Loading…
Loading…
The sector where the mandates already bite and the retention periods are long enough that the exposure is present tense, not a forecast.
Three of these are obligations you already have. The fourth is the reason the first three now include a question nobody was asking five years ago.
Regulation (EU) 2022/2554 has applied since 17 January 2025, with no national transposition step and the European Supervisory Authorities behind it. Its technical standards make cryptographic controls and key management examinable, and crypto-agility is the expectation sitting behind them. This is the only mandate in the post-quantum conversation that already comes with a supervisor.
What DORA asks for →Requirements 4.2.1.1 and 12.3.3 became mandatory on 31 March 2025. Between them they require an inventory of the keys and certificates protecting card data in transit, and cipher suites documented and reviewed at least every twelve months with a plan for responding to cryptographic weakness. PCI sets no quantum deadline, but that annual review is where the question lands.
PCI DSS v4 cryptography →Financial records are kept for years by obligation: transaction histories, KYC and AML files, contracts, audit trails, settlement archives. Encrypted traffic and backups captured today can be decrypted whenever a capable quantum computer exists. For anything with a multi-year confidentiality requirement, the exposure is not a forecast; it started when the data was first transmitted.
Harvest now, decrypt later →Payment infrastructure runs on long-lived trust: certificate hierarchies, HSM-held key material, code-signing roots for terminals and embedded devices in the field. Those signing keys are the assets where a break is least recoverable and where replacement has the longest lead time, which is why they are the wrong thing to leave until last.
Choosing a signature scheme →Every obligation above starts from the same artefact, and most institutions build it two or three times because each requirement asks for its own slice.
PCI 4.2.1.1 wants the keys and certificates protecting card data in transit. DORA wants cryptographic controls and key management across your ICT estate. ISO 27001 A.8.24 wants a cryptographic-controls policy. Post-quantum migration wants every place asymmetric cryptography lives, ranked by how long the data behind it must stay confidential.
These are the same exercise at different scopes. Done at algorithm level once, the narrow answers fall out of the broad one. Done narrowly first, you will do it again, and the second pass is not cheaper than the first.
The method is in our cryptographic inventory guide, qScan produces the machine-readable version, and the deadlines page sets out which obligation binds you first.
Not by name and not on a date. DORA requires cryptographic controls and key management proportionate to risk, kept current, and its technical standards make those examinable. In practice a supervisor asking how you manage cryptographic risk in 2026 is asking a question that includes quantum, and 'we have not looked at it' is a poor answer to give someone with enforcement powers.
For a transaction in flight, the exposure genuinely is lower than for medical records or state archives, and it is worth saying so. The risk in a financial estate sits elsewhere: KYC and contract archives held for years, backups under retention obligations, and the certificate and code-signing hierarchies that outlive every card they protect. Ask the shelf-life question per asset rather than per environment.
With an inventory, because it is the input to every one of these obligations at once. DORA, PCI DSS 4.2.1.1 and 12.3.3, ISO 27001 A.8.24 and every post-quantum mandate all require you to know what cryptography you run and where. Build it once at algorithm level and it satisfies all of them; build it narrowly for a single requirement and you will build it again.
For the leg between your customers and the CDN, largely yes, which is why public adoption figures look encouraging. The connection from the CDN to your origin is a separate handshake with its own algorithms and is frequently still classical, and none of it touches data at rest, inter-service traffic, message brokers or backups. Edge TLS is the easiest surface to fix and rarely the one carrying the most unrecoverable exposure.
A scoping call establishes which obligations bind you first and what an inventory of your estate would involve. It is a paid engagement and it produces a scope document, not a proposal.