Why Regulators Now Care About Your Cryptography
Cryptography used to be an engineering detail. Payment standards, financial supervisors and governments now ask for evidence about it. Here is why, and what kinds of rules exist.
Checked against primary sources and independently reviewed on . Sources are listed at the end.
Choosing an encryption algorithm has traditionally been treated as an engineering decision, made by developers and product vendors and reviewed, if at all, as a technical detail. That is changing. Over the last few years, payment card standards, EU financial rules, central banks and national governments have started to ask organisations to show which cryptography they use, where it runs and how they plan to change it. The Monetary Authority of Singapore published its quantum advisory in February 2024, a new payment card requirement became mandatory in March 2025, and several supervisors and governments followed with dated expectations in 2026.
This article explains what is driving that shift, the different kinds of rules you will meet, and the one request that almost all of them share. The rest of this section looks at each framework in more detail.
The Problem Regulators Are Responding To
Most secure connections and digital signatures rely on public-key algorithms such as RSA and elliptic curve cryptography. These are the algorithms that let two parties agree a secret key over an open network and let software prove who signed it. A large enough quantum computer, often called a cryptographically relevant quantum computer, could break those algorithms. The US Office of Management and Budget put the current position plainly in June 2026: such a machine “is not yet known to exist”, but steady progress could produce one within the coming decade.1
The timing matters less than you might expect, because of a tactic known as harvest now, decrypt later. An attacker can record encrypted traffic today and decrypt it once the capability exists. The G7 Cyber Expert Group, which advises G7 finance ministers and central bank governors, notes that under this scenario data can be at risk long before a quantum computer of that size appears.2
Migration is also slow. Cryptography sits inside applications, network devices, hardware security modules, vendor products and partner connections. Replacing it means finding it first, then testing, buying and rolling out alternatives. Regulators have concluded that organisations which wait for certainty will not finish in time.
Why Cryptography Became An Audit Topic
Three things turned this from a research topic into a compliance one.
First, standards caught up. The US National Institute of Standards and Technology (NIST), whose cryptographic standards are used well beyond the US, published its main post-quantum standards for key establishment and digital signatures in August 2024. Organisations now have approved replacements to plan towards.3
Second, existing rules already contained hooks. The Payment Card Industry Data Security Standard (PCI DSS) expects an organisation to keep a current list of the cipher suites and protocols it relies on, watch whether they stay safe, plan for weaknesses it can see coming, and revisit all of this at least once every 12 months. That requirement has been mandatory since 31 March 2025.4 The EU’s Digital Operational Resilience Act (DORA) applies technical standards that require financial entities to keep an encryption policy that allows cryptography to be updated as cryptanalysis develops.5 DORA’s binding articles do not name quantum computing, although recital 9 of the technical standard recognises quantum-related cryptographic risks,6 and the PCI DSS requirement is written in general terms, but both give auditors a reason to ask about it.
Third, newer instruments name the quantum threat directly. The Saudi Central Bank (SAMA) issued a circular in August 2026 requiring supervised institutions to make their procedures for identifying and classifying all cryptographic assets accurate and comprehensive by the end of 2026.7 In the US, a June 2026 executive order directed the budget office to set dates for federal systems to move to post-quantum key establishment and signatures, and the office’s memorandum turned those dates into a phased plan.1
Binding Rules, Supervisory Expectations And Guidance
Not every document carries the same weight, and treating guidance as law (or law as guidance) leads to poor decisions. It helps to sort the instruments into layers.
- Law And Binding RegulationLegally enforceable. Examples: DORA and its ICT risk technical standards for EU financial entities, the SAMA quantum circular, US executive orders and OMB memoranda for federal agencies.
- Contractual StandardsBinding through contracts with card brands and acquirers rather than by statute. Example: PCI DSS.
- Supervisory ExpectationsIssued by a regulator to the firms it supervises. Not always legally binding, but ignored at your own risk. Examples: the MAS quantum advisory in Singapore and FINMA Guidance 05/2026 in Switzerland.
- National Guidance And RoadmapsRecommended timelines from cyber agencies and governments. Examples: UK NCSC migration timelines and the EU coordinated roadmap.
- Non-Binding StatementsShared reference points from international groups. Example: the G7 Cyber Expert Group roadmap, which states that it sets no regulatory expectations.
The label tells you who can enforce it and what happens if you fall short. A missed PCI DSS requirement shows up in your assessment report. A missed SAMA deadline is a supervisory matter. A missed NCSC milestone has no direct penalty, though it may shape what your regulator expects next.
The Common Thread: Know What You Have
Read the instruments side by side and one request repeats. Before any migration date, almost every framework asks you to find and record the cryptography you depend on, usually alongside a risk assessment.
The Monetary Authority of Singapore advises financial institutions to keep an inventory that records each algorithm and key length, who owns it, and which system uses it.8 The UK National Cyber Security Centre asks organisations to complete discovery and an initial plan by 2028.9 Swiss supervisor FINMA starts with a risk analysis of business processes, which it expects to produce a comprehensive inventory that is kept up to date.10 The US migration memo for federal agencies opens with a discovery phase in 2026 and 2027.1
That is useful news. Work done once, if it is recorded well, can answer several regulators at the same time. The last article in this section shows how one inventory maps to several frameworks.
Deadlines Already In Play
Some of these dates have passed and others are close. The countdowns below update in your browser.
- In effect
European Union · European Commission Binding
Encryption policy, key lifecycle and certificate register rules apply through DORA from this date: the policy must provide for updating cryptography based on developments in cryptanalysis, and a register of certificates and certificate-storing devices must be kept up to date, at least for ICT assets supporting critical or important functions. The RTS itself entered into force on 15 July 2024.
- In effect
Global payments · PCI Security Standards Council Binding
Keep documentation of the cryptographic cipher suites and protocols in use, with a current inventory of what each does and where it runs, active tracking of whether each remains safe and a plan for reacting to foreseeable cryptographic weaknesses, and review it at least once every 12 months. Treated as a best practice until this date and required since.
- Upcoming
Saudi Arabia · Saudi Central Bank (SAMA) Binding
Ensure procedures identify and classify all cryptographic assets accurately and comprehensively.
- Upcoming
Saudi Arabia · Saudi Central Bank (SAMA) Binding
Complete a quantum risk assessment with action plans.
- Upcoming
United Kingdom · National Cyber Security Centre Guidance
Complete discovery and build an initial migration plan.
- Upcoming
United States · The White House and Office of Management and Budget Binding
OMB guidance issued under the order must require agencies to move all high value assets and high impact systems to post-quantum key establishment by this date. M-26-15 plans this as its 2028 to 2030 migration phase.
Footnotes
-
US Office of Management and Budget, “M-26-15: Execution of the Migration to Post-Quantum Cryptography”, 24 June 2026. whitehouse.gov ↩ ↩2 ↩3
-
G7 Cyber Expert Group, “Advancing a Coordinated Roadmap for the Transition to Post-Quantum Cryptography in the Financial Sector”, January 2026. home.treasury.gov ↩
-
Partners from 18 EU Member States, “Securing Tomorrow, Today: Transitioning to Post-Quantum Cryptography”, 27 November 2024. bsi.bund.de ↩
-
PCI Security Standards Council, “Payment Card Industry Data Security Standard: Requirements and Testing Procedures”, version 4.0.1, June 2024, requirement 12.3.3. pcisecuritystandards.org ↩
-
European Commission, “Commission Delegated Regulation (EU) 2024/1774”, Article 6, 13 March 2024. eur-lex.europa.eu ↩
-
European Commission, “Commission Delegated Regulation (EU) 2024/1774”, recital 9, 13 March 2024. eur-lex.europa.eu ↩
-
Saudi Central Bank, “Circular 482021280: Enhancement of Operational Resilience to Address Quantum Computing Risks”, 27 August 2026. rulebook.sama.gov.sa ↩
-
Monetary Authority of Singapore, “MAS/TCRS/2024/01: Advisory on Addressing the Cybersecurity Risks Associated with Quantum”, 20 February 2024. mas.gov.sg ↩
-
UK National Cyber Security Centre, “Timelines for migration to post-quantum cryptography”, 20 March 2025. ncsc.gov.uk ↩
-
FINMA, “FINMA Guidance 05/2026: Quantum computing”, 9 July 2026. finma.ch ↩
Knowledge Hub content is general information. It is not legal advice, a compliance certification, a guarantee of security or a substitute for an assessment of your own systems. Standards and rules change; check the sources for the latest position.