
The US Treasury has launched a public-private task force to coordinate the financial sector’s transition to post-quantum cryptography financial institutions, market infrastructures, technology providers and other private-sector participants.
The Quantum-Readiness Task Force will organise its work around three areas: sector alignment and migration; third-party and vendor readiness; and risks involving digital assets and emerging technologies. Treasury said the group would examine critical dependencies, cryptographic agility, interoperability and the operational resilience of the transition.
The initiative follows Executive Order 14412, issued in June, which established a federal programme for migration to cryptographic standards designed to withstand attacks from quantum and conventional technologies. The order requires federal high-value assets and high-impact systems to adopt post-quantum cryptography for key establishment by the end of 2030 and digital signatures by the end of 2031.
Treasury’s task force builds on the G7 Cyber Expert Group’s January 2026 transition roadmap which sets out six broad phases, beginning with awareness and cryptographic-asset inventories before moving through risk assessment, migration, testing and continuous monitoring. The roadmap is intended to encourage financial firms and authorities to prioritise systems according to their criticality and risk.
Both Treasury and the G7 roadmap identify vendor coordination and transparency as important to avoiding gaps between firms and their technology providers. “Post-quantum cryptography readiness is no longer a future-proofing exercise—it is a present-day risk control,” said Debbie Guild, Chair Emeritus at the Financial Services Sector Coordinating Council (FSSCC) and head of Technology at PNC Financial Services Group.
Treasury has yet to identify the task force’s participating organisations or provide dates for its work products or set migration deadlines for the industry. Its immediate focus is on industry coordination: identifying dependencies, aligning priorities and addressing practical obstacles before quantum-related cryptographic risks become operational threats.
The US Treasury is the latest jurisdiction to announce a response to emerging cyber threats from quantum technologies, but preparations are already under way across several major financial markets.
Australia has adopted the most demanding timetable, calling for organisations to complete migration plans by the end of 2026, begin implementation by 2028 and discontinue vulnerable asymmetric cryptography by 2030. The Australian Prudential Regulation Authority (APRA) plans to assess whether regulated firms and their boards are making timely progress.
The UK National Cyber Security Centre (NCSC) has set milestones of 2028 for discovery and planning, 2031 for priority migrations and 2035 for full implementation. The Bank of England has applied that timetable to financial-sector resilience, urging firms to map cryptographic dependencies and assess the readiness of material technology providers.
Canada’s Office of the Superintendent of Financial Institutions (OSFI) has published a financial-sector framework covering governance, cryptographic inventories, third-party dependencies, migration and testing. Japan’s Financial Services Agency (FSA) is similarly pressing financial institutions to prepare inventories and migration roadmaps, with progress subject to supervisory monitoring.
The European Union has set 2030 and 2035 milestones for critical and wider infrastructure. Europol’s Quantum Safe Financial Forum is translating that programme into practical guidance for financial institutions. Central banks are also testing implementation: Banque de France, the Monetary Authority of Singapore and partners in the Bank for International Settlements’ Project Leap have trialled post-quantum protection for communications, regulatory data transfers and payment systems.
The distinctive feature of the Treasury announcement is the decision to place sector alignment, vendor readiness and digital-asset within a single, Treasury-led task force. Other jurisdictions have generally split those functions between national cyber agencies, prudential regulators, industry forums and central-bank experiments.
Subscribe to our newsletter


