🏹 Happy Dussehra — victory of good over evil!

Post-Quantum Readiness in Banks: Crypto Agility for IT Security

ITSEC By Ashish Jain · IIBF STORE Editorial · 15 August 2026 · Updated 29 Sep 2026 · 11 min read · 62 views
Post-Quantum Readiness in Banks: Crypto Agility for IT Security

Every encrypted file a bank stores today has a shelf life, and quantum computing is the clock ticking against it. That is why post-quantum readiness in banks has moved from research-paper curiosity to a board-level IT risk item in 2026, sitting alongside patching and access control on the CISO's agenda. This guide explains the threat model, the finalised NIST standards, the migration timeline, and the crypto-agility steps an Indian bank is expected to document — in the exact depth the IIBF IT Security paper tests.

🔓 Why Quantum Computing Breaks Today's Bank Cryptography

Banks rely on two families of cryptography. Asymmetric (public-key) algorithms such as RSA, Diffie-Hellman and Elliptic Curve Cryptography secure TLS handshakes, digital certificates, code signing and message authentication. Symmetric algorithms such as AES, plus hash functions such as SHA-256, protect data at rest and provide integrity.

A sufficiently large, fault-tolerant quantum computer running Shor's algorithm can factor large integers and solve discrete logarithms in polynomial time. That single result collapses RSA, DH and ECC completely — not weakens them, breaks them. Every certificate, every TLS session key negotiated with ECDH, every signature that proves a message came from your bank becomes forgeable.

Symmetric cryptography fares far better. Grover's algorithm gives only a quadratic speed-up on brute-force search, effectively halving the security level of a symmetric key. AES-128 drops to roughly 64 bits of quantum resistance, while AES-256 retains about 128 bits — still comfortable. The practical rule for banks is therefore simple: replace asymmetric algorithms, and upgrade symmetric ones to AES-256 and SHA-384 for anything with a long confidentiality horizon.

The urgency comes from "harvest now, decrypt later". An adversary who cannot break RSA today can still copy encrypted traffic, backups or archived customer records now and decrypt them once a cryptographically relevant quantum computer exists. For a bank, KYC records, loan files, treasury positions and inter-bank messages retain value for a decade or more, so the exposure window has already opened. This retrospective risk is what separates the quantum problem from ordinary technology refresh planning, and it is the point examiners most often probe. The foundations are covered in the INFORMATION SECURITY chapter.

💡 Exam Tip: Shor's algorithm targets asymmetric cryptography and breaks it; Grover's algorithm targets symmetric cryptography and only halves its strength. Mixing up the two is the single most common error in quantum-security questions.

📊 Which Algorithms Fail and What Replaces Them

In August 2024 the US National Institute of Standards and Technology finalised the first three post-quantum standards, converting a decade-long global competition into deployable specifications. A fourth key-encapsulation mechanism, HQC, was selected in March 2025 as a mathematically different backup so that banks are not dependent on a single hard problem.

The table below is the one exam candidates should be able to reproduce from memory.

Algorithm / StandardBank use caseQuantum-safe?Replacement
RSA-2048Certificates, signatures❌ML-KEM / ML-DSA
ECDH / ECDSA P-256TLS key exchange, signing❌ML-KEM (FIPS 203)
Diffie-HellmanVPN, IPsec tunnels❌Hybrid ML-KEM exchange
AES-128Database and disk encryption⚠️ WeakenedAES-256
AES-256Long-retention archives✅Retain
SHA-256Integrity, HMAC✅ AdequateSHA-384 for long horizons
ML-KEM (FIPS 203)Key establishment✅Target state
ML-DSA (FIPS 204)Digital signatures✅Target state
SLH-DSA (FIPS 205)Firmware and code signing✅Hash-based fallback

ML-KEM (derived from CRYSTALS-Kyber) is a lattice-based key encapsulation mechanism used to agree a session key. ML-DSA (from CRYSTALS-Dilithium) is the general-purpose lattice signature scheme. SLH-DSA (from SPHINCS+) is stateless hash-based, slower and with larger signatures, but it rests on hash-function security alone — valuable as a hedge for firmware and long-lived root keys where a lattice break would be catastrophic.

Note what is not on the replacement list. Symmetric ciphers and hash functions survive with larger parameters, so a bank's database encryption, backup encryption and HMAC-based integrity checks need re-sizing rather than re-engineering. The disruptive work is concentrated in public-key infrastructure, TLS termination and digital-signature workflows, which is exactly where certificates, hardware security modules and payment-network interfaces converge.

Key Concepts — IT Security
Key Concepts — IT Security

🕒 The Migration Timeline Banks Are Working To

No regulator has yet fixed a hard post-quantum cut-over date for Indian banks, but the international timeline is now explicit enough to plan against. NIST's transition guidance treats RSA-2048 and 128-bit-equivalent elliptic curve cryptography as deprecated after 2030 and disallowed after 2035. Government and defence procurement timelines in several jurisdictions are tighter still.

That sounds distant until you count backwards through a bank's actual change cycle. A core banking upgrade, an HSM firmware refresh, a payment-switch certification and a full public-key infrastructure re-issuance are multi-year programmes individually. Certificates issued in 2028 with five-year validity will still be live when deprecation bites, so procurement decisions taken now already carry quantum risk.

The industry's interim answer is hybrid cryptography: run a classical and a post-quantum algorithm together so the session is safe if either survives. Mainstream browsers and TLS libraries already default to a hybrid X25519 plus ML-KEM-768 key exchange, which means a bank's internet-facing estate can gain quantum-resistant confidentiality by upgrading TLS terminators, load balancers and web application firewalls — often without touching application code.

Sequencing matters. Confidentiality-first systems, where harvested traffic has lasting value, take priority: customer data flows, backups, archives, inter-bank links and treasury systems. Authenticity-first systems such as code signing and certificate issuance are less exposed to harvesting, because a forged signature is only useful once quantum capability actually exists, but they need longer lead times because trust roots propagate slowly. Network termination points are the practical starting line, and the Network Controls chapter maps them well. Teams already running mature detection through a security operations centre in banks should extend telemetry to record negotiated cipher suites, not just connection counts.

⚠️ Common Mistake: Assuming quantum risk starts only when a quantum computer is built. Harvest-now-decrypt-later means data stolen in 2026 is already at risk; the deciding factor is your data's retention period, not the machine's arrival date.

🧭 Building Crypto-Agility: The Practical Roadmap

Crypto-agility is the ability to change cryptographic algorithms, key sizes and protocols without re-architecting the application. Most legacy bank systems fail this test because algorithm choices are hard-coded, buried in vendor binaries, or fixed inside hardware. A migration therefore begins not with new algorithms but with visibility.

The first deliverable is a cryptographic inventory, increasingly formalised as a Cryptographic Bill of Materials (CBOM). It records, for every application and interface, which algorithms and key lengths are used, where keys live, who owns them, certificate expiry dates, and the data's retention period. Discovery draws on TLS scanning, certificate stores, hardware security module reports, source-code scanning and vendor attestations.

Second comes risk-ranking. Score each system on retention period, exposure to untrusted networks, and difficulty of change. A twenty-year archive reachable over the internet outranks an internal batch job whose data expires in ninety days.

Third is remediation design: replace hard-coded algorithm identifiers with configurable cryptographic providers, shorten certificate lifetimes so re-issuance becomes routine, and confirm that HSMs and smart cards can be upgraded to post-quantum firmware rather than physically replaced. Larger post-quantum keys and signatures also increase packet sizes and handshake latency, so capacity testing is part of the design, not an afterthought.

Fourth, contract and vendor management: new procurement should carry crypto-agility clauses obliging suppliers to publish a PQC roadmap. The same discipline that governs secure coding practices in banks applies here — algorithm selection becomes a reviewable design gate, not a developer's default. Operational hand-offs are covered in SOFTWARE AND OPERATIONAL SECURITY.

Process & Framework — IT Security
Process & Framework — IT Security

🏦 Governance, RBI Expectations and Audit Evidence

Indian banks do not need a quantum-specific circular to be accountable. RBI's Master Directions, including the Master Direction on Information Technology Governance, Risk, Controls and Assurance Practices effective from 1 April 2024, already require a documented cryptography policy covering approved algorithms, minimum key lengths and the full key lifecycle, reviewed periodically. An algorithm known to be breakable within the data's retention window is, by definition, a policy exception that must be recorded and treated.

ISO 27001:2022 reinforces this through Annex A control A.8.24 on the use of cryptography, which expects rules on algorithm selection and key management rather than a one-time choice. Together these give auditors a clear line of questioning: show the inventory, show the risk assessment, show the roadmap, show the board reporting.

Practical governance artefacts a bank should be able to produce are a named accountable owner for cryptographic risk, a current cryptographic inventory, quantum risk entered on the IT risk register with rating and treatment plan, a dated migration roadmap, procurement clauses, and evidence of tabletop testing. Risk-committee framing is set out in ORGANISATIONAL SECURITY AND RISK MANAGEMENT.

Post-quantum work also fits the standard control taxonomy — preventive, detective and corrective — explained in types of security controls in banks, and it is fundamentally a duration-versus-exposure calculation, much like the interest-rate sensitivity logic behind PV01 and DV01 in treasury. More study notes are collected on the IT Security topic hub, and the full syllabus map sits under CAIIB and certificate courses.

📌 Remember: Crypto-agility is the examinable outcome, not any single algorithm. A bank that can swap algorithms by configuration has managed the risk; one that must rewrite applications has merely postponed it.
In Practice — IT Security
In Practice — IT Security

🧠 Practice MCQs: Post-Quantum Readiness in Banks

Q1. Which algorithm poses the most direct threat to RSA and elliptic curve cryptography used in a bank's PKI? (a) Grover's algorithm (b) Shor's algorithm (c) Diffie-Hellman exchange (d) Rijndael cipher

Answer: (b) — Shor's algorithm solves factoring and discrete logarithms efficiently on a quantum computer, breaking RSA, DH and ECC outright.

Q2. Under NIST's finalised standards, which is the approved key encapsulation mechanism specified in FIPS 203? (a) ML-DSA (b) SLH-DSA (c) ML-KEM (d) SHA-384

Answer: (c) — FIPS 203 standardises ML-KEM, derived from CRYSTALS-Kyber, for quantum-resistant key establishment; FIPS 204 and 205 cover signatures.

Q3. A bank archives loan documents for 15 years using AES-128 and transmits them over TLS with ECDH. Which risk is described as "harvest now, decrypt later"? (a) Insider misuse of archives (b) Adversary copying encrypted traffic today to decrypt after quantum capability arrives (c) Certificate expiry causing outage (d) Key escrow failure at the vendor

Answer: (b) — Retrospective decryption of previously captured ciphertext is the defining harvest-now-decrypt-later exposure for long-retention data.

Q4. What is the correct effect of Grover's algorithm on symmetric encryption? (a) It breaks AES completely (b) It roughly halves the effective security level (c) It has no effect on AES (d) It only affects hash functions

Answer: (b) — Grover gives a quadratic speed-up, so AES-128 falls to about 64-bit quantum resistance, which is why AES-256 is recommended.

Q5. Which deliverable should a bank produce FIRST when starting a post-quantum migration programme? (a) Purchase quantum-resistant HSMs (b) Rewrite all applications (c) Build a cryptographic inventory or CBOM (d) Disable TLS 1.2 bank-wide

Answer: (c) — Migration begins with discovery: you cannot risk-rank or remediate algorithms whose location, ownership and key lengths are unknown.

Want chapter-wise mock tests with 100+ MCQs? Start practising free →

❓ Frequently Asked Questions

Has RBI issued a specific post-quantum cryptography deadline for banks?

No dedicated quantum deadline has been prescribed. Obligations flow from existing requirements — notably the documented cryptography policy, key-lifecycle controls and IT risk assessment expected under RBI's IT governance and cyber security directions.

Do banks need to replace their hardware security modules?

Not necessarily. Many current HSMs can add post-quantum algorithms through firmware upgrades, subject to certification. The correct step is to obtain a written PQC roadmap from the vendor before assuming replacement is required.

What is hybrid cryptography and why is it used now?

Hybrid mode runs a classical algorithm such as X25519 alongside a post-quantum algorithm such as ML-KEM in the same handshake. The session stays secure if either component holds, which lets banks deploy early without betting on an unproven algorithm.

Is AES-256 still safe against quantum attack?

Yes, for the foreseeable future. Grover's algorithm reduces AES-256 to roughly 128 bits of effective security, which remains far beyond practical attack. The real replacement work is concentrated in asymmetric cryptography.

Key Takeaway for Your Exam

Treat post-quantum work as a data-lifetime problem, not a technology-arrival problem: inventory first, risk-rank by retention period, deploy hybrid key exchange at network edges, and prove crypto-agility to your auditor. Test yourself on the full IT Security question bank at iibf.store mock tests.

Next step

Practice this topic

Ready to put this into practice?

Take a free mock test, download chapter PDFs, or watch a video class — all included on iibf.store.

Keep reading