Banking Security

Post-Quantum Cryptography and DORA Compliance: The Bank Roadmap to 2030

Why banks must define a quantum-safe migration plan by end-2026 — a guide to ML-KEM, ML-DSA, crypto-agility, and DORA compliance.

Updated: 2026-07-12 9 min read
Encrypted data streams and the concept of quantum computing
“Harvest now, decrypt later” is pushing banks toward post-quantum cryptography.

Quantum computers have not yet broken today's cryptography, but attackers are already storing encrypted data to decrypt later — the threat known as Harvest Now, Decrypt Later. For banks that retain decades of financial data, that risk is real today.

The Compliance Timeline: What and When

Motion view: the threat and defense cycle
Motion view: the threat and defense cycle

Financial regulators, the G7 Cyber Expert Group, and NIST have set a clear schedule:

DeadlineRequirement
End of 2026Define a PQC migration roadmap and begin transition activities
End of 2030Complete PQC transition for high-risk systems and critical financial infrastructure
Dec 31, 2026deadline to have a post-quantum migration roadmap

NIST-Standardized Algorithms

The transition is built on NIST-standardized algorithms that must replace RSA and ECC:

  • ML-KEM (based on CRYSTALS-Kyber) for key exchange and encapsulation.
  • ML-DSA (based on CRYSTALS-Dilithium) for digital signatures.
  • A hybrid approach: run classical and post-quantum algorithms together during the transition.

Crypto-Agility and the CBOM

More important than picking one algorithm is building crypto-agility — the ability to swap algorithms quickly without rewriting the whole system. The first step is a Cryptographic Bill of Materials (CBOM): a complete inventory of where, which algorithm, and which keys are used. Without it, migration is blind and risky.

A Five-Step Roadmap

  1. Discover: build a CBOM of all cryptographic assets across apps, APIs, and mobile banking.
  2. Prioritize: identify long-lived, high-risk data exposed to “harvest now”.
  3. Test: pilot hybrid implementations and measure performance impact.
  4. Migrate: gradually replace with ML-KEM and ML-DSA.
  5. Govern: continuously monitor and update in line with DORA and NIS2.

Frequently asked questions

What is “Harvest Now, Decrypt Later”?

Attackers collect encrypted data today to decrypt it once a powerful quantum computer is available. Long-lived financial data carries the highest risk.

What are ML-KEM and ML-DSA?

NIST-standardized algorithms for the post-quantum era: ML-KEM for key exchange and ML-DSA for digital signatures, replacing RSA and ECC.

How does DORA relate to quantum cryptography?

DORA mandates formal encryption and key-management policies and is the primary driver of the EU's coordinated push toward PQC.

Found this analysis useful?

Follow the related articles in this category and round out your organization's security strategy.

Back to articles

Related articles