The G7 Central Banks Just Put Quantum Risk on the Regulatory Record. The Mainstream Press Is Still Selling the Wrong Clock.
On May 11, eight G7 central banks published their first joint reference report on quantum technologies. It names harvest-now-decrypt-later as a current concern for the financial system. Six days later
Qtonic Quantum Research Team | May 19, 2026
On May 11, 2026, the G7 central banks’ Quantum Technologies Working Group published its first public deliverable, “Preparing for Quantum Technologies: Key Considerations for Financial Sector Participants.”1 The working group is co-chaired by Banque de France and the Bank of Canada, and includes the Deutsche Bundesbank, the Bank of England, the Banca d’Italia, the Bank of Japan, the Federal Reserve Board, and the European Central Bank. Eight central banks. One document. It is the clearest joint central-bank signal yet that quantum risk has moved into the financial-supervision conversation.
The report is explicit about timing. It states that while the arrival of a cryptographically relevant quantum computer remains uncertain, the potential impact of such a device is now well identified. It names the harvest-now-decrypt-later risk by name, with the framing that encrypted data collected today could be decrypted in the future, highlighting the need to consider long-term data confidentiality.1 Deputy Governor Agnès Bénassy-Quéré of the Banque de France framed the release as a shared analytical framework for the financial ecosystem.
On May 17, CNN ran “Quantum computing threatens to unleash a cybersecurity crisis.”2 The piece cites Michele Mosca’s seventh edition Quantum Threat Timeline Report, Google’s 2029 commitment, and the March 31 elliptic curve cryptography paper. The framing is the framing every major outlet has converged on. There is a day called Q-Day. It arrives at some point in the future. We are racing to be ready when it does.
The G7 paper and the CNN piece tell two different stories about the same threat. The market has been reading the CNN version. The regulators just gave boards a different one.
Two clocks, and the G7 picked one
Figure 1. Two clocks of quantum risk. The hardware clock runs toward 2029 to 2035. The exposure clock started years ago.
There are two timelines that matter for any organization holding long-lived sensitive data. They run at different speeds. They require different actions.
The first clock is hardware capability. The arrival of a quantum computer capable of running Shor’s algorithm against production keys. Google’s working estimate is 2029.3 Mosca’s seventh edition Quantum Threat Timeline Report calls a full-scale CRQC quite possible within ten years and likely within fifteen.4 Those are real numbers. They are also the wrong numbers to plan against if the confidentiality requirement on your data runs longer than the gap between today and the earliest plausible CRQC date.
The second clock is exposure. Harvest now, decrypt later. Adversaries are collecting encrypted traffic today. They are betting that decryption capability will arrive before the data’s confidentiality requirement expires. For any data class with a ten to fifty year confidentiality window, including health records, financial transactions, intellectual property, defense communications, and personally identifiable information, that bet may already be economically rational for an adversary.
The G7 paper picked the second clock. It does not lead with when the hardware arrives. It leads with the long life span of sensitive data and what that means for institutions whose confidentiality requirements run past any reasonable estimate of when a CRQC is delivered. That framing is not new inside the cryptographic community. It is new on a G7 central banks document.
Why this paper is different from the January roadmap
The G7 Cyber Expert Group published its post-quantum cryptography roadmap for the financial sector on January 13, 2026.5 That paper was authored by cybersecurity authorities. It targeted CISOs and crypto teams. It moved the migration conversation forward.
The May 11 paper is different. It is from the central banks themselves, not the cyber advisory group. The text covers encryption, payment systems, financial modeling, and market operations. The Banque de France press release describes a fundamentally systemic consideration, citing potential implications for financial stability and the resilience of market infrastructures.1
That kind of document does not change regulation. It is likely to move G-SIB board and risk committee conversations this quarter, because it gives compliance counsel a central-bank document to cite. The supervisory frame has shifted. Quantum risk is no longer a future concern living inside the security team’s planning deck. It is a current concern living inside the central bank’s published thinking on financial stability. Boards that have been treating it as the former are about to be asked to defend that position.
NIST and the infrastructure operators moved this week too
On May 14, NIST advanced nine post-quantum digital signature algorithms into the third round of its additional signature standardization process. Refined submission packages are due August 14, 2026.6 The implication for any organization counting on a single algorithm choice is direct. The standards portfolio is still expanding. The defensible architectural decision is not which algorithm to deploy, but how to deploy one in a way that can be rotated without re-architecting the system.
Google and Cloudflare have both put 2029 on the table as an operational migration target. Google introduced a 2029 timeline to secure the quantum era.7 Cloudflare says it is targeting 2029 to be fully post-quantum secure across its global infrastructure.8 These are not policy papers. They are infrastructure operators telling the market what serious preparation now looks like.
That is crypto-agility, and it has been reinforced from three directions in the same week. Central banks pushed on what to migrate. NIST kept expanding the candidate set that migration planning may need to account for. Infrastructure operators put down a date and a deliverable. All three point to the same operating reality: the migration is not a one-time project. It is a permanent capability.
Why the countdown frame is sticky and dangerous
The Q-Day framing is sticky for understandable reasons. It is dramatic. It produces a calendar. It maps onto coverage models that work for hurricanes, elections, and Olympic torches. It also tells the executive reader what they want to hear, which is that there is still time.
The danger is what it tells the budget owner. A board that believes Q-Day is a 2029 problem will fund a 2027 procurement cycle and a 2028 migration. A board that reads the G7 paper and understands the harvest is already running treats every additional day of unmigrated long-lived data as net new exposure. Those are different budgets and different urgency profiles. The difference is the gap between reacting to a headline and reading the threat model the regulators just put on the record.
The CISO sitting on a board this week needs two answers, not one. What is the plan for 2029. And what was the exposure as of yesterday.
What measurable today actually means
Exposure on the second clock is measurable now. Not predicted. Measured.
In Qtonic’s internal assessment corpus, available for customer review under NDA, we have observed an average harvest-now-decrypt-later exposure of 99 percent across more than 50 Fortune 1000 engagements, with 162,000 cryptographic findings documented to date.9 The number that should concern an executive is not the average. It is the variance. Some environments are exposed at the perimeter. Others run quantum-vulnerable cryptography through identity, signing, and code distribution all the way to the boot loader. The buyer who treats this as one number is solving the wrong problem.
The Qtonic Quantum Lab independently scores 215 post-quantum implementations across 12 live categories. By the Lab’s scoring model, the current average remains below a passing enterprise-readiness threshold, under a signed and published methodology with no pay-to-play vendor inclusion.10 That is the state of the defenses being marketed to the same buyers reading the CNN piece. The market is full of products still benchmarking themselves against the same standards the buyer is supposed to be migrating to.
Forescout’s global adoption analysis adds a sobering external data point. Only 8.5 percent of SSH servers worldwide support post-quantum encryption. TLS 1.3 adoption, the TLS version needed for modern PQC deployment, sits at roughly 19 percent of global communications.11 The starting line is further back than most boards think.
None of these numbers is a forecast. All of them are produced by measurement against real environments and real implementations. They do not require a position on when Q-Day arrives. They describe what is true now.
What changes when you switch clocks
Three things change for the executive who runs the second clock instead of the first.
Procurement timelines compress. NIST’s Cryptographic Module Validation Program allows active FIPS 140-2 modules to be used until September 21, 2026, after which validation certificates move to the Historical list.12 CNSA 2.0 takes effect for all new National Security System acquisitions on January 1, 2027.13 Code signing and networking equipment milestones land in 2030. Operating systems and web and cloud services in 2033. Full NSS transition by 2035. The G7 financial sector roadmap aligns around the same 2030 to 2035 window. The EU NIS Cooperation Group roadmap asks member states to publish national PQC strategies, initiate cryptographic inventories, and launch pilots by the end of 2026.14 Those dates do not move when a CRQC is delivered. They move when the calendar does.
Inventory becomes the binding constraint. You cannot migrate what you cannot see. Public-key cryptography is embedded in TLS termination, certificate chains, code signing infrastructure, VPN tunnels, hardware security modules, IoT firmware, embedded medical devices, payment terminals, identity providers, mobile applications, and the dependency trees underneath all of it. Most security teams can produce a partial certificate inventory. Very few can produce a complete cryptographic bill of materials.
Crypto-agility replaces algorithm choice as the architectural requirement. NIST finalized FIPS 203, 204, and 205 in August 2024.15 Nine more signature candidates advanced this month. The defensible architecture is one that can rotate algorithms without rotating systems. That decision has to be made before the migration starts, not discovered during it.
Where Qtonic comes in
Qtonic Quantum Corp exists for the part of the problem most boards still underestimate: proving current exposure before the migration plan becomes a procurement exercise.
The question is no longer whether post-quantum migration belongs on the roadmap. The question is whether the institution can answer three things today.
That is what QScout was built to answer. QScout produces the cryptographic posture map across externally reachable infrastructure, certificates, TLS, DNS, public code exposure, cloud exposure indicators, identity surfaces, and quantum-vulnerable trust paths. The output is not a generic scan. It is a defensible evidence package: exposure findings, severity, harvest-now-decrypt-later signal, migration priority, CBOM in CycloneDX format, and compliance mapping across 15 frameworks.
QStrike tests whether the risk model survives contact with validation. It is not slideware. It validates quantum-relevant attack models and migration assumptions across approved platform profiles, bounded test designs, and available quantum hardware modalities.
QSolve turns the evidence into migration execution. Vendor-neutral, CISO-led, and aligned to the dates regulators and standards bodies are already putting on the calendar: FIPS 140-2 transition, CNSA 2.0, NSM-10, the G7 financial-sector roadmap, and the 2030 to 2035 transition window.
Qtonic Quantum Lab gives buyers a way to challenge the market. It scores post-quantum implementations under a signed methodology with no pay-to-play vendor inclusion, so boards can separate quantum-ready claims from quantum-ready evidence.
The operating model is simple. Find. Prove. Fix. Find the cryptography. Prove the exposure. Fix what matters first. That is the difference between having a post-quantum strategy and having evidence a regulator, auditor, acquirer, or board can trust.
The mainstream frame will keep selling the countdown because countdowns are good television. The threat model has not changed since Mosca first published the Quantum Threat Timeline in 2019. What changed on May 11 is that the G7 central banks put it on the record. The next supervisory cycle will read that paper. Your board’s compliance counsel already did.
A reasonable skeptic will argue that the second-clock framing is alarmist because most enterprise data does not have a ten to fifty year confidentiality window. That is fair for some data classes. It is not fair for the data classes that drive regulated industries, federal contracting, or any acquisition pipeline where a buyer’s diligence team will ask what was your exposure window. The harder argument to dismiss is that the inventory you need for 2029 is the inventory you needed in 2024. Starting in 2027 is starting late.
Find. Prove. Fix.
qtonicquantum.com | +1 (866) 4-QTONIC











