Post-quantum cryptography: The emerging threat

The transition to post-quantum cryptography (PQC) is becoming an urgent priority for the global financial sector due to the rapid evolution of quantum computing. 

Cryptographically relevant quantum computers exist only as research prototypes. However, their inevitable development threatens to compromise public-key cryptography—e.g., Rivest-Shamir-Adleman (RSA) and elliptical curve cryptography (ECC)—currently used to protect financial communications, digital signatures, and payment systems. 

For financial services institutions (FSIs) this is of particular concern, with several converging factors:

  • Data longevity of financial records: Highly sensitive and transactional data must remain secured for decades—subject to extensive regulatory mandates—requiring protection against future quantum attacks. 
  • Migration complexity: Transitioning and enhancing global digital infrastructure may be a lengthy process, sometimes with a decade-plus timeframe. This heightens the essential need of early planning. Because large-scale systems remediation in FSI typically takes 5 to 7 years, any data requiring confidentiality beyond the estimated quantum threat horizon (roughly estimated to be 2031), is already compromised if protected solely by classical cryptography.
  • Emerging regulatory requirements: Global and regional regulations are in place, or soon will be, which dictate the preparedness level for FSIs. This includes the U.S. Quantum Computing Cybersecurity Preparedness Act and the EU’s Quantum Europe Strategy, as well as directives from global financial governance bodies like the Global Financial Markets Association (PDF) and the World Economic Forum.

The goal of PQC

The long-term goal of PQC is to establish a quantum-resilient cryptographic ecosystem that’s agile enough to adapt as new standards and threats emerge.

Current public-key encryption relies on virtually unbreakable mathematical problems. But a fully capable quantum computer leaves this level of encryption vulnerable and could decipher currently implemented encoded data streams in a matter of hours. 

Encrypted data is already at risk

Quantum computers capable of breaking current encryption are estimated to be within 2-5 years away, a date often designated as "Q-Day."

Why the urgency?

One of the major drivers for immediate action is the ongoing "harvest now, decrypt later" (HNDL) threat. HNDL is where malicious actors intercept and store encrypted financial data today with the intention of decrypting it once quantum computers are powerful enough and become available.

Fighting traditional and quantum threats 

PQC uses different, more complex math, such as high-dimensional lattices, to maintain resistance. It replaces RSA and ECC public-key algorithms with new mathematical methods to protect against both classical and quantum attacks, providing for long-term confidentiality, authentication, and data integrity across modern cryptographic systems.  

Lattice methods are favored because they balance strong security with efficient performance. They rely on mathematical assumptions that remain difficult for both classical and quantum computers to solve. The best-known examples—ML-KEM (FIPS 203) and ML-DSA (FIPS 204)—form the foundation of the U.S. National Institute of Standards and Technology (NIST)’s post-quantum standards.

Immediate and long-term goals 

In the near term, NIST and global partners will accelerate and refine interoperability, performance benchmarks, and migration tooling. Organizations will expand from in-place classical implementations toward hybrid deployments, while preparing for fully post-quantum environments.

The long-term goal extends beyond algorithm replacement toward the realization of a flexible, quantum-resilient cryptographic ecosystem. Achieving that ideal will require ongoing coordination among standards bodies, hardware manufacturers, and service providers throughout the next decade.

To fully address the future threat, organizations need a proactive endgame strategy anchored in architectural flexibility to enable PQC. 

  • PQC: NIST-standardized mathematical algorithms are the broad, scalable defense layer. Deployable across existing communication channels, high-performance servers, and standard endpoints without requiring extensive hardware upgrades. PQC secures the network protocols and digital signatures across the enterprise. 

This combinational approach minimizes business disruption and distributes migration costs over time.

Implementing PQC will be a phased effort

Preparing for the post-quantum era is more than a cryptography upgrade. Replacing existing encryption is not a trivial undertaking, considering the near-universal dependence on public-key infrastructures linking certificates, trust chains, and authentication processes.

In a practical sense, it will encompass a multiyear transformational effort affecting architectures and vendors across entire ecosystems. Government and industry roadmaps forecast that quantum migrations have the potential to expand through 2030-2035, making early coordination and establishment of working proofs of concept essential.

Organizations may mitigate the complexity of this effort via a hybrid encryption approach in which classical and post-quantum algorithms run simultaneously, permitting systems to remain compatible while gaining quantum resistance. For example, enabling hybrid key exchanges, pairing current encryption with lattice-based algorithms (ML-KEM), allows organizations to test PQC performance and interoperability before making full replacements.  

By institutionalizing this “crypto agility,” anchored in architectural adaptability, the ability to swap algorithms without major system redesign can support phased migrations, making it easier to incorporate future NIST standards as they evolve. Furthermore, the governance required for PQC migration directly enhances operational resilience and regulatory compliance, specifically addressing the requirements of the EU’s Digital Operational Resilience Act (DORA). With robust key lifecycle management and access controls, PQC readiness becomes synonymous with regulatory compliance.

Assessing the migration to PQC 

The combination of strict regulatory deadlines and technological necessity builds a compelling case for immediate action. Procrastination exposes an organization to potentially severe regulatory penalties, and catastrophic system failure. 

The most critical initial steps are centered around executing a comprehensive quantum risk assessment (QRA) to understand precisely where classical cryptography exists—and how it’s used—within the organization. This is followed by a more mature phase focused on embedding crypto agility, implementing phased PQC transition plans, and testing new PQC implementations for performance enhancement.

Phase 1: Cryptographic inventory and QRA 

  • Inventory scope: Deploy automated discovery tools to map all use of public-key cryptography (RSA, ECC, keys, certificates) across hardware, firmware, operating systems, and protocols (Transport Layer Security [TLS], Secure Shell [SSH]).
  • Risk analysis: Classify assets based on criticality, data value, and required secrecy lifetime, explicitly prioritizing systems with high exposure to the HNDL threat. 
    • Distinguish data value: Some data loses sensitivity quickly, but other information—like intellectual property, biometric identifiers, or financial records—must remain secure for decades.
  • Third-party audits: Catalog and audit all critical vendors and subcontractors. These dependencies must provide documented PQC roadmaps aligned with NIST standards to prevent external suppliers from becoming the weakest link.

Phase 2: Architectural remediation and testing

  • Deployment strategy: Implement phased PQC transition plans, often starting with network encryption, to enable quantum-safe standards adoption without immediately overhauling all legacy applications.
  • Testing mandate: Rigorously test and validate new PQC implementations for functional correctness, performance impact, and smooth integration within the complex existing infrastructure. Conduct vendor testing as well.
  • Key management: Upgrade security to accommodate PQC, establishing strict access control policies and secure key replacement procedures.

Coordination across suppliers, cloud providers, and hardware vendors to drive consistent algorithm support and timely updates is mandatory. Large-scale migration(s) will unfold gradually over the next decade, demanding sustained collaboration across the entire technology ecosystem.

Red Hat Enterprise Linux: A strategic catalyst in PQC

Red Hat acknowledges FSIs face an enduring and challenging transition period. We’re actively integrating PQC readiness into our enterprise platforms to provide crucial support for organizations navigating the complex transition to quantum-safe security. 

We’re spearheading both the urgent need to protect against the HNDL threat and help customers meet future global regulatory compliance mandates, helping to foster cryptographic agility.

Red Hat Enterprise Linux (RHEL) 10 is a critical differentiator for organizations and is the 1st enterprise Linux distribution to be post-quantum capable. These developments are especially applicable in security-conscious and highly regulated sectors, such as global banking.

Core PQC advantages in RHEL 10

  • Integration of NIST-aligned algorithms: RHEL 10 incorporates quantum-resistant algorithms into core components, supporting ML-KEM (FIPS 203) and ML-DSA (FIPS 204), with more algorithms planned for subsequent releases.
  • Agile FIPS validation: A new Federal Information Processing Standards (FIPS) module in RHEL 10 allows FIPS cryptographic standards to be validated separately. This is a crucial strength, allowing critical security fixes to be applied immediately without waiting for a new FIPS validation certificate (a process that may take more than 300 days). This agility is especially important for highly regulated environments that can’t afford extended downtime or security vulnerability exposure.
  • Crypto-policy testing: RHEL 10 introduces systemwide crypto-policies and a dedicated testing profile, letting administrators rapidly enforce and validate PQC algorithms in isolated research-and-development environments.
  • Support for a phased, hybrid transition: Red Hat’s 4-phase roadmap is designed to help customers manage the shift, starting with RHEL 10 in the PQ-Capable phase. This phased approach is a major strength, providing a clear path forward for systems relying on underlying IT infrastructure. 
    • Phase 1 - Classical: The traditional state where no quantum-resistant algorithms (QRAs) are available.
    • Phase 2 - PQ-Capable: The introductory phase where RHEL 10 is currently positioned. QRAs and PQC functions are available for use, and systems may be configured to use them, but traditional classical cryptography remains the default setting.
    • Phase 3 - PQ-Ready: A future state where QRAs and PQC functions will become the default wherever available, while classical cryptography will remain configurable as a fallback where needed.
    • Phase 4 - Deprecation and removal: The final stage where classical algorithms will be deprecated and eventually removed. Systems will be specifically designed to resist downgrade attacks, which might try to force a fallback to vulnerable legacy encryption.

This practical path is intended to manage complexity and risk by offering a controlled, hybrid environment aligning with global regulatory momentum, which mandates concrete roadmaps for transitioning critical infrastructure to quantum-resistant cybersecurity by 2030.

Conclusion and further resources

The eventual arrival of cryptographically relevant quantum computers poses an imminent, existential threat to the security infrastructure of the financial sector, which currently relies on soon-to-be vulnerable public-key cryptography. Significant technological, regulatory, and logistical challenges must be tackled immediately, especially concerning mandates with fixed deadlines and malicious actions occurring presently. 

As organizations migrate to a quantum-resistant end state, they must embrace the new reality of a post-quantum cryptography future, which enures: 

  • Long-term confidentiality.
  • Authentication.
  • Data integrity across modern cryptographic systems.

Red Hat is addressing the underlying infrastructure and transitional challenges by embedding PQC readiness directly into the operating system layer to foster cryptographic agility without the need for major system(s) redesign. RHEL 10 is positioned as the foundational operating system platform for PQC-capable architectural overhauls. It’s also key in facilitating Red Hat’s structured migration approach, which introduces architectural crypto flexibility while mitigating the possibility of risks associated with business continuity and strategic exposure. 

Learn more:

Red Hat Product Security

Red Hat believes that everyone, everywhere, is entitled to quality information needed to mitigate security and privacy risks, as well as the access to do so.

About the author

John has extensive experience guiding organizations to success via innovative architecture of products, digital strategy, and customer and user experiences - particularly in online and mobile marketing, e-commerce, product management, web analytics and interactive content development.

UI_Icon-Red_Hat-Close-A-Black-RGB

Keep exploring

Browse by channel

automation icon

Automation

The latest on IT automation for tech, teams, and environments

AI icon

Artificial intelligence

Updates on the platforms that free customers to run AI workloads anywhere

open hybrid cloud icon

Open hybrid cloud

Explore how we build a more flexible future with hybrid cloud

security icon

Security

The latest on how we reduce risks across environments and technologies

edge icon

Edge computing

Updates on the platforms that simplify operations at the edge

Infrastructure icon

Infrastructure

The latest on the world’s leading enterprise Linux platform

application development icon

Applications

Inside our solutions to the toughest application challenges

Virtualization icon

Virtualization

The future of enterprise virtualization for your workloads on-premise or across clouds