Treasury has set up a task force to move the financial system off encryption a quantum computer could break, and the order behind it sets no date for anyone outside government
Stock photo
Treasury announced a Quantum-Readiness Task Force on Monday. The executive order it follows does not require one.
The task force is described as a public-private initiative to accelerate the American financial sector's transition to quantum-safe technology, building on the G7 Cyber Expert Group roadmap for the move to post-quantum cryptography. It will run three workstreams: Sector Alignment and PQC Transition, Third-Party and Vendor Readiness, and Digital Assets and Emerging Technology Risk. Treasury quotes its Assistant Secretary for Financial Institutions, Luke Pettit, and Deborah Guild, chair of the Financial Services Sector Coordinating Council and head of technology at PNC Financial Services Group, who says post-quantum readiness "is no longer a future-proofing exercise" but a present-day risk control.
The order's deadlines are for federal systems
The announcement follows Executive Order 14412 of 22 June 2026, Securing the Nation Against Advanced Cryptographic Attacks, published at 91 FR 38483. Its dates bind agencies. Federal high value assets and high impact systems must use post-quantum cryptography for key establishment by 31 December 2030 and for digital signatures by 31 December 2031, and the Federal Acquisition Regulatory Council was directed to propose a rule requiring covered contractors to comply with the relevant standards by that same 2030 date.
The order does not mention the Treasury Department anywhere in its text. Its critical infrastructure provision, section 5(a), directs agencies serving as Sector Risk Management Agencies to work with the Cybersecurity and Infrastructure Security Agency to assist owners and operators in developing migration plans, and attaches no date to that work.
Why a body with no deadline is still early
Section 1 of the order states the threat in two parts. One is the arrival of large-scale quantum computers in the hands of adversaries. The other is that an adversary can collect information now and decrypt it later, once such machines are operational, which is the part that makes any timetable a function of how long the stored material stays sensitive rather than of when the machine turns up.
