PQC Migration for Banking, Capital Markets, and Insurance
Financial services is among the most cryptography-dense environments in existence. In a cryptographic discovery exercise our faculty ran on representative components, written up in The Cryptographic Iceberg Inside a Mobile Banking Transaction, opening a mobile banking app triggered approximately 320 cryptographic function calls, and a cross-border payment chain traversed upward of 30,000 unique cryptographic functions across nine parties. Those figures illustrate order of magnitude rather than an industry benchmark. The same pattern shows up in the institutions the course authors have worked with. Most of those functions will need to transition to post-quantum algorithms, and the binding constraint is not any one institution’s readiness but the coordination across interconnected counterparties, payment networks, and market infrastructure.
This course applies the PQC Migration Framework to the financial services sector, covering the specific regulatory requirements, the multi-party coordination challenge, and the structural advantages that well-governed financial institutions bring to the transition.
Course Outline
Module 1. The Financial Services Cryptographic Estate
The density and interconnectedness of cryptography in financial services. Inter-bank payment flows and their cryptographic dependencies. Trading, clearing, and settlement systems. Customer-facing channels. The multi-party coordination challenge: why no single institution can migrate in isolation.
Module 2. Regulatory Drivers
G7 Cyber Expert Group guidance and its implications. PCI DSS PQC roadmap. DORA crypto-agility requirements. MAS and HKMA directives. SEC disclosure considerations. How regulatory timelines differ across jurisdictions and what that means for global institutions.
Module 3. Migration Strategy for Financial Services
Where to start: high-value data at rest versus high-volume data in transit. The HSM estate challenge. Cross-border coordination requirements. The sector’s structural advantages: mature governance, established vendor relationships, and regulatory pressure that justifies budget. Building the financial services-specific migration roadmap.
Module 4. Implementation Considerations
HSM upgrade and key management migration. SWIFT and payment network coordination. Trading platform cryptographic migration. Regulatory reporting during transition. Testing and validation in financial services environments.
Prerequisites
None. Sector experience is helpful but not required. For a broader PQC foundation, consider starting with Post-Quantum Foundation.
Certificate of Completion
Upon completion, you will receive a Quantum Academy certificate of completion. This is not a professional certification.
Who this course is for
Security leaders, risk managers, compliance officers, technology architects, and program managers at banks, broker-dealers, asset managers, insurers, and financial market infrastructure operators. Also appropriate for financial regulators and supervisory technology specialists.
What you’ll be able to do afterward
- Assess the cryptographic density of financial services environments and identify migration scope
- Map financial sector regulatory requirements (G7 CEG roadmap, PCI DSS v4.0 Requirement 12.3.3, DORA, NIS2, HKMA Quantum Preparedness Index) to migration timelines
- Plan multi-party PQC migration across interbank messaging, payment networks, and market infrastructure
- Address HSM-intensive environments and key management migration challenges
- Coordinate with sector coordination bodies (FS-ISAC PQC Working Group, Quantum Safe Financial Forum)
- Apply the financial sector’s structural advantages (three-lines governance, examination-hardened evidence culture, mature third-party risk programs) to accelerate migration
What you leave with
You leave with the course handbook, a PDF of the full material with the instructor notes written out in place of the slides’ bullet points, and a PDF copy of Quantum Ready, included at no extra cost. The handbook is yours to keep. For most organizations, that shared reference is the clearest return on a training budget.
Enrollment includes 180 days of access to the online on-demand course. Where that course is not yet published, the 180 days start on the day it is.
Where this course fits
Nothing is required. Post-Quantum Foundation covers the algorithm vocabulary if you want it first. The Quantum-Safe Financial Services Intensive is the full-day working session where you build the plan. Cryptographic Discovery, Inventory, and CBOM suits teams about to start discovery.
Why we teach this
The course is built on the Financial Services Extension of the Applied Quantum PQC Migration Framework, published openly under Creative Commons at pqcframework.org and written by the practitioners who teach here. Our faculty runs migration programs in this sector, and that is where the constraints in this material come from.
About this program
Quantum Academy credentials are private professional credentials issued by Quantum Academy, a trade name of Post-Quantum Institute. They are not government-issued licenses, accredited degrees, or academic credit, and earning one does not guarantee employment, promotion, regulatory approval, or any other specific outcome.
Quantum Academy programs are educational and informational only, and are not legal, compliance, or engineering advice.