Taiwan FSC Issues Post-Quantum Cryptography Guidelines to Prepare for Financial Risks
As quantum computing capabilities continue to advance, the asymmetric encryption used in financial transactions could eventually be broken, exposing customer identities, transaction data and information retained for long periods. Taiwan’s Financial Supervisory Commission is therefore promoting migration to post-quantum cryptography to help financial institutions adjust their cybersecurity governance and encryption architecture in advance.
The FSC has issued its Reference Guidelines for Post-Quantum Cryptography Migration in the Financial Sector, setting out seven major strategies, including governance mechanisms and an inventory of cryptographic technologies. The guidelines also call for a cryptographic bill of materials, or CBOM, and cryptographic agility. They treat the possible emergence of quantum computers in 2029 as a risk milestone, encouraging the financial industry to begin planning its migration early.
All Coverage
2 original reportsThe Backstory
The history behind this eventTaiwan, US Push Financial Sector Toward Post-Quantum Security
Advances in quantum computing could eventually break encryption that underpins financial transactions, identity verification and online communications. The threat extends beyond cybersecurity: compromised cryptographic systems could erode trust among banks, customers and markets. Attackers may also collect encrypted data now and decrypt it once quantum capabilities mature, increasing pressure on financial institutions and their technology suppliers to begin a complex, multi-year transition before current protections become vulnerable.
The US Treasury and Taiwan’s Financial Supervisory Commission have established response groups and issued migration guidance for the financial sector. Institutions are being steered to inventory cryptographic assets, assess quantum exposure and prepare to deploy post-quantum cryptography, or PQC, with readiness targeted by 2035. The timetable makes migration a major enterprise transformation challenge, as banks must coordinate upgrades across core systems, vendors and cross-border transaction networks while maintaining security and operational continuity.
Taiwan Regulator Bolsters Financial Cyber Defenses for AI, Quantum Risks
Artificial intelligence can amplify automated cyberattacks, identity fraud and vulnerability discovery, while quantum computing could eventually undermine widely used public-key encryption. Taiwan’s Financial Supervisory Commission is responding through its Financial Cybersecurity Resilience Development Blueprint, shifting the sector’s focus beyond preventing intrusions to include rapid response, business continuity and recovery. The initiative matters because a successful attack on a major financial institution could disrupt payments, expose customer data and spread operational risk across the broader financial system.
The Financial Supervisory Commission has issued strategic recommendations for countering AI-enabled attacks and guidance for migrating to post-quantum cryptography. Financial institutions are expected to inventory cryptographic assets, identify systems most exposed to future decryption risks and prepare phased transition plans. The regulator disclosed no specific budget or single completion date in the provided reports, signaling that the effort is a longer-term preparedness program aimed at improving detection, response and recovery before quantum computers become capable of compromising existing encryption standards.
G7 and Taiwan’s FSC Advance Financial-Sector PQC Transition Roadmap
Rapid advances in quantum computing threaten to break conventional encryption algorithms, posing a major cybersecurity risk to the global financial system. To guard against “harvest now, decrypt later” attacks, the Group of Seven and Taiwan’s Financial Supervisory Commission are actively helping the industry upgrade its defenses. The transition to post-quantum cryptography, or PQC, is critical not only to institutional cybersecurity but also to national financial security.
The G7 Cyber Expert Group and Taiwan’s FSC recently reached a consensus, formally recommending that financial institutions aim to complete the migration of high-risk systems to PQC by 2035. Firms will need to pursue a six-stage transition covering risk assessment and implementation, while building cryptographic agility to address future threats.
Taiwan FSC Strengthens Financial-Sector Cybersecurity Coordination and AI Talent Development
Pi Wallet, owned by PChome, was reportedly hacked in a breach involving the personal data of about 3.5 million users, renewing scrutiny of data protection and cross-institutional incident response in the electronic payments industry. Meanwhile, advances in quantum computing and AI are accelerating both cyberattacks and defenses. Existing public-key cryptography could eventually be cracked, requiring financial institutions to upgrade encryption systems early and cultivate cybersecurity talent.
Taiwan's Financial Supervisory Commission issued its Reference Guidelines for the Financial Industry's Migration to Post-Quantum Cryptography on June 18, 2026, recommending that firms complete the transition by 2035 at the latest. A July 2 report quoted FSC Chairman Peng Jin-lung as acknowledging that salary structures constrain the recruitment of AI cybersecurity professionals. The Banking Bureau said the Financial Information Sharing and Analysis Center, or F-ISAC, operated by the Financial Information Service Co., would share hacker intelligence in real time and extend its coordinated defenses to the electronic payments industry.
Banks Must Accelerate Shift to Post-Quantum Cryptography as Quantum Threats Mount
U.S. banks and credit unions largely rely on public-key cryptography such as RSA and ECC to protect transactions and customer data. If fault-tolerant quantum computers become viable, those safeguards could be broken. The threat is already present because attackers can use a “harvest now, decrypt later” strategy, storing encrypted data today and decoding financial records that remain sensitive in the future.
NIST released three immediately deployable post-quantum cryptography standards—FIPS 203, 204 and 205—on August 13, 2024, covering ML-KEM and two digital-signature schemes. Google has used PQC to protect internal communications since 2022 and enabled ML-KEM by default in desktop Chrome in May 2024. Banks should immediately inventory their cryptographic assets and begin a phased migration.
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.
If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →