Blog · October 11, 2026

What would Q-Day mean for your bank?

Card payments and PINs are mostly safe from quantum computers. Online banking sessions, stored records and the keys that prove a message really came from a bank are not. A system-by-system look.

A round bank vault door drawn in white dots, with bolts around its edge and a three-spoke handle wheel.

Less than the headlines suggest for card payments, and more than most people realise for the records banks keep. Q-Day is the day a quantum computer can break the encryption most of the internet relies on. Paying with a card and entering a PIN use a different kind of encryption, which quantum computers barely weaken. The exposed parts are online banking sessions, stored records, and the digital signatures that prove a message or update really came from a bank.

Two kinds of encryption

Banks use two kinds, and a quantum computer affects them very differently.

Symmetric encryption uses one shared secret key to lock and unlock. AES is the common one. The best known quantum attack, Grover’s algorithm, only halves the effective length of the key, and a 128-bit AES key already has a large margin to spare. The US standards agency NIST doesn’t plan to retire it.

Public-key encryption uses a pair of keys, one shared openly and one kept private. It is how two computers that have never met agree on a secret, and how a signature proves who sent something. RSA and elliptic curves are the common ones. Shor’s algorithm breaks both outright.

So the question for each part of a bank is which kind it uses.

● Uses encryption Shor's algorithm breaks. ○ Doesn't.

Read later, or forge later

A broken public key can be used in two ways, and they have different deadlines.

Reading later. Someone can record encrypted traffic today and decrypt it once a large enough quantum computer exists. This is called harvest now, decrypt later. It affects anything that has to stay private for years after it is sent.

Forging later. Once a key is broken, someone can sign things as if they were the bank: a fake certificate for a banking website, a fake card that passes an offline check, or a malicious update that looks official. That needs the quantum computer to exist first, so it puts nothing happening today at risk. The fix is to switch to new signatures before that happens.

Card payments sit mostly outside both. A chip card proves itself to the bank with a symmetric key, and the codes it produces are useless once the payment is done. EMVCo, which writes the chip card standards, doesn’t expect a practical quantum threat to them before 2040.

The data that has to stay secret longest

A simple rule, from the cryptographer Michele Mosca, sets the real deadline. Add how long the data must stay secret to how long switching to new encryption will take. If the total is longer than the time until a large quantum computer exists, you are already late.

A mortgage file sent today over a connection without post-quantum protection needs to stay private for the length of the loan, often 25 years, which runs to about 2051. Identity documents collected when you open an account need to stay private for life. Even EMVCo’s cautious “not before 2040” falls well inside that.

Estimates of when the machine will exist vary widely. In a survey published by the Global Risk Institute in March 2026, experts put the chance of one within ten years at roughly 28% to 49%. The Q-Day tracker shows how the hardware compares with the estimates.

The deadlines

Governments have set dates for banks and others to stop relying on RSA and elliptic curves.

Who Deadline
US (NIST) Deprecated after 2030, disallowed after 2035
European Union High-risk systems, including finance, by the end of 2030. Everything by the end of 2035.
United Kingdom Plans by 2028, priority systems by 2031, everything by 2035
G7 finance ministries Critical systems by 2030 to 2032, everything by 2035 (guidance, not binding)

What has been tried

In 2025 the Bank for International Settlements, with the central banks of France, Germany and Italy, tested post-quantum signatures on real transfers in a working payment system. Every test passed, though processing took noticeably longer. JPMorgan runs a link between two of its data centres secured with quantum key distribution, a separate technique that uses light rather than math. HSBC has tested post-quantum encryption for trading tokenised gold.

These are trials. The slow part is everything that has to change together: card network root keys that stay valid until the mid-2030s, terminals in shops and transit gates, hardware security modules, and software at thousands of banks.

What you can check

For your own online banking, the part you can see is the connection. Recent versions of Chrome already use post-quantum key agreement by default, so a recorded session can’t be decrypted later, as long as the bank’s servers support it too. To check, open your bank’s site in Chrome, then open Developer Tools and find the Security or Privacy and security panel. If the connection lists X25519MLKEM768, it is protected against harvest now, decrypt later.

Nothing else on this list is something a customer can change.

Sources