Payments has the tightest constraints of any sector. A 300-millisecond contactless budget, an authentication field measured in a couple of hundred bytes, a terminal estate that turns over across years rather than quarters, and certification gates that add months to every hardware change. None of those move because a standard was published.
This is a working day. You bring your own authorization flows, your HSM estate, and your terminal refresh schedule, and you leave with a plan sequenced against the gates that govern it.
Who this intensive is for
Payment security architects, cryptography and HSM engineers, terminal and card product managers, scheme compliance leads, and the risk staff who will sign the plan. It suits issuers, acquirers, processors, schemes, terminal manufacturers, and payment service providers.
Mixed teams get more from the day than individuals, because the engineer who knows the HSM estate rarely knows the terminal refresh schedule and neither of them owns the scheme relationship.
What you’ll be able to do afterward
- Size the post-quantum problem inside your own authorization path against its latency and message-size budgets
- Map the card and terminal installed base, and say which of it migrates in place and which is replaced
- Sequence migration around dual FIPS 140-3 and PCI PTS certification gates and the months they add
- Apply what BIS Project Leap Phase 2 established to your own settlement and messaging paths
- Use the ISO 20022 migration as the modernization window rather than running two competing programs
- Meet PCI DSS 12.3.3 with a cryptographic inventory that is genuinely usable rather than a compliance artifact
What you leave with
Every participant receives the course handbook, a PDF of the full material with the instructor notes written out, and a PDF copy of Quantum Ready. The day itself produces a payment cryptographic exposure worksheet covering the authorization path end to end, a card and terminal population model populated with your own refresh data, a certification gate calendar, and a scheme and processor coordination plan. All are editable and yours to keep.
The day
Morning, first block. The authorization path. Trace cryptography through your own flows. Where the budgets bind, where they do not, and where nobody has measured.
Morning, second block. The installed base. Cards, terminals, and HSMs. Building the population model and separating in-place migration from replacement.
Afternoon, first block. Gates and coordination. Certification sequencing. Scheme timelines. What you cannot do alone and who else has to move first.
Afternoon, second block. The plan. Assemble the roadmap against the gate calendar. Draft the scheme and vendor conversations the plan depends on.
Where this sits in your path
Quantum-Safe Payments is the prerequisite in substance rather than in rule. It covers the same ground at overview depth, and participants who arrive having taken it start the day with the vocabulary already shared. Afterward, PKI Modernization for Post-Quantum for the teams that own key material, and Cryptographic Discovery, Inventory, and CBOM for whoever runs discovery.
Why we teach this
The day is built on the Payments Extension of the Applied Quantum PQC Migration Framework, published openly under Creative Commons at pqcframework.org. The instructors run migration programs in this sector, and that is where the constraints in this material come from.