PQCClear Intelligence

Quantum compliance, demystified for financial institutions

Analysis, regulatory breakdowns, and practical guidance for the TPRM and security teams at banks, credit unions, and payment processors navigating the PQC compliance transition.

Latest post

FintechRegulatory BriefSeptember 16, 2026  ·  PQCClear

The Quantum Execution Gap: What New Survey Data Means for Financial Services

An independent survey of 1,001 IT and security leaders finds 87% of organizations planning, testing, or implementing post-quantum cryptography, and 7% that have actually deployed it, a figure that moved less than two percentage points in a full year. The barrier breakdown is the part worth reading: only 3% say they do not know where to start, and only 8% point to executive buy-in. Financial transaction data also ranks as the single most likely first target under harvest now, decrypt later, ahead of cryptocurrency assets.

Read the brief

More articles

FintechSeptember 15, 2026

Trust Now, Forge Later: The Quantum Risk to Signatures, Not Just Encryption

Harvest now, decrypt later gets most of the attention in this space. Its quieter sibling, trust now, forge later, is about trust captured today and abused later: a signature or certificate that is credible only because forging one is currently impossible. Different mechanism, different clock, and a sharper problem once it starts, because a forged signing key does not just threaten new signatures. It threatens every trust relationship still resting on the old algorithm, which is why migration sequencing that treats encryption as the priority is often backwards.

Read the brief
FintechSeptember 12, 2026

The G7 Just Warned That Delaying PQC Could Cost You Government Contracts

All seven G7 cybersecurity agencies co-signed a call to action on September 3, widening the post-quantum message from critical infrastructure to every sector. The line worth planning around is in the procurement section, where organizations that delay are told they may be excluded from contracting opportunities. Why the pressure does not stop at the prime contractor.

Read the brief
FintechSeptember 11, 2026

New Industry Data Places Finance at “Planning” for Post-Quantum Readiness, Not “Deployment”

An industry maturity model presented this week by IBM’s lead for quantum-safe networks puts financial services in the planning column, ahead of most sectors mapped alongside it. The reason it is not further along is that finance has no single lever: central banks, regulators, payment networks, and retail banks are each migrating on their own terms. The detail worth reading twice is a row down, where SME sits in the no-readiness column.

Read the brief
FintechSeptember 10, 2026

Cloudflare Just Proved “PQC Capable” and “PQC Protected” Are Different Things

Cloudflare now actively scans the origin servers behind its network instead of guessing what they support, and the scan turned up thousands of servers that were fully capable of post-quantum encryption and had never once used it, simply because nothing had ever asked. Why a vendor’s stack supporting a standard and that standard actually protecting a live connection are two separate facts.

Read the brief
FintechSeptember 8, 2026

TLS Just Got a Post-Quantum Standard: Why “Supported” Doesn’t Mean “Protected”

The IETF has published RFC 10024, an official way for browsers and websites to agree on post-quantum encryption. It is a real step forward, and it is also the point where most vendor assessments stop asking questions. A request rarely reaches one server directly: it passes through a CDN, a load balancer, a gateway, and each of those does its own handshake. Why supporting the standard, negotiating it once, and being protected end to end are three different claims, and what to ask a vendor to tell them apart.

Read the brief
Threat IntelligenceSeptember 6, 2026

RSA-260 Was Just Factored: Why It Doesn't Change Your Quantum Timeline

A record-breaking factoring result went viral this week, and it is a genuine achievement in computational number theory. It is also 863 bits against the 2,048-bit keys production systems actually use, and the gap between those two numbers is exponential, not arithmetic. Why the only thing that moves your migration deadline is a different kind of computer entirely.

Read the brief
ComplianceSeptember 3, 2026

What Your Bank Examiner Will Ask About Post-Quantum Cryptography in 2027

FFIEC examiners are already asking about quantum risk planning. The exact questions they'll ask, and how to prepare your answers.

Read the brief
RegulatoryAugust 28, 2026

Treasury Launches a Quantum-Readiness Task Force, and Vendor Assessment Is One of Its Three Pillars

On August 24 the Treasury Department stood up a public-private Quantum-Readiness Task Force for the financial sector, and assessing the readiness of technology vendors and other third parties is not a side note in it. It is one of three named work streams, alongside the sector-wide transition and digital assets. What that shift means for banks and credit unions, where it sits against the G7 roadmap and the June executive orders, and the three things worth doing this quarter.

Read the brief
PQC BasicsAugust 23, 2026

How PQCClear Protects the CBOMs Banks and Vendors Trust Us With

Part 10 of a plain-English series. A CBOM is exactly as useful to a defender as it is dangerous in the wrong hands. The five design principles PQCClear is built on, and an honest account of which mechanisms are live and which are still being built.

Read part 10
PQC BasicsAugust 23, 2026

CBOM Access Control: Who Should Actually See Your Cryptographic Inventory?

Part 9 of a plain-English series. A detailed CBOM is one of the most useful documents a security team can have, and in the wrong hands close to a map of where to attack. Who legitimately needs the full document, and what changes once one platform holds many of them.

Read part 9
PQC BasicsAugust 23, 2026

PQC Readiness Score vs. Certificate vs. CBOM: What Should You Actually Look At?

Part 8 of a plain-English series. A score, a certificate, and a full CBOM report are not competing formats. They answer different questions, and reaching for the wrong one at the wrong moment is where most of the confusion in this space comes from.

Read part 8
PQC BasicsAugust 23, 2026

“Industry-Standard Encryption” Isn’t an Answer: What to Ask Instead

Part 7 of a plain-English series. That sentence sounds reassuring and says almost nothing. What a vague answer actually tells you about a vendor's own visibility, and the five things a real, checkable answer contains instead.

Read part 7
PQC BasicsAugust 21, 2026

Harvest Now, Decrypt Later: The Quantum Data Risk Explained

Part 6 of a plain-English series. An attacker doesn't need to break your encryption today to benefit from breaking it years from now. They only need a copy of the data waiting when they can, which is why waiting for a quantum computer to exist is the wrong strategy.

Read part 6
PQC BasicsAugust 21, 2026

Third-Party Risk Management and Encryption: Why Vendor Cryptography Is Your Problem Too

Part 5 of a plain-English series. A bank can do everything right with its own encryption and still be exposed, because most of what touches customer data was built by someone else. Why encryption became its own line item inside an old, familiar process.

Read part 5
PQC BasicsAugust 20, 2026

Post-Quantum Cryptography Deadlines: Why 2026 Changed the Timeline

Part 4 of a plain-English series. Nobody's encryption is broken today, and the machine that could break it does not exist yet. So why does the response to it suddenly carry dates? What changed in a single eight-day stretch of June 2026.

Read part 4
PQC BasicsAugust 20, 2026

So What Is a CBOM, Actually?

Part 3 of a plain-English series. A CBOM is a list of every piece of encryption a system uses, written down in enough detail that someone can actually evaluate it. What a single entry contains, field by field, and why this took longer to build than a component list did.

Read part 3
PQC BasicsAugust 19, 2026

Meet the “Bill of Materials” Idea: Before CBOM, There Was SBOM

Part 2 of a plain-English series. A bill of materials is a manufacturing term that predates computers entirely. Software borrowed it and called it an SBOM, and there is one question about your encryption that the list still cannot answer.

Read part 2
PQC BasicsAugust 17, 2026

Why Would Anyone Need an Inventory of Their Own Encryption?

Part 1 of a plain-English series. What encryption does your organization actually use, and where? Most well-run organizations cannot answer that today, and the reason has nothing to do with not caring.

Read part 1
Vendor RiskAugust 10, 2026

The Vendor Pitch That Should Cost Them Points: “Proprietary and Patent-Pending”

Why custom and proprietary cryptography scores at the floor of our model rather than the middle, and what the track record of homegrown ciphers, from the 1978 knapsack to Rainbow and SIKE, actually shows.

Read the brief
Breaking DataAugust 4, 2026

Hong Kong Banks Score 2.3/10 on Quantum Readiness. US Banks Are No Different.

An aggregate score of 2.3 out of 10, 68% of institutions with no quantum initiatives at all, and 87% naming vendor dependencies as their biggest barrier. What the HKMA and FINMA data says about US banks.

Read the analysis
StandardsJuly 28, 2026

FIPS 203, 204, 205 Explained: What Each One Actually Means for a Vendor's Algorithm Risk Score

NIST's post-quantum standards, read the way a TPRM team needs to read them: what ML-KEM, ML-DSA, and SLH-DSA each reveal about a vendor's cryptographic risk.

Read the primer
Third-Party RiskJuly 19, 2026

Your Fintech Vendors Don't All Answer to the Same Standard: Why PQC Fragmentation Is a Vendor Risk Problem

Four regions are now standardizing four different, and not fully interoperable, sets of post-quantum algorithms. The six questions your vendor questionnaire probably isn't asking yet.

Read the brief
DORAJune 30, 2026

DORA Article 28 and Quantum Risk: What EU Banks Must Do Now

DORA makes EU banks legally responsible for vendor cryptographic posture. The specific obligations, with a practical compliance checklist.

Read the brief
TPRMJune 30, 2026

How to Classify Your Fintech Vendors for Quantum Risk: The Five-Category Framework Every Bank TPRM Team Needs

You cannot assess every vendor the same way. The five-category taxonomy that decides which questions, which evidence, and which engagement motion each vendor gets.

Read the framework
RegulatoryJune 23, 2026

Trump Just Signed a PQC Executive Order. Here's What Every Bank CISO Needs to Do This Week.

The most consequential cybersecurity mandate for financial institutions since DORA, and the three things every CISO should do this week.

Read the analysis
TPRMComing soon

The 500-Vendor Problem: How Mid-Size Banks Should Prioritize Their PQC Vendor Assessment

You can't assess 500 vendors at once. Here's the risk-based framework for deciding where to start.

Coming soon