Mastodon Skip to content
LIVE - NYSE/-/- CRYPTO/OPEN/24/7
BTC$84,171▲ 1.68%ETH$2,716▲ 2.57%SOL$119.77▲ 1.45%TOTAL CRYPTO$2.87T▼ 1.10%S&P 5007,658.44▼ 0.69%NASDAQ26,769.38▲ 1.39%DOW51,157.92▼ 4.48%GOLD4,193.10▼ 7.44%WTI91.55▲ 9.77%BRENT96.98▲ 8.59%EUR/USD1.1334▼ 2.76%USD/JPY157.66▼ 1.04%DXY101.48▲ 1.78%
Technology

EU Tells Banks to Adopt Quantum-Safe Encryption by 2030

ENISA published guidance urging banks, payment providers and blockchain platforms to move critical systems to post-quantum cryptography by 2030.

The European Union Agency for Cybersecurity told banks, payment providers and blockchain platforms on Monday to move critical systems to post-quantum cryptography by 2030. The guidance from ENISA, published in Athens, follows warnings that advances in quantum computing could eventually break the algorithms securing everything from wire transfers to Bitcoin.

The agency directed institutions toward standards finalized by the US National Institute of Standards and Technology, chiefly the ML-KEM and ML-DSA algorithms. Financial firms should complete an inventory of systems using vulnerable cryptography within a year and prioritize long-lived data and high-value transaction infrastructure first.

Why the deadline is now

The driving concern is the harvest now, decrypt later attack. An adversary can record encrypted traffic today and store it until a sufficiently powerful quantum computer exists, then decrypt it retroactively. Data with a long shelf life, client records, settlement instructions, state secrets, is therefore exposed already, even though no cryptographically relevant quantum computer has been publicly demonstrated.

ENISA guidance aligns with a European Commission roadmap that sets 2030 as the deadline for high-risk use cases and 2035 for the wider economy. The agency acknowledged that migrations at large banks can take several years, which is precisely why the planning needs to start well before the deadline rather than after the first credible quantum threat appears.

What it means for crypto

Blockchain platforms got a direct mention, which is new for an EU cybersecurity directive at this level of detail. Bitcoin and Ethereum rely on elliptic curve signatures that quantum computers running Shor algorithm could theoretically forge. Researchers distinguish between the exposure of public keys, which become visible when coins are spent from an address, and unused addresses, whose public keys remain hidden. Estimates of when a machine capable of breaking those signatures might exist range from the early 2030s to much later, and the uncertainty is itself part of the planning problem.

Several blockchains have already drafted quantum-resistant migration paths, but none has executed one. Moving a live network to new signature schemes requires coordinated soft forks across millions of nodes and wallets, a process with no successful precedent at this scale. The EU guidance does not require blockchain migration by 2030, but it puts the sector on notice that European regulators expect a plan.

The banking bill

Industry groups, including the European Banking Federation, warned that the shift will require significant investment and coordination across payment networks. Every payment card, HSM, and interbank messaging link eventually needs new cryptographic primitives, and legacy hardware often cannot run the post-quantum algorithms efficiently. Some post-quantum signatures are an order of magnitude larger than the ones they replace, which stresses protocols designed around tight packet sizes.

Deadline Scope
Within 1 year Inventory of vulnerable cryptographic systems
2030 High-risk use cases migrated to post-quantum standards
2035 Wider economy migration complete

The United States moved first on the same problem. NIST finalized its post-quantum standards in 2024, and US financial regulators have issued their own notices urging preparation without setting a hard date. The EU now goes further by attaching a deadline, and the divergence will complicate life for global banks that operate on both sides of the Atlantic under two timelines.

ENISA cautioned that delay would leave sensitive financial and personal data exposed once large-scale quantum computers mature. The agency framing puts the burden on institutions to show progress, not just intent. For banks that have spent the past two years absorbing cyber incident reporting rules under DORA, the quantum migration is one more compliance line item with a real engineering cost behind it.

The practical first step for most institutions is unglamorous: find out where the vulnerable cryptography actually lives. Surveys repeatedly show that large organizations discover significant undocumented cryptographic dependencies during exactly this kind of inventory, and the discovery phase alone has taken some early movers more than a year.

Not everyone treats the timeline as urgent. Some cryptographers argue that fault-tolerant quantum machines capable of running Shor algorithm at the required scale remain far away, and that mandatory deadlines divert security budgets from threats that are actively causing losses today, ransomware above all. The counterargument, which ENISA effectively endorses, is that cryptographic migration is the slowest kind of security project, and waiting for the threat to be proven means starting too late by definition.

There is also a standards wrinkle worth watching. Early deployments of hybrid schemes, which combine classical and post-quantum algorithms, have exposed implementation bugs, including a 2025 incident where a flaw in a widely used hybrid key exchange library weakened both components rather than either alone. Migration is not a drop-in replacement, and the testing period is part of why the deadlines stretch to 2030 and 2035 rather than next year.

For European crypto firms under MiCA licensing, the guidance lands as one more item on an already long compliance list. But it also offers a small competitive angle: exchanges and custodians that can demonstrate a credible quantum-readiness plan may find it easier to win institutional mandates, particularly from banks whose own regulators are now asking the same question of their counterparties.

Vendors are already selling against the deadline. Hardware security module makers have shipped firmware supporting ML-KEM and ML-DSA, and consultancies have stood up post-quantum readiness practices staffed largely by the same people who ran Y2K and GDPR programs. Buyers should expect a range in quality, and the ENISA inventory requirement is a useful filter: any vendor that cannot map your cryptographic estate accurately is not going to migrate it either.

SourcesENISA guidance, September 28, 2026; European Commission post-quantum roadmap; NIST post-quantum standards; Next Edition
Share: X