2026-06-18

Added · Updated

Financial Industry Post-Quantum Cryptography Migration Reference Guidelines

The Financial Supervisory Commission issues reference guidelines requiring financial institutions to prepare for quantum computing risks by adopting seven strategic directions: establishing PQC governance, creating a cryptographic bill of materials, enhancing crypto-agility, building ecosystem collaboration, prioritizing migration based on risk, updating supply chain management, and establishing testing and resilience mechanisms. The guidelines outline a phased timeline with short-term goals for 2026-2027, mid-term objectives for 2027-2029, and long-term migration targets through 2035, focusing on high-risk systems and ecosystem alignment.

Financial Supervisory Commission Taiwan logo

Taiwan

Financial Supervisory Commission Taiwan

Click to view thumbnail

Announcement Information

Back to Homepage

Announcement Information

Press Release

Press Release

_

FACEBOOK

Line

Twitter

Print-Friendly

Back to Previous Page

Financial Supervisory Commission Releases "Financial Industry Post-Quantum Cryptography Migration Reference Guidelines" to Guide Financial Institutions in Strengthening Quantum Risk Preparedness

2026-06-18

To assist financial institutions in addressing cybersecurity risks potentially brought by the development of quantum computing technology, the Financial Supervisory Commission (hereinafter referred to as the FSC) has released the "Financial Industry Post-Quantum Cryptography Migration Reference Guidelines" as a reference for the financial industry's preparation work for Post-Quantum Cryptography (PQC) migration. The guidelines propose planning priorities and recommendations regarding governance mechanisms, cryptographic technology inventory, crypto-agility, ecosystem collaboration, risk prioritization, supply chain management, and testing and switching, to facilitate financial institutions in preparing relevant migration operations in accordance with risk-oriented and gradual principles.

The FSC previously released the "Financial Cybersecurity Resilience Development Blueprint" at the end of 2025, which listed the migration of post-quantum cryptography in the financial industry as one of the key promotion items. Considering that financial services highly rely on identity verification, transaction signatures, cross-institutional interfacing, and data protection mechanisms, as quantum computing technology continues to develop, current public key cryptography mechanisms may face security risks in the future. This may give rise to threats such as "Harvest Now, Decrypt Later" (HNDL, i.e., intercepting encrypted data first and decrypting it later when quantum computing technology matures) and "Trust Now, Forge Later" (TNFL, i.e., digital signatures or certificates that are currently trusted may be forged later), thereby affecting transaction security, data confidentiality, integrity, and the operational stability of financial institutions. Therefore, it is necessary for financial institutions to plan and promote preparation work early.

The FSC stated that this reference guideline focuses on application scenarios unique to the financial industry, cross-institutional interoperability dependencies, and high-availability operational constraints, providing seven strategic directions for the financial industry to respond to PQC:

  1. PQC Policy and Governance - Incorporating Cryptographic Technology Risks into Enterprise Risk Management: PQC migration is a long-term project spanning multiple years and departments. Financial institutions must elevate quantum risks to the board of directors level, treating them as strategic issues in enterprise risk management. Additionally, a cross-departmental "Post-Quantum Migration Working Group" should be established, chaired by the Chief Information Security Officer (CISO), Chief Information Officer (CIO), or equivalent senior management, with clear responsibilities and authorities defined.

  2. Inventory Cryptographic Technology Applications, Establish a Cryptographic Bill of Materials (CBOM): Cryptographic technology inventory must form a maintainable, linkable list of cryptographic technology assets connected to business usage scenarios and external dependencies. It is advisable to adopt a strategy of "first limiting the inventory scope based on risk and priority, then gradually expanding coverage," prioritizing list quality. Progress can be made gradually through methods such as establishing a basic ledger, scenario-oriented approaches, establishing a maintainable CBOM, layered inventory introduction methods, and institutionalizing inventory. Additionally, the use of AI and other automated tools to assist in inventory and CBOM maintenance should be evaluated.

  3. Enhance Crypto-Agility, Prioritize Elimination of "Cryptographic Anti-Patterns": Given that PQC standards and products continue to evolve, migration strategies should not aim for one-time algorithm replacement. Instead, crypto-agility (the ability to quickly and effectively adjust algorithms) should be enhanced simultaneously, facilitating routine changes during algorithm or parameter iterations to avoid every update becoming a large-scale renovation project. The goal is to design cryptographic mechanisms as independent modules, paired with automated certificate management. Practically, it is recommended to prioritize improving cryptographic anti-patterns (such as manual management of Transport Layer Security (TLS) certificates, weak cipher suites, hardcoded key certificates, etc.).

  4. Establish Ecosystem Collaboration Mechanisms and Common Business Risk Profiles: Given the high interconnectivity of the financial ecosystem, this reference guideline promotes cross-institutional alignment using the "Four-Stage Presentation" concept. Hub institutions (such as the Taiwan Financial Services Center, Taiwan Stock Exchange, etc.) take on the role of coordinating promotion, responsible for drafting the ecosystem migration roadmap and operating cross-institutional collaboration mechanisms. Representative financial institutions should first propose common business inventory frameworks and risk profiles as reference drafts, assisting peers in conducting their own inventories with a consistent context.

  5. Establish Migration Priorities Based on Risk: A cross-evaluation using "Quantum Risk Scoring" and "Migration Time Scoring" axes is adopted. The results of the two axes are converted into risk levels and migration difficulty clusters, using relative ranking to determine migration priorities and resource allocation. Necessary constraints (such as timelines involving ecosystem migration) are included, transforming migration priorities into executable, phased, verifiable, and rollable migration roadmaps.

  6. Update Procurement and Supply Chain Management Requirements: Financial institutions should explicitly incorporate PQC readiness and crypto-agility into procurement, outsourcing, and contract management mechanisms. This can be introduced in phases through actions such as initiating PQC readiness surveys for key suppliers, updating procurement document requirements (procurement/specifications/acceptance), revising procurement and outsourcing contracts (responsibilities/service levels), establishing early disposal mechanisms for bottleneck components, establishing a supply chain joint verification mechanism, and feeding supply chain information back into migration prioritization.

  7. Establish Testing, Switching, and Operational Resilience Mechanisms: In addition to selecting algorithms and completing supply chain coordination, the key to the safe launch and stable operation of PQC or hybrid models lies in testing governance, switching strategies, rollback drills, and observability. Financial institutions should institutionalize related activities to form repeatable, auditable evidence chains, reducing risks of service interruption, interoperability failure, and exception handling during migration. This can be gradually introduced through practices such as testing governance, switching and rollback, monitoring and observability, evidence retention, and audit correspondence.

Regarding the overall promotion timeline, the guidelines reference migration roadmaps and international standard development trends proposed by international organizations such as NIST, G7, and FS-ISAC, recommending that the financial industry carry out relevant preparation work in a step-by-step manner. Short-term (2026 to 2027) focuses on establishing governance structures, inventory methods, cryptographic technology ledgers, and the foundation of crypto-agility. Mid-term (2027 to 2029) emphasizes promoting pilot validations, basic upgrades, and common testing mechanisms. Medium-to-long term (through 2035) prioritizes migration for high-risk and highly critical systems, gradually expanding migration scenarios.

The FSC also stated that the current stage primarily aims to drive financial institutions and key suppliers to plan and prepare early. It will continue to focus on three main lines: ecosystem alignment, supply chain governance, and pilot validation. These include hub institutions drafting financial ecosystem migration plans, establishing (or integrating) common supply chain surveys and tracking mechanisms, and promoting pilot trials and experience sharing.

The FSC will also continue to review and adjust the promotion timeline and refine the guideline content in a rolling manner, depending on domestic and international technological developments, standard evolution, and financial practical needs. Through pilot validations, experience sharing, and ecosystem collaboration, it will consolidate consensus and practices for post-quantum cryptography migration in the financial industry, facilitating smooth alignment with international development trends and the overall ecosystem promotion timeline.

Contact Unit: Information Services Division Contact Phone: (02)8968-0806 For any questions, please email: Our Public Opinion Mailbox

Related Attachments

PQC Presentation

Financial Industry Post-Quantum Cryptography Migration Reference Guidelines

Page Views: 9274

Last Updated: 2026-06-18

:::

Privacy Policy Declaration |

Information Security Policy Declaration |

Our Website Data Open Declaration |

Subscribe to Newsletter |

Latest Newsletter

Financial Supervisory Commission Copyright 220232 No. 18, Section 2, Xianmin Avenue, Banqiao District, New Taipei City

FSC Electronic Map

Phone: (02)8968-0899 Fax: (02)8969-1215

Our Representative Office in New York: 1 E.42 Street, 13F, New York, NY 10017, U.S.A. Contact Phone: (1-212) 317-7326

Our Representative Office in London: 46-48 Grosvenor Gardens London SW1W 0EB, UK Contact Phone: (44-20)7628-1501

If you have specific suggestions for improving our global information network, please email us. Thank you.

Last Updated: 2026-08-14

Visitor Count: 61516910

Back to Top

More like this from FSC

FSC published 10 documents in the last 30 days. We email you each new one the day it's published.

Share