PQCClear Intelligence
Quantum compliance, demystified for financial institutions
Analysis, regulatory breakdowns, and practical guidance for the TPRM and security teams at banks, credit unions, and payment processors navigating the PQC compliance transition.
Latest post
The Quantum Execution Gap: What New Survey Data Means for Financial Services
An independent survey of 1,001 IT and security leaders finds 87% of organizations planning, testing, or implementing post-quantum cryptography, and 7% that have actually deployed it, a figure that moved less than two percentage points in a full year. The barrier breakdown is the part worth reading: only 3% say they do not know where to start, and only 8% point to executive buy-in. Financial transaction data also ranks as the single most likely first target under harvest now, decrypt later, ahead of cryptocurrency assets.
Read the briefMore articles
Trust Now, Forge Later: The Quantum Risk to Signatures, Not Just Encryption
Harvest now, decrypt later gets most of the attention in this space. Its quieter sibling, trust now, forge later, is about trust captured today and abused later: a signature or certificate that is credible only because forging one is currently impossible. Different mechanism, different clock, and a sharper problem once it starts, because a forged signing key does not just threaten new signatures. It threatens every trust relationship still resting on the old algorithm, which is why migration sequencing that treats encryption as the priority is often backwards.
Read the briefThe G7 Just Warned That Delaying PQC Could Cost You Government Contracts
All seven G7 cybersecurity agencies co-signed a call to action on September 3, widening the post-quantum message from critical infrastructure to every sector. The line worth planning around is in the procurement section, where organizations that delay are told they may be excluded from contracting opportunities. Why the pressure does not stop at the prime contractor.
Read the briefNew Industry Data Places Finance at “Planning” for Post-Quantum Readiness, Not “Deployment”
An industry maturity model presented this week by IBM’s lead for quantum-safe networks puts financial services in the planning column, ahead of most sectors mapped alongside it. The reason it is not further along is that finance has no single lever: central banks, regulators, payment networks, and retail banks are each migrating on their own terms. The detail worth reading twice is a row down, where SME sits in the no-readiness column.
Read the briefCloudflare Just Proved “PQC Capable” and “PQC Protected” Are Different Things
Cloudflare now actively scans the origin servers behind its network instead of guessing what they support, and the scan turned up thousands of servers that were fully capable of post-quantum encryption and had never once used it, simply because nothing had ever asked. Why a vendor’s stack supporting a standard and that standard actually protecting a live connection are two separate facts.
Read the briefTLS Just Got a Post-Quantum Standard: Why “Supported” Doesn’t Mean “Protected”
The IETF has published RFC 10024, an official way for browsers and websites to agree on post-quantum encryption. It is a real step forward, and it is also the point where most vendor assessments stop asking questions. A request rarely reaches one server directly: it passes through a CDN, a load balancer, a gateway, and each of those does its own handshake. Why supporting the standard, negotiating it once, and being protected end to end are three different claims, and what to ask a vendor to tell them apart.
Read the briefRSA-260 Was Just Factored: Why It Doesn't Change Your Quantum Timeline
A record-breaking factoring result went viral this week, and it is a genuine achievement in computational number theory. It is also 863 bits against the 2,048-bit keys production systems actually use, and the gap between those two numbers is exponential, not arithmetic. Why the only thing that moves your migration deadline is a different kind of computer entirely.
Read the briefWhat Your Bank Examiner Will Ask About Post-Quantum Cryptography in 2027
FFIEC examiners are already asking about quantum risk planning. The exact questions they'll ask, and how to prepare your answers.
Read the briefTreasury Launches a Quantum-Readiness Task Force, and Vendor Assessment Is One of Its Three Pillars
On August 24 the Treasury Department stood up a public-private Quantum-Readiness Task Force for the financial sector, and assessing the readiness of technology vendors and other third parties is not a side note in it. It is one of three named work streams, alongside the sector-wide transition and digital assets. What that shift means for banks and credit unions, where it sits against the G7 roadmap and the June executive orders, and the three things worth doing this quarter.
Read the briefHow PQCClear Protects the CBOMs Banks and Vendors Trust Us With
Part 10 of a plain-English series. A CBOM is exactly as useful to a defender as it is dangerous in the wrong hands. The five design principles PQCClear is built on, and an honest account of which mechanisms are live and which are still being built.
Read part 10CBOM Access Control: Who Should Actually See Your Cryptographic Inventory?
Part 9 of a plain-English series. A detailed CBOM is one of the most useful documents a security team can have, and in the wrong hands close to a map of where to attack. Who legitimately needs the full document, and what changes once one platform holds many of them.
Read part 9PQC Readiness Score vs. Certificate vs. CBOM: What Should You Actually Look At?
Part 8 of a plain-English series. A score, a certificate, and a full CBOM report are not competing formats. They answer different questions, and reaching for the wrong one at the wrong moment is where most of the confusion in this space comes from.
Read part 8“Industry-Standard Encryption” Isn’t an Answer: What to Ask Instead
Part 7 of a plain-English series. That sentence sounds reassuring and says almost nothing. What a vague answer actually tells you about a vendor's own visibility, and the five things a real, checkable answer contains instead.
Read part 7Harvest Now, Decrypt Later: The Quantum Data Risk Explained
Part 6 of a plain-English series. An attacker doesn't need to break your encryption today to benefit from breaking it years from now. They only need a copy of the data waiting when they can, which is why waiting for a quantum computer to exist is the wrong strategy.
Read part 6Third-Party Risk Management and Encryption: Why Vendor Cryptography Is Your Problem Too
Part 5 of a plain-English series. A bank can do everything right with its own encryption and still be exposed, because most of what touches customer data was built by someone else. Why encryption became its own line item inside an old, familiar process.
Read part 5Post-Quantum Cryptography Deadlines: Why 2026 Changed the Timeline
Part 4 of a plain-English series. Nobody's encryption is broken today, and the machine that could break it does not exist yet. So why does the response to it suddenly carry dates? What changed in a single eight-day stretch of June 2026.
Read part 4So What Is a CBOM, Actually?
Part 3 of a plain-English series. A CBOM is a list of every piece of encryption a system uses, written down in enough detail that someone can actually evaluate it. What a single entry contains, field by field, and why this took longer to build than a component list did.
Read part 3Meet the “Bill of Materials” Idea: Before CBOM, There Was SBOM
Part 2 of a plain-English series. A bill of materials is a manufacturing term that predates computers entirely. Software borrowed it and called it an SBOM, and there is one question about your encryption that the list still cannot answer.
Read part 2Why Would Anyone Need an Inventory of Their Own Encryption?
Part 1 of a plain-English series. What encryption does your organization actually use, and where? Most well-run organizations cannot answer that today, and the reason has nothing to do with not caring.
Read part 1The Vendor Pitch That Should Cost Them Points: “Proprietary and Patent-Pending”
Why custom and proprietary cryptography scores at the floor of our model rather than the middle, and what the track record of homegrown ciphers, from the 1978 knapsack to Rainbow and SIKE, actually shows.
Read the briefHong Kong Banks Score 2.3/10 on Quantum Readiness. US Banks Are No Different.
An aggregate score of 2.3 out of 10, 68% of institutions with no quantum initiatives at all, and 87% naming vendor dependencies as their biggest barrier. What the HKMA and FINMA data says about US banks.
Read the analysisFIPS 203, 204, 205 Explained: What Each One Actually Means for a Vendor's Algorithm Risk Score
NIST's post-quantum standards, read the way a TPRM team needs to read them: what ML-KEM, ML-DSA, and SLH-DSA each reveal about a vendor's cryptographic risk.
Read the primerYour Fintech Vendors Don't All Answer to the Same Standard: Why PQC Fragmentation Is a Vendor Risk Problem
Four regions are now standardizing four different, and not fully interoperable, sets of post-quantum algorithms. The six questions your vendor questionnaire probably isn't asking yet.
Read the briefDORA Article 28 and Quantum Risk: What EU Banks Must Do Now
DORA makes EU banks legally responsible for vendor cryptographic posture. The specific obligations, with a practical compliance checklist.
Read the briefHow to Classify Your Fintech Vendors for Quantum Risk: The Five-Category Framework Every Bank TPRM Team Needs
You cannot assess every vendor the same way. The five-category taxonomy that decides which questions, which evidence, and which engagement motion each vendor gets.
Read the frameworkTrump Just Signed a PQC Executive Order. Here's What Every Bank CISO Needs to Do This Week.
The most consequential cybersecurity mandate for financial institutions since DORA, and the three things every CISO should do this week.
Read the analysisThe 500-Vendor Problem: How Mid-Size Banks Should Prioritize Their PQC Vendor Assessment
You can't assess 500 vendors at once. Here's the risk-based framework for deciding where to start.
Coming soon