Post-quantum cryptography: The emerging threatThe transition to post-quantum cryptography (PQC) is becoming an urgent priority for the global financial sector due to the rapid evolution of quantum computing. Cryptographically relevant quantum computers exist only as research prototypes. However, their inevitable development threatens to compromise public-key cryptography—e.g., Rivest-Shamir-Adleman (RSA) and elliptical curve cryptography (ECC)—currently used to protect financial communications, digital signatures, and payment systems. For financial services institutions (FSIs) this is of particular concern, with several converging factors:Data longevity of financial records: Highly sensitive and transactional data must remain secured for decades—subject to extensive regulatory mandates—requiring protection against future quantum attacks. Migration complexity: Transitioning and enhancing global digital infrastructure may be a lengthy process, sometimes with a decade-plus timeframe. This heightens the essential need of early planning. Because large-scale systems remediation in FSI typically takes 5 to 7 years, any data requiring confidentiality beyond the estimated quantum threat horizon (roughly estimated to be 2031), is already compromised if protected solely by classical cryptography.Emerging regulatory requirements: Global and regional regulations are in place, or soon will be, which dictate the preparedness level for FSIs. This includes the U.S. Quantum Computing Cybersecurity Preparedness Act and the EU’s Quantum Europe Strategy, as well as directives from global financial governance bodies like the Global Financial Markets Association (PDF)1 and the World Economic Forum.The goal of PQCThe long-term goal of PQC is to establish a quantum-resilient cryptographic ecosystem that’s agile enough to adapt as new standards and threats emerge.Current public-key encryption relies on virtually unbreakable mathematical problems. But a fully capable quantum computer leaves this level of encryption vulnerable and could decipher currently implemented encoded data streams in a matter of hours. Encrypted data is already at riskQuantum computers capable of breaking current encryption are estimated to be within 2-5 years away, a date often designated as "Q-Day."Why the urgency?One of the major drivers for immediate action is the ongoing "harvest now, decrypt later" (HNDL) threat. HNDL is where malicious actors intercept and store encrypted financial data today with the intention of decrypting it once quantum computers are powerful enough and become available.Fighting traditional and quantum threats PQC uses different, more complex math, such as high-dimensional lattices, to maintain resistance. It replaces RSA and ECC public-key algorithms with new mathematical methods to protect against both classical and quantum attacks, providing for long-term confidentiality, authentication, and data integrity across modern cryptographic systems. Lattice methods are favored because they balance strong security with efficient performance. They rely on mathematical assumptions that remain difficult for both classical and quantum computers to solve. The best-known examples—ML-KEM (FIPS 203) and ML-DSA (FIPS 204)—form the foundation of the U.S. National Institute of Standards and Technology (NIST)’s post-quantum standards.Immediate and long-term goals In the near term, NIST and global partners will accelerate and refine interoperability, performance benchmarks, and migration tooling. Organizations will expand from in-place classical implementations toward hybrid deployments, while preparing for fully post-quantum environments.The long-term goal extends beyond algorithm replacement toward the realization of a flexible, quantum-resilient cryptographic ecosystem. Achieving that ideal will require ongoing coordination among standards bodies, hardware manufacturers, and service providers throughout the next decade.To fully address the future threat, organizations need a proactive endgame strategy anchored in architectural flexibility, combining PQC with Quantum Key Distribution (QKD). PQC: NIST-standardized mathematical algorithms are the broad, scalable defense layer. Deployable across existing communication channels, high-performance servers, and standard endpoints without requiring extensive hardware upgrades. PQC secures the network protocols and digital signatures across the enterprise.1QKD: Provides an information-theoretic, provably secure key exchange. Ideal for securing critical, high-throughput, point-to-point links, such as Data Center Interconnects (DCIs). This combinational approach minimizes business disruption and distributes migration costs over time.Implementing PQC will be a phased effortPreparing for the post-quantum era is more than a cryptography upgrade. Replacing existing encryption is not a trivial undertaking, considering the near-universal dependence on public-key infrastructures linking certificates, trust chains, and authentication processes.In a practical sense, it will encompass a multiyear transformational effort affecting architectures and vendors across entire ecosystems. Government and industry roadmaps forecast that quantum migrations have the potential to expand through 2030-2035, making early coordination and establishment of working proofs of concept essential.Organizations may mitigate the complexity of this effort via a hybrid encryption approach in which classical and post-quantum algorithms run simultaneously, permitting systems to remain compatible while gaining quantum resistance. For example, enabling hybrid key exchanges, pairing current encryption with lattice-based algorithms (ML-KEM), allows organizations to test PQC performance and interoperability before making full replacements. By institutionalizing this “crypto agility,” anchored in architectural adaptability, the ability to swap algorithms without major system redesign can support phased migrations, making it easier to incorporate future NIST standards as they evolve. Furthermore, the governance required for PQC migration directly enhances operational resilience and regulatory compliance, specifically addressing the requirements of the EU’s Digital Operational Resilience Act (DORA). With robust key lifecycle management and access controls, PQC readiness becomes synonymous with regulatory compliance.Assessing the migration to PQC The combination of strict regulatory deadlines and technological necessity builds a compelling case for immediate action. Procrastination exposes an organization to potentially severe regulatory penalties, and catastrophic system failure. The most critical initial steps are centered around executing a comprehensive quantum risk assessment (QRA) to understand precisely where classical cryptography exists—and how it’s used—within the organization.1 This is followed by a more mature phase focused on embedding crypto agility, implementing phased PQC transition plans, and testing new PQC implementations for performance enhancement.Phase 1: Cryptographic inventory and QRA Inventory scope: Deploy automated discovery tools to map all use of public-key cryptography (RSA, ECC, keys, certificates) across hardware, firmware, operating systems, and protocols (Transport Layer Security [TLS], Secure Shell [SSH]).1Risk analysis: Classify assets based on criticality, data value, and required secrecy lifetime, explicitly prioritizing systems with high exposure to the HNDL threat.1 Distinguish data value: Some data loses sensitivity quickly, but other information—like intellectual property, biometric identifiers, or financial records—must remain secure for decades.Third-party audits: Catalog and audit all critical vendors and subcontractors. These dependencies must provide documented PQC roadmaps aligned with NIST standards to prevent external suppliers from becoming the weakest link.1Phase 2: Architectural remediation and testingDeployment strategy: Implement phased PQC transition plans, often starting with network encryption, to enable quantum-safe standards adoption without immediately overhauling all legacy applications.Testing mandate: Rigorously test and validate new PQC implementations for functional correctness, performance impact, and smooth integration within the complex existing infrastructure. Conduct vendor testing as well.Key management: Upgrade security to accommodate PQC, establishing strict access control policies and secure key replacement procedures.Coordination across suppliers, cloud providers, and hardware vendors to drive consistent algorithm support and timely updates is mandatory. Large-scale migration(s) will unfold gradually over the next decade, demanding sustained collaboration across the entire technology ecosystem.Red Hat Enterprise Linux: A strategic catalyst in PQCRed Hat acknowledges FSIs face an enduring and challenging transition period. We’re actively integrating PQC readiness into our enterprise platforms to provide crucial support for organizations navigating the complex transition to quantum-safe security. We’re spearheading both the urgent need to protect against the HNDL threat and help customers meet future global regulatory compliance mandates, helping to foster cryptographic agility.1Red Hat Enterprise Linux (RHEL) 10 is a critical differentiator for organizations and is the 1st enterprise Linux distribution to be post-quantum capable. These developments are especially applicable in security-conscious and highly regulated sectors, such as global banking.Core PQC advantages in RHEL 10Integration of NIST-aligned algorithms: RHEL 10 incorporates quantum-resistant algorithms into core components, supporting ML-KEM (FIPS 203) and ML-DSA (FIPS 204), with more algorithms planned for subsequent releases.1Agile FIPS validation: A new Federal Information Processing Standards (FIPS) module in RHEL 10 allows FIPS cryptographic standards to be validated separately. This is a crucial strength, allowing critical security fixes to be applied immediately without waiting for a new FIPS validation certificate (a process that may take more than 300 days).1 This agility is especially important for highly regulated environments that can’t afford extended downtime or security vulnerability exposure.Crypto-policy testing: RHEL 10 introduces systemwide crypto-policies and a dedicated testing profile, letting administrators rapidly enforce and validate PQC algorithms in isolated research-and-development environments.1Support for a phased, hybrid transition: Red Hat’s 4-phase roadmap is designed to help customers manage the shift, starting with RHEL 10 in the PQ-Capable phase. This phased approach is a major strength, providing a clear path forward for systems relying on underlying IT infrastructure. Phase 1 - Classical: The traditional state where no quantum-resistant algorithms (QRAs) are available.Phase 2 - PQ-Capable: The introductory phase where RHEL 10 is currently positioned. QRAs and PQC functions are available for use, and systems may be configured to use them, but traditional classical cryptography remains the default setting.Phase 3 - PQ-Ready: A future state where QRAs and PQC functions will become the default wherever available, while classical cryptography will remain configurable as a fallback where needed.Phase 4 - Deprecation and removal: The final stage where classical algorithms will be deprecated and eventually removed. Systems will be specifically designed to resist downgrade attacks, which might try to force a fallback to vulnerable legacy encryption.This practical path is intended to manage complexity and risk by offering a controlled, hybrid environment aligning with global regulatory momentum, which mandates concrete roadmaps for transitioning critical infrastructure to quantum-resistant cybersecurity by 2030.1Conclusion and further resourcesThe eventual arrival of cryptographically relevant quantum computers poses an imminent, existential threat to the security infrastructure of the financial sector, which currently relies on soon-to-be vulnerable public-key cryptography. Significant technological, regulatory, and logistical challenges must be tackled immediately, especially concerning mandates with fixed deadlines and malicious actions occurring presently. As organizations migrate to a quantum-resistant end state, they must embrace the new reality of a post-quantum cryptography future, which enures: Long-term confidentiality.Authentication.Data integrity across modern cryptographic systems.Red Hat is addressing the underlying infrastructure and transitional challenges by embedding PQC readiness directly into the operating system layer to foster cryptographic agility without the need for major system(s) redesign. RHEL 10 is positioned as the foundational operating system platform for PQC-capable architectural overhauls. It’s also key in facilitating Red Hat’s structured migration approach, which introduces architectural crypto flexibility while mitigating the possibility of risks associated with business continuity and strategic exposure. Learn more:Post-quantum cryptography for Red Hat Enterprise LinuxPreparing your organization for the quantum future
No time to lose: Why post-quantum security for financial services must start now
Now is the time to prepare your financial data for the the post-quantum era with Red Hat Enterprise Linux 10's post-quantum cryptography support.






