Fintech Regulatory Brief
What Your Bank Examiner Will Ask About Post-Quantum Cryptography in 2027, and How to Prepare Your Answers
September 3, 2026 · Updated September 1, 2026 · PQCClear · 9 minute read
Guidance arrives, examination questions follow within 12 to 24 months, and post-quantum cryptography is following that same pattern. In the final week of June 2026, the federal government published five interlocking policy documents that together create the most complete PQC migration mandate to date.
The Pattern Every Compliance Team Knows
Bank examiners do not wait for institutions to feel ready before asking hard questions. The pattern is consistent across every major cybersecurity development of the past decade, from cloud adoption to ransomware resilience to third-party risk management. Guidance arrives, examination questions follow within 12 to 24 months, and the institutions that prepared in advance look significantly better than those that waited.
Post-quantum cryptography is following the same pattern, and the pace accelerated dramatically in the final week of June 2026.
In eight days, the federal government published five interlocking policy documents that together create the most complete federal PQC migration mandate ever assembled. On June 22, President Trump signed Executive Order 14412, Securing the Nation Against Advanced Cryptographic Attacks, setting hard deadlines for civilian high-value assets. Two days later, OMB issued Memorandum M-26-15, Execution of the Migration to Post-Quantum Cryptography, which replaced M-23-02 as the operative civilian implementation guidance and published a detailed five-phase migration timeline running to 2035. The speed of M-26-15 (issued just two days after the executive order when 90 days were allowed) signals it was written alongside the order, not in response to it.
The pattern did not stop there. Weeks later, Treasury raised the stakes again, naming vendor readiness a core pillar of its new Quantum-Readiness Task Force. That puts the exact problem this brief is about on a federal task force’s agenda: a bank can secure its own systems and still be exposed through the vendors it depends on. The full breakdown of what the task force means for banks and credit unions is in that post.
This is not a future problem. It is a current compliance posture question. And FFIEC examination guidance will follow.
Why PQC Is an Examination Issue Now, Not Later
The FFIEC Cybersecurity Assessment Tool and the IT Examination Handbook already contain the framework through which PQC will be assessed. Examiners do not need new PQC-specific guidance to ask about cryptographic risk management, it falls squarely within existing information security examination categories.
Examination area
Information Security Program
NIST finalized ML-KEM, ML-DSA, and SLH-DSA in August 2024. Algorithms at ≤112-bit security (including RSA-2048 and ECDSA P-256) are deprecated after 2030 and disallowed after 2035.
Examination area
Third-Party Risk Management
Cryptographic practices are information security practices. CISA's PQC Product Categories List (Jan 23, 2026) gives examiners a framework to assess quantum-capable procurement.
Examination area
Business Continuity & Resilience
Harvest-now-decrypt-later is named an active threat in EO 14412: adversaries are “collecting United States information now, and decrypting it later.”
Examination area
Board & Senior Management Oversight
OMB M-26-15 states PQC migration “is not the sole responsibility of agency CIOs and CISOs.” No board-level discussion is a governance finding waiting to happen.
The Eight Questions Your Examiner Is Most Likely to Ask
Open each question to see what the examiner is actually testing, what a strong answer looks like, and what to do this quarter to get there.
01Has your institution completed a cryptographic inventory?
What they're asking
Do you know what encryption algorithms your institution uses, where they're deployed, and what data they protect?
Good looks like
A documented cryptographic inventory (ideally in CBOM format) identifying every algorithm, the assets it protects, and data sensitivity/retention. Dated, version-controlled, with a named owner. CISA must publish minimum CBOM elements by March 19, 2027. Institutions starting now will be ahead of that standard.
Bad looks like
“We use industry-standard encryption” with no further documentation.
Do this quarter
Begin your cryptographic inventory. An inventory that exists before an examiner asks is far stronger evidence than one assembled under examination pressure.
02Does your institution have a PQC migration plan?
What they're asking
Beyond knowing what algorithms you use, do you have a documented plan to migrate quantum-vulnerable algorithms to NIST-approved PQC standards?
Good looks like
A phased roadmap prioritizing systems by risk, with budget estimates, ownership, and target dates. OMB M-26-15's five phases (2026 to 2035) are a direct template.
Bad looks like
“We are monitoring developments.” After a presidential executive order and OMB guidance, this is a finding.
Do this quarter
Document a plan even at a high level. Board-approved, risk-prioritized, phased: that is the bar.
03Have you assessed your fintech vendors' quantum readiness?
What they're asking
Your cryptographic security is only as strong as your weakest vendor. Have you extended PQC assessment to your vendor portfolio?
Good looks like
Documentation showing assessment, or an active program to assess, critical and important ICT vendors, including cryptographic inventories and contractual assessment rights. Flag the FAR contractor provision (December 31, 2030 deadline), which cascades to vendors holding federal contracts.
Bad looks like
A strong internal PQC program with no corresponding vendor assessment program.
Do this quarter
Add quantum readiness assessment to vendor onboarding and annual reassessment. For critical vendors, an automated cryptographic scan producing a CBOM is the appropriate standard of evidence.
04What is your exposure to harvest-now-decrypt-later risk?
What they're asking
EO 14412 explicitly names harvest-now-decrypt-later as an active threat. Cloudflare moved its own PQC target to 2029 after April 2026 research breakthroughs. Have you assessed your exposure?
Good looks like
A documented assessment identifying which data categories use quantum-vulnerable algorithms, their sensitivity, and their retention period. Financial records, loan files, and long-term transaction histories first.
Bad looks like
Treating quantum cryptographic risk as a future problem. The executive order makes clear it is a current exposure.
Do this quarter
Add HNDL risk to your risk register. Quantify exposure by volume and sensitivity of data that will be retained beyond 2030.
05Has your board been briefed on quantum cryptographic risk?
What they're asking
Has the board been made aware of quantum cryptographic risk and the regulatory migration timeline?
Good looks like
Board minutes documenting a presentation on EO 14412, OMB M-26-15, and the institution's plan. A board resolution approving the plan is the strongest evidence. OMB M-26-15 states PQC migration “is not the sole responsibility of agency CIOs and CISOs.”
Bad looks like
No board-level documentation of any quantum risk discussion.
Do this quarter
Schedule a board briefing. A 10-minute agenda item citing EO 14412 and M-26-15 by name is sufficient to establish documented awareness.
06How do you assess vendor quantum readiness before procurement?
What they're asking
Is quantum readiness assessment built into your procurement process for new vendors?
Good looks like
A documented pre-procurement process requiring new ICT vendors to demonstrate readiness or provide a migration roadmap before contract execution.
Bad looks like
Signing a new contract with a quantum-vulnerable fintech vendor in 2027 with no documented assessment.
Do this quarter
Add a quantum readiness gate to your vendor onboarding checklist, effective immediately.
07What algorithms protect your most sensitive customer data?
What they're asking
A specific, technical question testing whether your institution actually knows the answer, or is relying on generic assurances.
Good looks like
Stating specifically, by system and data category, which algorithms protect your highest-sensitivity assets, and naming your top-priority remediation item.
Bad looks like
“We use bank-grade encryption.” That answer is itself an information security finding.
Do this quarter
Know the answer before your examination. This requires a minimum viable cryptographic inventory focused on your highest-sensitivity systems.
08What is your plan for systems where vendors control the crypto?
What they're asking
For many institutions, cryptographic algorithms are implemented by third-party core banking vendors and payment processors. What is your plan where you do not control the migration?
Good looks like
Documented communication with each critical vendor requesting their PQC roadmap, contractual migration timeframes, and a monitoring process to verify progress.
Bad looks like
“That is our vendor's responsibility.” Under FFIEC's third-party risk framework, vendor cryptographic security is the institution's responsibility.
Do this quarter
Contact your three most critical vendors and request their PQC migration roadmap. Document the response, or the non-response.
The Updated Regulatory Timeline Every Bank Should Track
Aug 2024
NIST finalizes FIPS 203, 204, 205
PQC standard now established. Migration can begin.
Jan 2025
CISA PQC initiative active
Examiner benchmark for “current standards.”
Jan 23, 2026
CISA PQC Product Categories List published
Defines “Widely Available” vs. “Transitioning” products.
Jun 22, 2026
Executive Order 14412 signed
Board awareness expected immediately.
Jun 24, 2026
OMB M-26-15 issued
Five-phase migration framework established.
Aug 24, 2026
Treasury launches Quantum-Readiness Task Force
Third-party and vendor readiness named as one of three core work streams.
TodayYou are here
Preparation window
This is the window to build your examination-ready package before guidance arrives.
Oct 2026 (120 days)
Federal agencies submit PQC migration plans
Model for institution plan structure.
Mar 19, 2027
CISA CBOM minimum elements guidance
CBOM standard arrives. Be ready before it does.
2027–2028
FFIEC examination guidance expected
Examiners will ask all eight questions above.
Dec 31, 2030
PQC key establishment deadline
Hard deadline for federal contractor banks.
Dec 31, 2031
PQC digital signatures deadline
All signing systems must be quantum-safe.
2035
All remaining systems: full migration
Final horizon for complete transition.
A Note for Community Banks and Credit Unions
Smaller institutions frequently say PQC compliance feels like a large-bank problem. That framing is incorrect in two ways. First, NCUA supervisory guidance follows FFIEC examination frameworks closely, credit unions face the same examination environment, tracking the same federal policy developments.
Second, community banks and credit unions are often more exposed to vendor cryptographic risk, relying more heavily on third-party core banking vendors and digital banking platforms. That makes vendor quantum readiness assessment a higher priority for smaller institutions, not a lower one.
How to Prepare Before Your Next Examination
You do not need to complete your PQC migration before your next examination. Examiners are looking for evidence of awareness, documentation, and a credible plan. The minimum examination-ready package:
- 01
Cryptographic inventory covering your highest-sensitivity systems, in a standard format, dated and version-controlled.
- 02
Migration plan approved by senior management, prioritized by risk, aligned to the OMB M-26-15 five-phase framework.
- 03
Board briefing documentation showing the board has been informed of the risk, the executive order, and the plan.
- 04
Vendor assessment records showing you've assessed, or begun assessing, critical vendors' quantum readiness.
- 05
Risk register entry for harvest-now-decrypt-later exposure, quantified by data sensitivity and retention.
This package takes most institutions three to six months to assemble properly. Institutions that begin this quarter will have examination-ready documentation before 2027 examination cycles begin.
Get every fintech vendor examination-ready
PQCClear helps banks, credit unions, and payment processors assess the quantum readiness of every fintech vendor in their portfolio, generating a Quantum Readiness Score, a full CBOM, and an FFIEC and NCUA examination-ready report for each vendor.
Request accessThis post represents the editorial analysis of PQCClear as of June 30, 2026, updated September 1, 2026. It should not be construed as legal advice. Financial institutions should consult legal counsel and compliance advisors regarding their specific examination obligations.
Key sources: Executive Order 14412 (whitehouse.gov, June 22, 2026); OMB M-26-15 (whitehouse.gov, June 24, 2026); NIST FIPS 203/204/205 (csrc.nist.gov, August 2024); CISA PQC Product Categories List (cisa.gov, January 23, 2026); NIST IR 8547 initial public draft (November 12, 2024); U.S. Department of the Treasury, “Treasury Announces the Quantum-Readiness Task Force” (home.treasury.gov, August 24, 2026).