time. Picnic was not among the algorithms NIST later standardized, and the standard ML-DSA signatures (FIPS 204) perform differently, but the lesson holds: test on your own volumes before committing. The BIS Innovation Hub’s Project Leap reached a similar conclusion in Europe. Its second phase, completed in December 2025 with the Bank of Italy, the Banque de France, the Deutsche Bundesbank, Nexi-Colt and Swift, replaced traditional signatures with quantum-resistant ones in an operational payment system and reported “significantly higher processing time.”
New infrastructure is also being built right now. Colombia’s open finance rules (SFC Circular Externa 004 of 2024), Brazil’s Open Finance and new real-time payment services all create APIs and certificates that will still be running in 2035. Designing them for crypto-agility today costs much less than retrofitting them later.
A post-quantum roadmap to 2030 for a Latin American bank
The roadmap below follows the phases of the G7 statement (awareness, discovery and inventory, risk assessment and planning, migration execution, testing, validation) and puts dates on them so that critical key exchange is done by 2030. Adjust the pace to your size and vendor dependence; the order matters more than the exact quarter.
| When | Phase | What gets done |
|---|---|---|
| Q4 2026 | Awareness and governance | Board briefing, a named executive owner, a budget line for the inventory; vendor questionnaire sent to core banking, HSM, card, channel and cloud providers |
| H1 2027 | Discovery and inventory | Cryptographic inventory of payments, customer channels, interbank links, card issuing and HSMs; each item ranked by data lifetime and difficulty of change |
| H2 2027 | Risk assessment and planning | Migration plan approved; post-quantum and crypto-agility clauses in procurement and renewals; test lab running hybrid TLS with ML-KEM |
| 2028 | First migrations and pilots | Hybrid key exchange on external channels and APIs (mobile app, open finance, partner integrations); HSM firmware or hardware upgrades scheduled; internal PKI plan for post-quantum certificates |
| 2029 | Priority migrations | Key exchange on links carrying long-lived data (data center interconnects, backups, interbank connections where counterparties are ready); signatures in internal systems begin |
| 2030 | Critical key exchange complete | Key establishment on critical systems migrated, in line with the US federal and EU dates; signatures on critical systems on track for the G7’s 2030 to 2032 window; remaining systems scheduled for 2035 |
A few notes on the plan. Hybrid key exchange, which combines a classical algorithm with ML-KEM, is the practical first step for most channels because browsers, operating systems and OpenSSH already support it. Signatures come later for most banks because they touch PKI, HSMs and counterparties. And the inventory has to be maintained throughout; our guide to building a cryptographic inventory (CBOM) covers how.
For the full list of international dates this plan borrows from, see our post-quantum migration deadlines tracker.
What should the board ask?
Five questions tell a board whether the bank is on track, and each has a factual answer:
- Who owns post-quantum migration, and is there a budget for this year?
- Do we have an inventory of where our critical systems use public-key cryptography, and when was it last updated?
- Which of our vendors have given us a dated post-quantum roadmap, and which have not?
- Which data do we hold that must stay confidential beyond 2035, and how is it protected in transit today?
- What will we tell a correspondent bank or a supervisor who asks for our plan next year?
If the answers are “nobody,” “no,” “we don’t know,” “we haven’t classified it” and “we’d have to put something together,” the bank is at the start of the roadmap, and its first two rows are where to begin.
This sequence is how our post-quantum cryptography migration service is organized, from inventory through pilots, and the quantum readiness assessment is a shorter way to answer the board’s five questions. More on the sector is on our banking and finance page.
Sources
- G7 Cyber Expert Group, Statement on a coordinated roadmap for the transition to PQC in the financial sector, January 2026
- Finsiders Brasil, BC estuda regulação para IA e criptografia quântica, 26 March 2026
- Microsoft News Center Brasil, Banco Central, Brazil Quantum and Microsoft explore post-quantum cryptography for Pix, 11 May 2022
- Banco de México, Estrategia de Ciberseguridad del Banco de México 2024 to 2027
- Expansión, México crea consejo para anticipar riesgos del cómputo cuántico, 22 September 2026
- CINTEL, Criptografía postcuántica, Colombia crea la primera mesa sectorial, June 2026
- Infobae, Colombia ante la computación cuántica (IBM Institute for Business Value data), 3 June 2026
- Bank for International Settlements, Project Leap
- Superintendencia Financiera de Colombia, Part I, Title IV, Chapter V, minimum requirements for information security and cybersecurity