Migration Is Mandatory. The Roadmap Is Silent.
By: Paul Schaus
September 30, 2026
A banker asked me a question recently that deserved a better answer than this industry has been giving: Is quantum computing a technology that should be in our planning session? My first reaction was not yet, but I had my team dig inside the research, the government deadlines, the vendor disclosures, the supervisory letters coming out from regulators worldwide, and my thoughts come in two parts. First, the migration to quantum-safe security is becoming mandatory on published government clocks, and the vendors who run US banking solutions have not published a plan to meet them. Second, quantum’s impact is not one story, it is four different stories, one for each tier of this industry, that happen to share a deadline. Know which story is yours, because most of what has been written on this subject fails by giving every bank the same advice.
Start with the plain version the hype has buried. A quantum computer works through enormous numbers of possibilities at once where a conventional computer works one at a time, and it matters to banking for one reason: the encryption protecting every wire, every online session, and every stored customer record depends on math problems conventional computers cannot solve. A large enough quantum computer solves them easily.
Nobody has built that machine. The benchmark expert survey by the Global Risk Institute, puts the probability of one arriving within ten years at 49%, up from 34% a year earlier. The honest framing is not “the sky is falling.” It is “the lease on our encryption has a termination date, and we do not control the building.”
Criminals do not need the machine, because encrypted data can be stolen today and held until it arrives to unlock it. The security trade calls this harvest now, decrypt later, and it puts your longest-lived data, loan files, wire instructions, decades of account records, on the clock already.
The answer is not exotic. NIST has published new encryption standards, post-quantum cryptography in the trade, built on different math that quantum computers cannot break. The work is replacing the old locks with new ones across every system and every vendor platform a bank touches, and the deadlines are no longer theoretical. Our team at CCG Catalyst compiled the clocks now on the books:
| Authority | What it requires | The clock |
|---|---|---|
| White House, Executive Order 14412 | Federal systems move to post-quantum encryption | Key protection by 2030, digital signatures by 2031 |
| NIST draft guidance | Today’s standard encryption phased out | Deprecated by 2030, disallowed by 2035 |
| United Kingdom, NCSC | Migration plans, then execution | Plans by 2028, priority systems by 2031, complete by 2035 |
| European Union roadmap | High-risk sectors, banking included, quantum-safe | 2030 |
| Singapore, MAS | Formal supervisory expectations due later this year | Quantum resilience “before the end of this decade” |
| Hong Kong, HKMA | Preparedness index published, quantum risk added to exams | Full readiness by 2030 |
| Switzerland, FINMA | Strategy, inventory, and migration roadmap expected | Guidance in force now |
Notice who is missing from that table. The US banking agencies have issued no quantum guidance, and neither has the NCUA, whose latest resilience report names the threat and stops there. I read that silence as sequencing, not reprieve: with supervisors on three continents formalizing expectations in the same twelve months, and Treasury standing up a Quantum-Readiness Task Force, the American exam question is a matter of when.
Artificial intelligence is now driving the quantum timeline, in one direction only. The hardest quantum engineering problems are pattern-recognition problems, exactly what AI is good at: Google DeepMind’s error-correction decoder, published in Nature, beat every conventional method it was tested against, and NVIDIA has wired quantum processors into its AI computing stack. NVIDIA’s chief executive said useful quantum was 15 to 30 years away, then publicly recanted within months, and published estimates of the machine size needed to break today’s encryption fell roughly twentyfold in a single year. AI cuts the other way too: the most expensive step of migration, finding every place cryptography lives in your systems, is now being automated, and IBM and SandboxAQ sell AI-driven discovery today. The threat is arriving faster, the fix is getting cheaper, and both cut against waiting. This, more than anything, is what moved my answer from not yet to now.
Now the part of this story nobody is writing about, and the reason I am. A community bank cannot perform this migration itself. The encryption lives inside the account processing, digital banking, card, and payment platforms the bank rents, not owns. Three vendors hold the majority of the community bank account processing market. The migration happens when they do it, on their schedule, or it does not happen at all.
Our team went looking for the vendors' plans. As of mid-September, CCG Catalyst’s review found no published quantum migration roadmap from any of the major account processing vendors, the challenger cores, or the digital banking and credit union vendors. The lone meaningful exception, Broadridge’s quantum-safe program in capital markets processing, mostly proves the point: it can be done, and it is not being done where community banking lives.
The deadline is shared. The work is not. Every prior banking technology adopted top-down, reaching community banks late, cheap, and proven. Quantum inverts that curve: the obligations arrive everywhere at once, because a government deadline does not care about asset size, and a $2 billion bank’s data is encrypted with the same math as a $2 trillion bank’s. The burden lands down-market ahead of the benefit.
Community banks and credit unions. For institutions under $10 billion, this is a contract problem wearing a physics costume. These institutions will never touch a quantum computer and should never spend a dollar trying; their exposure is the long-lived customer data inside rented vendor platforms. And when the vendors finally migrate thousands of client institutions, somebody is first in line and somebody is last; the bank that raised the question at renewal, in writing, will not be waiting at the back. The benefits arrive the same mediated way: D-Wave is developing quantum-hybrid fraud models with Nasdaq Verafin, whose platform serves 2,800-plus institutions, likely arriving 2028 to 2030 as an ordinary upgrade inside software they already buy. Credit unions run the identical playbook with added urgency, because their regulator has named the risk without guidance.
Regional banks. Between $10 billion and $100 billion the story changes, because ownership changes. Regionals run enough of their own infrastructure, treasury systems, data centers, the hardware modules that hold their cryptographic keys, that the vendor letter covers only part of the exposure. This tier carries an inventory obligation of its own and will feel examiner expectations first after the money-center banks. The opportunity is commercial and underrated: a regional that can tell corporate depositors “your payment data is quantum-safe” two years before its competitors has a trust product. The constraint is people: the professionals who know this migration number in the hundreds, and the regionals that hire early will pay less.
Large US banks. The only tier with direct quantum programs, and its future is already two-track. Defense is in production: Wells Fargo is engineering quantum-safe protections into its infrastructure, Capital One has shipped hybrid post-quantum encryption in a commercial product, and JPMorganChase runs the field’s largest bank program; by the early 2030s their standards will flow outward as counterparty requirements, the way their cybersecurity questionnaires do today. Offense remains unproven: the most rigorous benchmark to date found well-built conventional software still solves real 1,000-asset portfolio problems to proven perfection in seconds. Judge every quantum pitch with one question: did it beat the best conventional approach on our actual data? So far, nothing has.
International banks. Abroad, the future is not a forecast, it is a filing requirement taking shape. Supervisors in Singapore, Hong Kong, Switzerland, and Japan formalized quantum expectations within a single twelve-month window, most with a 2030 horizon, and the European Central Bank has promised a dedicated quantum letter. The production work is there too: Banque de France has run post-quantum encryption through its live regulatory reporting platform, and Korea’s Naver Pay completed a full post-quantum migration. The defining feature for a global institution is the strictest-clock problem: a bank in ten jurisdictions is held to the earliest deadline among them, which today means UK-style migration plans by 2028.
Our team at CCG Catalyst summarizes the four stories:
| Tier | Where the threat lands | Who does the work | When benefits arrive | First action |
|---|---|---|---|---|
| Community banks & credit unions | Long-lived data inside rented vendor platforms | The vendors, unless the contract says otherwise | ~2028–2030, inside fraud/AML software already in use | Vendor roadmap letter, in writing, at renewal |
| Regional banks | Own infrastructure plus vendor platforms | Shared: bank inventories and hardware, vendors' platforms | Same vendor channel, plus a trust story sooner | Cryptographic inventory; hire expertise early |
| Large US banks | Production systems, counterparties, the payment system itself | The bank: defense in production now | Defense is the benefit; offense unproven at any scale | Extend quantum-safe standards to counterparties and vendors |
| International banks | Every jurisdiction’s clock at once; the strictest governs | The bank, under supervisors writing expectations | Earliest pilots live now; production compute still zero | Map obligations to the earliest deadline in the footprint |
Two weeks ago I wrote that the agencies' joint statement on core service providers made vendor contract practices an examination factor. Quantum belongs on exactly that list. A vendor’s migration plan for the encryption inside your systems is a contract term, as concrete as an exit clause, and the window to put it in writing is the renewal you are negotiating right now. Silence in a sales meeting costs nothing. Silence in a signed contract is a term, and it always favors the party who wrote it.
None of this requires a quantum physicist, and my advice fits in five moves. First, make the list: inventory where cryptography lives across your systems, vendors, and data. Second, ask every critical vendor, in writing, for its post-quantum migration plan and timeline; silence is an answer worth documenting for your file and your examiner. Third, put the commitment in the contract at the next renewal. Fourth, catch the free rides: security hardware and certificate tools now ship with the new NIST standards built in, so specify quantum-ready at the normal refresh, at the same budget. Fifth, protect the longest-lived data first, because that is exactly what harvest-now-decrypt-later reaches. Then do your tier’s work and only your tier’s work.
My final comment: the banker asked whether quantum computing belongs in the planning session, and my first reaction, not yet, did not survive the research. The machine may still be years away, but the deadlines, the data theft, and the contract cycle are not, so it belongs in this year’s plan, sized to your tier, and it enters the plan as vendor management, not as a technology project. The machine is the technology companies' race, and a bank’s balance sheet should sit it out entirely. The data, the deadlines, and the contracts are the bank’s race, and it has already started. The institutions that put the question in writing this renewal cycle will meet the deadlines on someone else’s engineering budget. The ones that wait will discover that the most expensive sentence in bank technology is the one that never made it into the contract.
One closing note on where this goes next. The vendors this commentary examined for their quantum roadmaps are the same companies that run your digital banking and your account opening, and they deserve the same scrutiny there. Beginning Tuesday, October 6, we turn to them directly: a three-week series on the state of digital banking across retail, business, and treasury, the vendor landscapes for digital banking and account opening, and where the account opening experience goes from here.
CCG Catalyst advises banks, credit unions, and fintech companies on technology strategy, vendor selection, and contract negotiation. If your institution is working out which of these four stories is yours, reach out to our team at www.ccgcatalyst.com.
See our latest announcement: CCG Catalyst’s Paul Schaus Named a 2026 Top Consultant by Consulting Magazine
By: Paul Schaus | Founder & Managing Partner, CCG Catalyst Consulting
Disclaimer: The views expressed in this article represent the perspective of CCG Catalyst Consulting based on our direct experience advising financial institutions. This commentary is intended to stimulate industry discussion and does not constitute legal, accounting, or regulatory advice.