NIST published the first final post-quantum cryptography standards on August 13, 2024: FIPS 203 for the ML-KEM key-encapsulation mechanism and FIPS 204 and 205 for the ML-DSA and SLH-DSA signature schemes (NIST, 2024). Draft transition guidance that November proposed deprecating RSA and elliptic-curve cryptography after 2030 and disallowing it after 2035 (NIST, 2024). Payment systems hold millions of those keys.
Nuv Media publishes information, not financial advice. This explainer covers what quantum computing actually threatens in payments, what federal memoranda require, and why migration timelines consume the entire runway.
What breaks, exactly?
Two algorithms define the damage. Shor's algorithm, run on a sufficiently large fault-tolerant quantum computer, breaks the integer factorization and discrete-log problems behind RSA and elliptic-curve cryptography — every TLS handshake, digital certificate and signed firmware update in payments relies on them. Grover's algorithm weakens symmetric ciphers like AES only quadratically, which doubling key lengths addresses; symmetric encryption is the lesser worry.
The exposed layer is the asymmetric wrapper around everything. Card-not-present sessions ride TLS whose key exchange uses elliptic curves; EMV chip authentication and network certificate hierarchies use RSA or ECDSA; the hardware security modules that mint payment keys are built around the same mathematics. A cryptographically relevant quantum computer would not attack the AES-encrypted PIN block — it would forge the certificates and session keys around it.
No such machine exists today. Published engineering roadmaps still need orders-of-magnitude improvements in error correction, and NIST's standards were designed against known quantum attacks including those published since selection. The deadline exists because of what adversaries can do before the machine arrives.
What is harvest now, decrypt later?
A recording attack: an adversary captures encrypted traffic or encrypted stored data today, holds it, and decrypts it once a capable quantum computer exists. Nothing about the capture is exotic — backbone taps and breached databases already supply the raw material. The attack only pays off against secrets that stay valuable longer than the wait, which is why the doctrine focuses on data lifetime.
Payments fail that test badly. Cardholder data and transaction records carry retention duties measured in years under tax and anti-money-laundering rules; SWIFT message archives, settlement files and token-vault backups hold intelligence value for a decade. Traffic encrypted today with elliptic-curve key exchange and stored by an adversary becomes readable in the 2030s under NIST's own retirement schedule — within the lifetime of the data (NIST, 2024).
Security planners run the arithmetic as three horizons: how long the secret must stay secret, how long migration will take, and when a cryptographically relevant computer might arrive. When the first horizon is ten-plus years and the second is five, migration has to start before anyone can prove the third — which is the whole policy argument.
What deadlines has the government actually set?
Four documents anchor the timeline. National Security Memorandum 10, signed May 4, 2022, directed agencies to inventory quantum-vulnerable cryptography and begin planning migration (White House, 2022). OMB memo M-23-02 of November 2022 ordered federal agencies to inventory that cryptography and report yearly (OMB, 2022). The Quantum Computing Cybersecurity Preparedness Act, Public Law 117-260 of December 2022, wrote the inventory requirement into statute (Congress, 2022).
The fourth sets the technical clock. NIST Internal Report 8547, issued as a draft in November 2024, proposes that RSA-2048 and elliptic-curve cryptography be deprecated after 2030 and disallowed after 2035 across federal systems (NIST, 2024). The NSA's CNSA 2.0 suite, announced September 2022, imposes a parallel schedule for national security systems, with full transition by 2033 (NSA, 2022). None of these documents names Visa or a core banking platform — but payment networks interconnect with federal systems, follow FIPS-validated cryptography, and buy HSMs on the same supply chains, so the schedules pull the industry with them.
What makes payments slow to migrate?
Hardware and certification cycles. Payment key management runs through FIPS 140-validated hardware security modules; post-quantum validation of HSMs and the migration of key ceremonies is measured in years, not sprints. Card issuance adds another lag: EMV keys loaded onto plastic live for the card's life, so certificates issued in 2026 with classical keys still circulate near the 2035 disallowance date.
Interoperability is the second drag. Payment networks cannot switch key exchange unilaterally; acquirers, issuers, gateways and processors must negotiate algorithms in flight. The internet's answer — hybrid key exchange that combines elliptic curves with ML-KEM in a single TLS handshake — reached default status in major browsers during 2024, so payment endpoints that ride standard TLS stacks already speak some post-quantum without noticing (browser vendor release notes, 2024). Proprietary payment links lack that automatic upgrade path.
The third drag is discovery. Institutions often cannot enumerate where RSA and ECC live: embedded certificates in payment terminals, mainframe crypto calls, vendor-managed gateways. NIST's National Cybersecurity Center of Excellence opened a migration project precisely to build discovery and interoperability practices, and its participants describe discovery as the longest phase (NIST, 2023).
What should a payments team do first?
Inventory before replacing. Enumerate cryptographic assets — certificates, key stores, TLS endpoints, HSM partitions, mainframe crypto usage — and tag each by algorithm, owner and secret lifetime. Data protected for less than a decade tolerates a later migration; long-lived archives and signing keys go first. Second, put hybrid post-quantum TLS on the roadmap wherever standard stacks allow it, because it is the cheapest immediate reduction of harvest-now exposure. Third, write post-quantum requirements into HSM and gateway procurement now, so the 2030 hardware refresh arrives compliant instead of stranded. The institutions that treat 2035 as a procurement backstop rather than a technical deadline are the ones that will not be re-plumbing in a panic.
For more context, read How Agentic Commerce Would Let AI Agents Pay for You.
For more context, read iso 20022 migration.
For more context, read ai underwriting banks.




