Banks Can Finish Post-Quantum Migration and Still Be Exposed: Treasury Targets Vendors
The US Department of the Treasury launched its Quantum-Readiness Task Force on August 24 — a public-private body designed to coordinate the American financial sector's migration to encryption that future quantum computers cannot break.…
Tech Times
Publisher
Aug 26, 2026 at 7:50 PM UTC · 14 dk okuma

The US Department of the Treasury launched its Quantum-Readiness Task Force on August 24 — a public-private body designed to coordinate the American financial sector's migration to encryption that future quantum computers cannot break. What the announcement reveals, between its formal workstream names, is a structural reality that has received little direct government attention until now: a financial institution's quantum readiness ceiling is not set by its own engineers. It is set by the vendors those engineers depend on.
That is the gap the Task Force's Third-Party & Vendor Readiness workstream was created to close. Most banks, credit unions, exchanges, and clearing houses do not write their own cryptographic libraries. They buy core banking software from a handful of major vendors, process payments through platforms they cannot audit end-to-end, and run operations on SaaS products whose cryptographic internals are entirely opaque to them. When those vendors are not ready for post-quantum cryptography (PQC), the institution is not ready — regardless of how much internal migration work has been completed. "Bank quantum readiness ends where third-party vendor crypto opacity begins," as Moody's vice president David Tao framed it in an assessment published by Computer Weekly.
Article Intelligence
Related Coverage
Sponsored
AdNewsLayer Premium
Unlock deeper intelligence.
Ad-free reading, exclusive research, and real-time onchain insights.
Go Premium
