Payment systems are built on trust. Every transaction, every authentication, every data exchange relies on cryptographic foundations that ensure confidentiality and integrity. The transaction data containing an individual’s credit card number, account number and authentication credentials are protected through multi-layered encryption and signatures that only the intended recipients can decrypt and validate. Yet these encryption algorithms that protect trillions of dollars in daily transactions are approaching obsolescence.
Quantum computers capable of breaking today’s encryption algorithms are no longer a distant risk; they’re an approaching reality. We believe that by the early 2030s, a “cryptographically relevant” quantum computer can be used to break current encryption standards.
For financial institutions managing payment systems, the question isn’t whether quantum computing will disrupt current security measures, but when. Even more concerning is the fact that cybercriminals are already preparing, harvesting encrypted payment data today with the intent to decrypt it tomorrow. They plan to exploit this data when they’re able to gain access to such powerful quantum computers.
To protect payment data from such post-quantum risks, organizations must upgrade the cryptography used during transit through the network and at rest to the latest post-quantum cryptography standards.
Current payment encryption standards weren’t designed for a quantum future. The mathematical problems that make RSA and ECC secure today will be trivially solvable by quantum computers sometime in the next few years. Unlike typical cybersecurity threats that target immediate vulnerabilities, the post-quantum risk is unique. Adversaries can steal encrypted data along with the public keys now and simply wait to gain access to “cryptographically relevant” quantum computers before decrypting it.
The responsibility for protecting customers’ financial data, authentication credentials and other personal data, such as a mobile number and a social security number, lies with multiple entities of the payment ecosystem. These institutions include:
· Market infrastructures: Central securities depositories, CCPs, payment system operators, ACH operators, RTGS operators
· Central banks: Issuing and operating wCBDC, operating settlement infrastructure, RTGS and related high-value payment systems
· Commercial banks: Institutions operating as direct RTGS participants, correspondent banks, stable coin issuers
· Fintech payment processors: Those handling high-volume real-time payments, cross-border gateways
· Stable coin and digital asset operators: Licensed stable coin issuers, token-based deposit platforms
Payment data in these systems has long-term value. Compromised transaction histories, customer profiles and authentication data can be exploited years after capture. Regulatory bodies worldwide are developing new compliance frameworks that will require quantum-safe cryptography.
The financial consequences can be substantial. IBM’s 2026 Cost of a Data Breach research consistently shows that data breaches in the financial sector rank among the most expensive across industries, with the average cost of a breach reaching USD 6.29 million. These costs extend well beyond incident response to include customer churn, regulatory scrutiny, litigation and reputational damage. Organizations that proactively strengthen their security posture can significantly reduce financial exposure when incidents occur.
The challenge extends beyond technology. Many financial institutions lack visibility into where cryptographic keys are used across their payment infrastructure. The lack of visibility makes migration to quantum-safe standards seem overwhelming. The complexity of payment ecosystems, with multiple platforms, legacy systems and interconnected partners, amplifies the challenge.
The 2026 Cost of Data Breach Report found that only 37% of breached organizations reported encrypting sensitive data at the time of the breach. Just 34% had controls in place to monitor and secure cryptographic assets such as keys and certificates across their environments. As payment ecosystems become increasingly interconnected, these visibility and governance gaps can create significant exposure.
Building quantum resilience requires more than deploying new algorithms. It requires discovering where cryptography is used, identifying vulnerabilities, establishing crypto-agility and creating a roadmap for migration to post-quantum security standards.
Recognizing the urgency and complexity of this challenge, IBM Payments Center®, IBM Consulting® and Thales have joined forces to deliver a comprehensive Quantum Safe Payments offering. This collaboration combines IBM’s deep expertise in payment platform integration with Thales’ leadership in cryptographic security. This partnership provides financial institutions with a clear path to post-quantum resilience.
At the heart of this offering are Thales quantum-safe hardware security modules (HSMs) and high-speed encryptors (HSEs), validated to FIPS 140-3 Level 3. Both support NIST-standardized post-quantum algorithms developed by IBM cryptography researchers: Luna HSMs support ML-KEM and ML-DSA. High-speed encryptors support ML-KEM, ML-DSA and SLH-DSA.
The HSMs provide cryptographic protection across critical payment rails, from real-time gross settlement (RTGS) and real-time payments (RTP) to emerging wholesale central bank digital currencies (wCBDC) and stable coin infrastructure. High-speed encryptors protect payment data in motion across network links.
Built-in crypto agility ensures that payment platforms can seamlessly shift between cryptographic algorithms as standards evolve, without requiring infrastructure overhauls. This future-proof approach protects your investment while maintaining the flexibility to adapt to emerging threats and regulatory requirements.
The solution enables seamless integration with minimal operational impact across the entire payment ecosystem. Financial institutions can protect RTGS settlement systems, RTP networks, cross-border payment flows and digital asset infrastructure while maintaining business continuity and ensuring uninterrupted service to customers.
Centralized security management provides visibility and control over cryptographic operations across all payment rails. This unified approach eliminates fragmentation, replacing siloed cryptographic systems with a coordinated strategy that addresses the full scope of payment security, from traditional banking rails to next-generation digital currencies.
While quantum-safe protection is the immediate driver, the benefits extend far beyond threat mitigation. Organizations that act now position themselves for strategic advantage across multiple dimensions.
Risk mitigation and trust protection: By implementing quantum-safe cryptography today, financial institutions protect against future quantum risks while safeguarding their most valuable asset, customer trust. A security breach involving payment data can take years to recover from. Proactive post-quantum cryptography protection demonstrates a commitment to customer security and brand integrity.
Operational efficiency: The centralized approach to cryptographic management streamlines security operations, reducing complexity and administrative burden. Organizations gain clear visibility into their cryptographic infrastructure, enabling better governance and faster response to emerging threats. The minimal disruption to existing operations means that security teams can focus on strategic initiatives rather than crisis management.
Competitive advantage: Early movers in quantum-safe payments gain significant competitive benefits. They can market their post-quantum cryptography-ready infrastructure to security-conscious customers and partners, differentiate themselves in competitive markets and establish themselves as innovation leaders. As quantum risks become more widely understood, customers will increasingly favor institutions that have taken proactive steps to protect their financial data.
Regulatory readiness: With regulatory frameworks for quantum-safe cryptography emerging globally, organizations that implement these quantum-safe protections now will be ahead of compliance requirements rather than scrambling to meet them. The use of NIST-approved algorithms, which will continue to evolve and expand over time, ensures alignment with evolving standards, demonstrating due diligence to regulators and reducing compliance risk.
Proven implementation methodology: The offering includes the structured, phased approach from IBM Consulting that manages risk and ensures success:
• Assess current cryptographic infrastructure and quantum-safe readiness
• Plan and design the optimal quantum-safe architecture
• Pilot the solution in controlled environments to validate its effectiveness
• Build the production implementation with proven methodologies
• Test comprehensively to ensure security and performance
• Deploy across the payment ecosystem
This methodology provides measurable milestones, risk-managed transitions and validation at each phase, transforming what seems like an overwhelming challenge into a manageable, step-by-step journey.
At IBM, we’ve spent decades helping financial institutions navigate technological disruption, from mainframes to quantum computers, from batch processing to real-time payments. We’re now addressing what can be the most significant cryptographic challenge of our generation. The risk of cryptographically relevant quantum computing to payment security.
This quantum risk to payment security is real, imminent and requires action today. While the quantum-safe technology can seem complex, the path forward doesn’t need to be. Together, IBM and Thales have created a comprehensive solution that makes quantum-safe payments achievable for financial institutions of all sizes.
Whether you’re a central bank protecting national payment infrastructure, a commercial bank securing customer transaction, a market infrastructure provider ensuring system integrity or a fintech innovating in digital payments, the time to act is now. The organizations that move first will not only protect themselves against future quantum risks. They’ll position themselves as leaders in the next era of payment security.
Contact IBM Payments Center or IBM Consulting to learn how the Quantum Safe Payments offering can protect your organization’s future. Our teams are ready to assess your current infrastructure, design a tailored quantum-safe strategy and guide you through every step of the journey to post-quantum resilience.
The future of payments is quantum-safe. Those leaders who act now will define the standard. Everyone else will be forced to follow it.