All posts

Fintech Regulatory Brief

What Your Bank Examiner Will Ask About Post-Quantum Cryptography in 2027, and How to Prepare Your Answers

September 3, 2026  ·  Updated September 1, 2026 ·  PQCClear  ·  9 minute read

Guidance arrives, examination questions follow within 12 to 24 months, and post-quantum cryptography is following that same pattern. In the final week of June 2026, the federal government published five interlocking policy documents that together create the most complete PQC migration mandate to date.

The Pattern Every Compliance Team Knows

Bank examiners do not wait for institutions to feel ready before asking hard questions. The pattern is consistent across every major cybersecurity development of the past decade, from cloud adoption to ransomware resilience to third-party risk management. Guidance arrives, examination questions follow within 12 to 24 months, and the institutions that prepared in advance look significantly better than those that waited.

Post-quantum cryptography is following the same pattern, and the pace accelerated dramatically in the final week of June 2026.

In eight days, the federal government published five interlocking policy documents that together create the most complete federal PQC migration mandate ever assembled. On June 22, President Trump signed Executive Order 14412, Securing the Nation Against Advanced Cryptographic Attacks, setting hard deadlines for civilian high-value assets. Two days later, OMB issued Memorandum M-26-15, Execution of the Migration to Post-Quantum Cryptography, which replaced M-23-02 as the operative civilian implementation guidance and published a detailed five-phase migration timeline running to 2035. The speed of M-26-15 (issued just two days after the executive order when 90 days were allowed) signals it was written alongside the order, not in response to it.

The pattern did not stop there. Weeks later, Treasury raised the stakes again, naming vendor readiness a core pillar of its new Quantum-Readiness Task Force. That puts the exact problem this brief is about on a federal task force’s agenda: a bank can secure its own systems and still be exposed through the vendors it depends on. The full breakdown of what the task force means for banks and credit unions is in that post.

This is not a future problem. It is a current compliance posture question. And FFIEC examination guidance will follow.

Why PQC Is an Examination Issue Now, Not Later

The FFIEC Cybersecurity Assessment Tool and the IT Examination Handbook already contain the framework through which PQC will be assessed. Examiners do not need new PQC-specific guidance to ask about cryptographic risk management, it falls squarely within existing information security examination categories.

Examination area

Information Security Program

NIST finalized ML-KEM, ML-DSA, and SLH-DSA in August 2024. Algorithms at ≤112-bit security (including RSA-2048 and ECDSA P-256) are deprecated after 2030 and disallowed after 2035.

Examination area

Third-Party Risk Management

Cryptographic practices are information security practices. CISA's PQC Product Categories List (Jan 23, 2026) gives examiners a framework to assess quantum-capable procurement.

Examination area

Business Continuity & Resilience

Harvest-now-decrypt-later is named an active threat in EO 14412: adversaries are “collecting United States information now, and decrypting it later.”

Examination area

Board & Senior Management Oversight

OMB M-26-15 states PQC migration “is not the sole responsibility of agency CIOs and CISOs.” No board-level discussion is a governance finding waiting to happen.

The Eight Questions Your Examiner Is Most Likely to Ask

Open each question to see what the examiner is actually testing, what a strong answer looks like, and what to do this quarter to get there.

01Has your institution completed a cryptographic inventory?

What they're asking

Do you know what encryption algorithms your institution uses, where they're deployed, and what data they protect?

Good looks like

A documented cryptographic inventory (ideally in CBOM format) identifying every algorithm, the assets it protects, and data sensitivity/retention. Dated, version-controlled, with a named owner. CISA must publish minimum CBOM elements by March 19, 2027. Institutions starting now will be ahead of that standard.

Bad looks like

“We use industry-standard encryption” with no further documentation.

Do this quarter

Begin your cryptographic inventory. An inventory that exists before an examiner asks is far stronger evidence than one assembled under examination pressure.

02Does your institution have a PQC migration plan?

What they're asking

Beyond knowing what algorithms you use, do you have a documented plan to migrate quantum-vulnerable algorithms to NIST-approved PQC standards?

Good looks like

A phased roadmap prioritizing systems by risk, with budget estimates, ownership, and target dates. OMB M-26-15's five phases (2026 to 2035) are a direct template.

Bad looks like

“We are monitoring developments.” After a presidential executive order and OMB guidance, this is a finding.

Do this quarter

Document a plan even at a high level. Board-approved, risk-prioritized, phased: that is the bar.

03Have you assessed your fintech vendors' quantum readiness?

What they're asking

Your cryptographic security is only as strong as your weakest vendor. Have you extended PQC assessment to your vendor portfolio?

Good looks like

Documentation showing assessment, or an active program to assess, critical and important ICT vendors, including cryptographic inventories and contractual assessment rights. Flag the FAR contractor provision (December 31, 2030 deadline), which cascades to vendors holding federal contracts.

Bad looks like

A strong internal PQC program with no corresponding vendor assessment program.

Do this quarter

Add quantum readiness assessment to vendor onboarding and annual reassessment. For critical vendors, an automated cryptographic scan producing a CBOM is the appropriate standard of evidence.

04What is your exposure to harvest-now-decrypt-later risk?

What they're asking

EO 14412 explicitly names harvest-now-decrypt-later as an active threat. Cloudflare moved its own PQC target to 2029 after April 2026 research breakthroughs. Have you assessed your exposure?

Good looks like

A documented assessment identifying which data categories use quantum-vulnerable algorithms, their sensitivity, and their retention period. Financial records, loan files, and long-term transaction histories first.

Bad looks like

Treating quantum cryptographic risk as a future problem. The executive order makes clear it is a current exposure.

Do this quarter

Add HNDL risk to your risk register. Quantify exposure by volume and sensitivity of data that will be retained beyond 2030.

05Has your board been briefed on quantum cryptographic risk?

What they're asking

Has the board been made aware of quantum cryptographic risk and the regulatory migration timeline?

Good looks like

Board minutes documenting a presentation on EO 14412, OMB M-26-15, and the institution's plan. A board resolution approving the plan is the strongest evidence. OMB M-26-15 states PQC migration “is not the sole responsibility of agency CIOs and CISOs.”

Bad looks like

No board-level documentation of any quantum risk discussion.

Do this quarter

Schedule a board briefing. A 10-minute agenda item citing EO 14412 and M-26-15 by name is sufficient to establish documented awareness.

06How do you assess vendor quantum readiness before procurement?

What they're asking

Is quantum readiness assessment built into your procurement process for new vendors?

Good looks like

A documented pre-procurement process requiring new ICT vendors to demonstrate readiness or provide a migration roadmap before contract execution.

Bad looks like

Signing a new contract with a quantum-vulnerable fintech vendor in 2027 with no documented assessment.

Do this quarter

Add a quantum readiness gate to your vendor onboarding checklist, effective immediately.

07What algorithms protect your most sensitive customer data?

What they're asking

A specific, technical question testing whether your institution actually knows the answer, or is relying on generic assurances.

Good looks like

Stating specifically, by system and data category, which algorithms protect your highest-sensitivity assets, and naming your top-priority remediation item.

Bad looks like

“We use bank-grade encryption.” That answer is itself an information security finding.

Do this quarter

Know the answer before your examination. This requires a minimum viable cryptographic inventory focused on your highest-sensitivity systems.

08What is your plan for systems where vendors control the crypto?

What they're asking

For many institutions, cryptographic algorithms are implemented by third-party core banking vendors and payment processors. What is your plan where you do not control the migration?

Good looks like

Documented communication with each critical vendor requesting their PQC roadmap, contractual migration timeframes, and a monitoring process to verify progress.

Bad looks like

“That is our vendor's responsibility.” Under FFIEC's third-party risk framework, vendor cryptographic security is the institution's responsibility.

Do this quarter

Contact your three most critical vendors and request their PQC migration roadmap. Document the response, or the non-response.

The Updated Regulatory Timeline Every Bank Should Track

  1. Aug 2024

    NIST finalizes FIPS 203, 204, 205

    PQC standard now established. Migration can begin.

  2. Jan 2025

    CISA PQC initiative active

    Examiner benchmark for “current standards.”

  3. Jan 23, 2026

    CISA PQC Product Categories List published

    Defines “Widely Available” vs. “Transitioning” products.

  4. Jun 22, 2026

    Executive Order 14412 signed

    Board awareness expected immediately.

  5. Jun 24, 2026

    OMB M-26-15 issued

    Five-phase migration framework established.

  6. Aug 24, 2026

    Treasury launches Quantum-Readiness Task Force

    Third-party and vendor readiness named as one of three core work streams.

  7. TodayYou are here

    Preparation window

    This is the window to build your examination-ready package before guidance arrives.

  8. Oct 2026 (120 days)

    Federal agencies submit PQC migration plans

    Model for institution plan structure.

  9. Mar 19, 2027

    CISA CBOM minimum elements guidance

    CBOM standard arrives. Be ready before it does.

  10. 2027–2028

    FFIEC examination guidance expected

    Examiners will ask all eight questions above.

  11. Dec 31, 2030

    PQC key establishment deadline

    Hard deadline for federal contractor banks.

  12. Dec 31, 2031

    PQC digital signatures deadline

    All signing systems must be quantum-safe.

  13. 2035

    All remaining systems: full migration

    Final horizon for complete transition.

A Note for Community Banks and Credit Unions

Smaller institutions frequently say PQC compliance feels like a large-bank problem. That framing is incorrect in two ways. First, NCUA supervisory guidance follows FFIEC examination frameworks closely, credit unions face the same examination environment, tracking the same federal policy developments.

Second, community banks and credit unions are often more exposed to vendor cryptographic risk, relying more heavily on third-party core banking vendors and digital banking platforms. That makes vendor quantum readiness assessment a higher priority for smaller institutions, not a lower one.

How to Prepare Before Your Next Examination

You do not need to complete your PQC migration before your next examination. Examiners are looking for evidence of awareness, documentation, and a credible plan. The minimum examination-ready package:

  1. 01

    Cryptographic inventory covering your highest-sensitivity systems, in a standard format, dated and version-controlled.

  2. 02

    Migration plan approved by senior management, prioritized by risk, aligned to the OMB M-26-15 five-phase framework.

  3. 03

    Board briefing documentation showing the board has been informed of the risk, the executive order, and the plan.

  4. 04

    Vendor assessment records showing you've assessed, or begun assessing, critical vendors' quantum readiness.

  5. 05

    Risk register entry for harvest-now-decrypt-later exposure, quantified by data sensitivity and retention.

This package takes most institutions three to six months to assemble properly. Institutions that begin this quarter will have examination-ready documentation before 2027 examination cycles begin.

Get every fintech vendor examination-ready

PQCClear helps banks, credit unions, and payment processors assess the quantum readiness of every fintech vendor in their portfolio, generating a Quantum Readiness Score, a full CBOM, and an FFIEC and NCUA examination-ready report for each vendor.

Request access
FFIEC post quantum cryptography examinationbank examiner PQC questionsNCUA quantum cryptography examinationOCC post quantum cryptography guidancequantum readiness bank examinationPQC compliance community bank

This post represents the editorial analysis of PQCClear as of June 30, 2026, updated September 1, 2026. It should not be construed as legal advice. Financial institutions should consult legal counsel and compliance advisors regarding their specific examination obligations.

Key sources: Executive Order 14412 (whitehouse.gov, June 22, 2026); OMB M-26-15 (whitehouse.gov, June 24, 2026); NIST FIPS 203/204/205 (csrc.nist.gov, August 2024); CISA PQC Product Categories List (cisa.gov, January 23, 2026); NIST IR 8547 initial public draft (November 12, 2024); U.S. Department of the Treasury, “Treasury Announces the Quantum-Readiness Task Force” (home.treasury.gov, August 24, 2026).