Financial firms should look to integrate post-quantum cryptography (PQC) by 2034 at the latest, the G7’s Cyber Expert Group has warned, a timeline which will provide the time needed to test next-gen protections before the risk of quantum-enabled cyber-attacks hits.
Publishing a new roadmap for the industry, the CEG working group, which advises G7 finance ministers and central bank governors on cybersecurity, said that the transition to PQC will soon be essential to protect financial services systems and data, a move which will require planning and cooperation across jurisdictions.
Stressing that the roadmap isn’t a rulebook, the CEG said the guidance is designed to help senior leaders shape their own action plans before inevitable quantum risks surface, with the hope that this will spark wider PQC adoption across tech products, vendors, and third‑party providers.
Up until 2027, the financial sector remains in the first of the CEG’s six transition phases, awareness and preparation, with organisations expected to raise internal awareness of quantum threats and map out the systems and data most vulnerable to future attacks.
The next step, discovery and inventory, runs in parallel with the first phase from 2026 to 2028, during which financial firms will need to catalogue their networks and systems, including third‑party links, to uncover any gaps that might expose future vulnerabilities.
Those early milestones are simply a warm-up, however, as the heavy lifting of the CEG’s transition recommendations unfolds between 2027 and 2034, when firms should begin to migrate to and actively deploy quantum-resistant solutions, starting with priority functions.
The G7 cautioned that the generous pace of this PQC migration may have to speed up according to the evolution of the quantum threat landscape, meaning those taking proactive steps now will be best protected if quantum tech takes a leap similar to that experienced by AI.
Following their migration to PQC, the CEG blueprint then makes room for testing, validation, and monitoring of these quantum remedies over the years up until 2035, by which point the G7 strongly recommends financial services firms and institutions have fully transitioned.
Despite being almost a decade away, meeting these targets across the industry will require serious commitment and sector‑wide collaboration.
“While the trajectory of quantum computing development is uncertain, it may be helpful for organisations to establish comparable migration timelines to ensure their milestones can be achieved prior to the availability of cryptographically relevant quantum computers,” the CEG said.
“While such a time range is non-authoritative and will need to evolve with the risk landscape, it may be helpful as a general target to communicate planning among jurisdictions.”
Recommended reading
- NCSC Issues Quantum Security Roadmap For Businesses
- Firms Unprepared for Quantum Computing’s Rapid Rise
- Financial Services Under Quantum Threat, Warns Europol
Evidence suggests firms are already racing to adopt post‑quantum encryption as fears grow over “Q‑Day”, the moment when quantum computers could break today’s public‑key cryptography.
Research from Capgemini last year found that nearly two-thirds of organisations consider quantum computing the most critical threat they face over the next five years, with 86% of banking and financial institutions working on quantum protections.
Capgemini’s study found that the majority (70%) of firms said that meeting government regulations was a key factor in their urgency to adopt post-quantum security, making guidance like that from the G7 essential for steering timely PQC adoption.





