Quantum Academy begins operations on September 15, 2026. Enrollment opens soon.
Skip to content

Sectors

Quantum Computing in Finance: What Has a Deadline and What Does Not

Marin Ivezic12 min read

On August 13, 2024, the U.S. National Institute of Standards and Technology (NIST) published three finished cryptographic standards: FIPS 203, 204 and 205. They define ML-KEM for establishing shared keys, ML-DSA for digital signatures, and SLH-DSA as a signature reserve built on different mathematics in case the first one is broken. In November 2024 NIST followed with a draft transition schedule, NIST IR 8547, which proposes that RSA-2048 and 256-bit elliptic-curve cryptography be deprecated after 2030 and disallowed after 2035.

Those dates are why quantum computing reached finance agendas years before any quantum computer can do anything useful for a bank. They also cover only half the subject. The other half, the compute half, has no dates on it and much thinner evidence behind it. Vendor decks and board briefings routinely present the two as one topic, and that’s a budgeting error rather than a presentational one. This guide separates them.

Two Programs Wearing One Name

The first program replaces cryptography. It is owned by the chief information security officer and the chief technology officer, it runs through procurement and vendor management, it has regulatory dates attached, and its success criterion is that nothing visible happens. The work is inventory, contract language, firmware paths and testing. It’s unglamorous, and it isn’t optional.

The second program explores whether quantum hardware will ever price a derivative or rebalance a portfolio faster than a well-tuned classical machine. It is owned by quantitative research or an innovation function, it has no deadline, and its honest justification is option value: a small standing capability so the institution can recognise a real result when one appears.

We see the failure mode often enough to name it. An institution funds a small quantum algorithms team, publishes a paper with a hardware vendor, and has no idea how many of its cryptographic dependencies belong to third parties. It has bought the optional half and skipped the mandatory one. The reverse failure is rarer and cheaper.

The Migration Side

What Has a Date

NIST’s three standards are final, which means vendors can now build against them rather than against candidates. NIST IR 8547 turns that into a schedule, and although the document is a draft and applies formally to U.S. federal systems, supervisors and large clients tend to adopt federal dates as a reference point.

The European Commission issued a recommendation in April 2024 asking member states to coordinate a post-quantum migration roadmap, and the follow-up work set a target for high-risk use cases before the end of the decade. Separately, the Digital Operational Resilience Act has applied to EU financial entities since January 2025. DORA says nothing about quantum computing. What it does is make the documentation of cryptographic controls and third-party dependency a supervisory matter, which is precisely the documentation a post-quantum migration requires.

There is also a second-order effect worth planning around. The NSA’s CNSA 2.0 suite applies to U.S. national security systems, not to commercial banks. But the vendors who sell hardware security modules, network equipment and certificate management software to banks also sell to defence buyers. Their post-quantum firmware roadmaps are being set by the defence timeline, and you will inherit those roadmaps whether or not you asked for them.

What Data Needs the Long Horizon

“Harvest now, decrypt later” (HNDL) describes an adversary who copies encrypted traffic today, stores it, and waits for a machine capable of decrypting it. Whether that is a real exposure for a given data flow depends on one question, and you can answer it without knowing anything about quantum physics: how long does this data have to stay confidential?

Take a 30-year mortgage originated in March 2026. The origination file carries identity documents, income history, account numbers and the borrower’s address history. Its confidentiality requirement runs past 2056. If the session that carried it is captured in 2026 and decrypted in 2040, the exposure is real and the borrower is still alive and still on that mortgage. Now take an intraday foreign exchange quote. Its confidentiality requirement is measured in seconds. Nobody will care about it in 2040, and no HNDL argument applies.

That contrast is the whole triage. In a typical financial institution the long-lifetime categories are a short list:

  • Know-your-customer packets and the identity documents inside them
  • Corporate advisory, merger and syndicated lending material
  • Long-dated derivative contracts, collateral agreements and their supporting positions
  • Custody and wallet key material, where the key itself is the asset
  • Employee payroll, pension and health records

Most traffic in a bank doesn’t belong on that list. Working out which flows do, and where each of them is encrypted, is the first deliverable of a migration program and the one most often skipped.

Where the Estate Locks In

The date that constrains a bank is usually not 2030 or 2035. It’s the next hardware refresh.

Consider hardware security modules. An HSM is a tamper-resistant appliance that holds and uses the keys behind payment authorisation, card issuance and certificate signing, and it never lets the key material out. Bank HSM fleets refresh on cycles of roughly seven to ten years, and the appliances are certified, audited and slow to change. An HSM purchased in 2027 with no firmware path to ML-KEM and ML-DSA is a 2035 problem bought at 2027 prices. The question belongs in the request for proposal, not in a later remediation plan.

The card estate works the same way from the other direction. EMV chip cards reissue on three-to-five-year cycles, and the cryptography they use is specified by the payment schemes rather than by the issuer. A bank can’t unilaterally migrate its cards. What it can do is know how many reissue cycles separate it from a scheme mandate, and make sure its issuance platform will not be the constraint when the mandate arrives.

Underneath all of this is an inventory problem. A cryptographic bill of materials, or CBOM, is a machine-readable list of every algorithm, key, certificate and cryptographic library in a system, together with where each one is used; we will call it the inventory from here. You can’t schedule the replacement of a dependency you can’t name, and in finance the majority of dependencies belong to somebody else: core banking vendors, payment processors, market data providers, custodians, clearing houses.

That’s why the migration is a vendor management exercise more than an engineering one. The engineering is largely done. NIST finished it in August 2024.

The Compute Side

Now the other program, held to the same standard of evidence.

Derivative Pricing and Monte Carlo

Monte Carlo simulation prices a complex instrument by simulating a large number of possible market paths and averaging the results. Its inconvenient property is that accuracy improves only with the square root of the number of runs, so cutting the error in half costs four times the compute. That property is why banks run risk in overnight batches rather than continuously.

Quantum amplitude estimation improves that scaling quadratically. The theorem is real and it has been known since the 1990s. The difficulty is the constant factors, and finance has one of the better public estimates of what they cost.

A 2021 study in the journal Quantum by researchers at JPMorgan Chase and IBM, A Threshold for Quantum Advantage in Derivative Pricing, worked out the resources needed to price a representative autocallable derivative fast enough to beat the classical overnight run. Their estimate came to roughly 7,500 logical qubits running at a logical clock rate around 10 MHz, which is far above what error-corrected architectures are currently projected to deliver.

The word “logical” is doing heavy work in that sentence. A logical qubit is an error-corrected qubit assembled from many physical ones, and how many depends on the hardware error rate and the error-correcting code, so a device with 7,500 logical qubits is a far larger machine in physical terms than the figure suggests. Devices demonstrated publicly today are in the low thousands of physical qubits with no error correction at that scale. For comparison, Craig Gidney of Google Quantum AI estimated in May 2025, in How to factor 2048 bit RSA integers with less than a million noisy qubits, that the job would take fewer than one million noisy qubits running for under a week, which tells you that breaking the cryptography is currently the easier engineering target than pricing the derivative.

The work is worth funding, provided the date on it is honest and a pricing result never shares a slide with a cryptographic deadline.

Portfolio Optimization

Portfolio optimization asks for the weights across a set of assets that maximise return for a given level of risk. The continuous version has been solved since the 1950s. What makes the production version hard is the constraints: minimum lot sizes, position limits, sector caps, turnover budgets, transaction costs. Those constraints are discrete, and discrete constraints are where the problem becomes combinatorial.

Quantum approximate optimization and quantum annealing have both been tested against small instances of this problem. Where published comparisons include a properly tuned classical baseline rather than a textbook implementation, the classical baseline generally wins at the sizes tested so far. Some of you will read that as dismissal, and we would rather argue it out than soften it: the most useful thing this line of research has produced for finance to date is better classical solvers, because the quantum-inspired methods fed back into tensor-network and annealing techniques that run on ordinary hardware today. That’s a genuine return on the research budget. It isn’t the return the decks describe.

Fraud Detection and Machine Learning

Quantum machine learning refers to models where part of the computation runs on quantum hardware. HSBC has announced collaborations with Quantinuum on fraud detection and on trading applications, and several other institutions have run comparable pilots.

The caveat here is structural rather than about any particular result. On classical data, quantum machine learning has no proven general advantage, and the data-loading step is usually the reason. Getting a large classical dataset into a quantum state costs roughly as much as the speedup is meant to save. Fraud detection is an unusually poor fit for the difficulty, because the datasets are enormous, the features are classical, and the latency requirement is tight.

Reading a Vendor Result

Executives and investors don’t need to evaluate the algorithms. They need four questions, and the answers are usually in the paper.

  1. Physical or logical qubits, and how many? A result quoted in logical qubits and a device quoted in physical qubits are separated by two or three orders of magnitude.
  2. What was the classical baseline? If the comparison is against an untuned or textbook classical implementation, the result says nothing.
  3. What problem size, and how does the cost scale? A five-asset portfolio is a demonstration. A 500-asset portfolio is a business.
  4. Hardware or simulation? Simulated results are legitimate research and are not evidence that hardware can do it.

We teach that checklist to non-technical participants because it works across every claim in this section without requiring a physics background.

Where QKD and QRNG Fit

Quantum key distribution (QKD) uses the physics of single photons to exchange encryption keys in a way that makes eavesdropping detectable. HSBC reported in 2023 that it had used QKD to protect a GBP 30 million foreign exchange trade, and similar point-to-point trials have run between central banks. The technology is real and it works.

Its limits are also real. QKD needs dedicated fibre or line of sight, it doesn’t authenticate the parties on its own, and it doesn’t extend to the internet-facing estate where almost all of a bank’s cryptographic exposure actually is. Both the NSA and the UK’s National Cyber Security Centre have advised against QKD as the basis for securing national security communications and recommend post-quantum cryptography instead. For a bank, QKD is a reasonable option for a small number of high-value links between owned facilities, and it isn’t a migration strategy.

A quantum random number generator (QRNG) produces randomness from a physical quantum process rather than from an algorithm. Key generation genuinely depends on good randomness, and QRNG devices are inexpensive and easy to deploy. In most banking systems a certified classical entropy source already meets the requirement, so this is an improvement at the margin rather than a control gap being closed.

Neither technology substitutes for replacing the algorithms. Both are sometimes sold as if they do.

What Boards Are Being Asked

Three questions separate an institution with a program from an institution with a slide.

Which of our data flows have confidentiality requirements past 2035, and where are they encrypted? This is the HNDL triage, and it produces a short list rather than a boil-the-ocean project.

What is in the inventory, and how much of it belongs to third parties? The answer determines whether this is an engineering program or a vendor management program. In finance it is usually the latter.

What in the next hardware and contract cycle locks us in past 2030? HSMs, payment platforms, certificate authorities, core banking renewals. The cheapest migration work available anywhere is a clause in a contract you are signing this year.

That clause has a name. Crypto-agility means the ability to change cryptographic algorithms without re-architecting the system around them, and in a procurement context it translates into specific commitments: a named firmware path to the NIST standards, a supported timeline, and the right to test it. Asking for crypto-agility in an RFP costs nothing. Discovering in 2033 that a certified appliance cannot be upgraded costs a replacement cycle.

For investors, the same three questions work as diligence questions, and the second one is the most revealing. An institution that can produce a cryptographic inventory on request has done the work. An institution that answers with a research partnership has not.

Building the Capability

The scarce skill inside a financial institution is translation. Somebody has to read a vendor’s quantum claim and the institution’s own cryptographic dependency map in the same afternoon, and then say which budget line each one touches and in which year. That person doesn’t need a physics degree, and in our experience the people who do it best come from risk, architecture and procurement rather than from research.

Quantum Academy builds that capability for finance teams: the vocabulary to read a quantum result without deferring to the vendor who produced it, the triage method for identifying long-lifetime data, and the procurement and inventory practices that turn a 2035 date into work scheduled across the next three contract cycles. You can see the current programs at quantumacademy.com/.

Two companions are worth having open alongside the training. The PQC Framework sets out the migration methodology in detail, including inventory structure and phasing. And PostQuantum.com carries the deeper technical treatment of the finance use cases for readers who want the underlying research rather than the executive reading of it. For teams working out who should own this internally, QuantumCareers.com maps the roles that are actually being hired for.

The dates in the first paragraph of this article are the only ones in the subject that are firm. Everything else is optionality, and optionality is cheap to hold and expensive to mistake for an obligation.