Quantum computing in banking and finance

For a bank, quantum computing is a cryptography deadline first and a pricing, risk and portfolio tool much later.

PQC · risk · portfolios

Banks run into quantum computing twice, on two separate clocks. The first is a security problem that already exists: payment messages, customer records and signed transactions protected by RSA and elliptic-curve cryptography. The second is a possible computing gain in pricing, risk and portfolio work that is still mostly research. Quantum computing in banking and finance deserves a budget line this year, but almost entirely because of the first one.

What quantum computing in banking and finance changes now, and later

Now (2026 to 2030) Later (after fault-tolerant machines exist)
Cryptography Inventory, vendor pressure, first migrations to ML-KEM and ML-DSA Legacy RSA and ECC disallowed in most standards
Pricing and risk Small experiments, mostly hybrid, no production advantage Possible speedups in Monte Carlo pricing and risk
Portfolios and trading Research pilots like HSBC’s bond work Possible gains in optimization, still unproven

The cryptography timeline is set by standards bodies. NIST published its first three post-quantum standards (FIPS 203, 204 and 205) on August 13, 2024. Its draft NIST IR 8547, released in November 2024, proposes deprecating RSA and elliptic-curve keys at the common 112-bit security level in 2030 and disallowing them in 2035. In June 2026 a US executive order went further for federal systems: post-quantum key establishment for high-value assets by December 31, 2030, and post-quantum signatures by the end of 2031. Banks are not federal agencies, but their cloud providers and HSM vendors sell to agencies and will change their products on those dates.

The computing timeline is much less certain. A 2021 study in the journal Quantum by researchers from Goldman Sachs and IBM (Chakrabarti and colleagues) estimated that a quantum advantage in pricing certain derivatives would need about 8,000 error-corrected logical qubits and a T-depth of 54 million. Google’s Willow chip, announced in December 2024, has 105 physical qubits. The gap is large.

Why is post-quantum cryptography a bank’s problem first?

Post-quantum cryptography comes first for banks because they hold data and signatures that must stay trustworthy for years, and replacing cryptography across HSMs, core platforms and vendor products takes longer than anything else on the quantum agenda. The NIST standards already exist, so this work can start now. Quantum pricing tools cannot.

Banks hold two kinds of secrets that outlive today’s encryption. One is confidential data with a long shelf life: loan files, account histories, M&A documents, internal models. An attacker who records that traffic today can decrypt it later, which is the “harvest now, decrypt later” risk. The other is signatures. Certificates in payment infrastructure, signed contracts and code-signing keys have to stay trustworthy for years, and forged signatures would be worse than leaked data.

Migration in a bank is slow because the cryptography sits in places nobody touches often: HSMs, core banking platforms, ATM fleets, card personalization, SWIFT connectivity and dozens of vendor products. The Bank for International Settlements tested this directly in Project Leap phase 2, with the Bank of Italy, Banque de France, Deutsche Bundesbank, Nexi-Colt and Swift. They replaced conventional digital signatures with post-quantum ones in an operational payment system and ran liquidity transfers through it. Every test scenario worked, but the BIS reported significantly higher processing times than with traditional algorithms, and many system components had to be modified to work with the new cryptographic libraries. The final report came out in December 2025. That is the kind of finding you want in a test environment, not in production.

Our post-quantum cryptography migration page covers the migration mechanics in detail.

Which regulators are pushing banks on quantum risk?

The clearest push on banks comes from the G7 Cyber Expert Group, which issued a statement on quantum risk in September 2024 and a post-quantum roadmap for the financial sector in January 2026. Neither document is binding. In Latin America, central banks and supervisors have studied the topic, but none has set a post-quantum deadline for banks.

The G7 roadmap of January 2026 says plainly that it “does not set guidance or regulatory expectations.” It describes the activities a financial institution should consider, uses the mid-2030s as its planning horizon and suggests moving the most critical systems earlier. It also points at vendor dependency, which is where smaller banks will feel the most pressure.

In Latin America the signals are earlier but real. The Banco Central do Brasil studied post-quantum signatures for Pix with Brazil Quantum and Microsoft, published through Fenasbac in 2022. In Colombia, a first sector working group on post-quantum cryptography was formed in June 2026 with participants from government, academia and finance. Supervisors such as the Superintendencia Financiera de Colombia, Mexico’s CNBV and the Banco Central do Brasil already set cybersecurity requirements for the entities they oversee. We expect post-quantum questions to show up in those supervisory reviews before any formal rule does.

Where could quantum algorithms help a bank?

Quantum algorithms could eventually help banks in a few narrow areas: Monte Carlo pricing and risk, portfolio optimization and some prediction tasks. The public results so far, such as HSBC’s 2025 bond trading trial with IBM, are research pilots whose claims of advantage are disputed, and no bank runs them at an advantage in production.

In an announcement on September 25, 2025, HSBC and IBM reported a hybrid quantum and classical workflow, run on IBM Quantum Heron processors, that improved predictions of whether a European corporate bond quote would be filled by up to 34% compared with the classical techniques they tested. It used production-scale data: more than one million quote requests across over 5,000 bonds. Critics, including computer scientist Scott Aaronson, argued the result is not evidence of quantum advantage.

In March 2025 JPMorgan Chase, Quantinuum and several US national labs published in Nature a protocol for certified randomness, using Quantinuum’s 56-qubit H2 machine and a classical supercomputer to verify the output. Random numbers matter for cryptography and for fair processes such as lotteries and audits. It is a real demonstration, but a narrow one.

Portfolio optimization, credit scoring and Monte Carlo risk remain the most studied areas. Amplitude estimation offers a quadratic speedup for Monte Carlo in theory, but it needs error-corrected hardware that does not exist yet.

A 2026 plan for a bank

  1. Build the cryptographic inventory. Start with systems that protect long-lived data and signatures. Automated discovery helps, but vendor answers are the slow part.
  2. Put post-quantum requirements into procurement. Every new HSM, core platform or SaaS contract should state how and when the vendor supports ML-KEM and ML-DSA.
  3. Test hybrid key exchange where it is cheap. Internal TLS and new APIs are good starting points.
  4. Keep quantum algorithm work small and measured. One well-scoped experiment with a strong classical baseline teaches more than a demo pilot built for a press release.
  5. Train a few people properly. Security architects need post-quantum depth; quants need enough quantum literacy to judge vendor claims.

How AndesQubit can help

Most banks should start with a quantum readiness assessment, which maps cryptographic exposure and separates real use cases from vendor noise. From there, the migration service handles the cryptography, and quantum use case discovery looks at pricing, risk or portfolio problems with a classical baseline in hand. If your board wants a multi-year view, a quantum strategy and roadmap ties both tracks to dates and budget. We are opening engagements in stages, so tell us about your bank and we will say honestly whether it makes sense now.

Sources

  1. NIST CSRC, Post-quantum cryptography FIPS approved (FIPS 203, 204 and 205), August 13, 2024
  2. NIST IR 8547 (initial public draft), Transition to Post-Quantum Cryptography Standards, November 2024
  3. G7 Cyber Expert Group, Statement on advancing a coordinated roadmap for the transition to post-quantum cryptography in the financial sector, January 2026
  4. Bank for International Settlements, Project Leap
  5. HSBC, HSBC demonstrates world's first-known quantum-enabled algorithmic trading with IBM, September 25, 2025
  6. Chakrabarti et al., A threshold for quantum advantage in derivative pricing, Quantum 5, 463 (2021)

Questions we get about this

How will quantum computing affect banks?

In two ways, on two different timelines. A large enough quantum computer would break the RSA and elliptic-curve cryptography that protects payments, customer data and digital signatures, so banks need to migrate to post-quantum algorithms over the next several years. Separately, quantum algorithms may eventually help with pricing, risk and portfolio problems, but that work is still research and no bank runs it in production at an advantage today.

Can quantum computers already break bank encryption?

No. No public quantum computer today can break RSA-2048 or the elliptic curves used in banking. The concern is that encrypted data copied now can be decrypted once such a machine exists, and that replacing cryptography across a bank takes many years.

What did the HSBC and IBM bond trading experiment show?

In September 2025 HSBC reported that a hybrid quantum and classical workflow on IBM Heron processors improved its prediction of whether a European corporate bond quote would be filled by up to 34% compared with the classical methods it tested. It used real trading data. Some researchers dispute that it shows a quantum advantage, and the authors say more work is needed to see whether the effect holds in other markets.

Do banking regulators require post-quantum cryptography yet?

Most financial regulators have not set a binding deadline for banks. They have issued clear warnings instead, such as the G7 Cyber Expert Group statement of September 2024 and its post-quantum roadmap for the financial sector of January 2026, which is explicitly non-binding. Government deadlines, like the US executive order of June 2026, reach banks through their vendors and cloud providers.

What should a bank do about quantum computing in 2026?

Start a cryptographic inventory, ask your key vendors for their post-quantum plans in writing, and put crypto agility into every new system you buy or build. On the computing side, keep one or two small, well-scoped experiments at most, and measure them against strong classical baselines.

Get in before the queue forms

We are taking a short list of companies for our first readiness assessments and post-quantum migrations. Tell us what you are working on and we will get back to you within two business days.

Write to us