Branch and Vault
Live
Banks

Banks Face 2030 Deadline for Post-Quantum Security

European banks must upgrade encryption by 2030 to resist future quantum computer attacks, per new EU cybersecurity rules.

European banks must upgrade encryption by 2030 to resist future quantum computer attacks, per new EU cybersecurity rules

European banks and financial institutions must complete their migration to post-quantum cryptography by the end of 2030 for high-risk systems, according to an EU roadmap. This shift is driven by new regulations including the Digital Operational Resilience Act (DORA) and the NIS2 Directive, which raise the bar for encryption and the protection of sensitive data moving across networks.

The finance and insurance industry accounted for 23% of cyber incidents investigated by IBM X-Force in 2025, making it one of the most targeted sectors. In response, securing data in transit has become a fundamental requirement for maintaining operational resilience, not an optional extra.

The Regulatory Push for Crypto-Agility

The EU's coordinated post-quantum cryptography roadmap sets a clear deadline. Regulations like DORA are increasing expectations for what is termed 'crypto-agility'-the ability to adapt encryption standards without major hardware overhauls. For financial organisations, this means building network architectures that can evolve alongside security threats and regulatory demands.

Regulators now expect businesses to manage ICT risks across the full chain of infrastructure. This includes the geographically dispersed networks that connect internal systems to cloud platforms and third-party providers.

Managing Risk in Distributed Networks

Modern banking operations are spread across private data centres, cloud platforms, and third-party providers simultaneously. A single transaction can pass through all these environments before it settles. This distribution supports flexibility but makes the network harder to oversee, complicating the task of tracing data flows and identifying exposure points for network operations teams.

Historically, much security investment focused on applications, endpoints, and stored data. Today, institutions need the same level of confidence in how information is protected during transit as they have when it is at rest.

Building a Resilient Network Architecture

The challenges of distributed networks and new regulations are changing what banks need from their network infrastructure. Capacity and low latency remain critical, but they are now joined by non-negotiable requirements for stronger visibility and operational assurance. Key capabilities include:

  • Dedicated private connectivity between critical locations.
  • Optical-layer encryption to protect sensitive data in transit.
  • Greater visibility across the transport layer to support monitoring.
  • Crypto-agile architecture that supports new standards without hardware swap-outs.
  • Predictable, low-latency performance for critical applications like trading platforms.

Resilient infrastructure depends on these elements working in combination to provide confidence in the security and integrity of critical services.

The Long Transition Ahead

The transition to post-quantum security is a long-term project, requiring planning and alignment with hardware refresh cycles. Flexible network infrastructure that can adapt to evolving standards will allow financial institutions to manage this shift without disrupting services. The banks that invest now in network visibility, secure data transit, and dedicated infrastructure will be best positioned to meet the converging demands of network performance, finance, and security tomorrow.

Topics

#Banks

Related coverage

More from Banks