By Rajsri Rengan, VP and Head – Product Development, Infosys Finacle
Quantum computing has transitioned from laboratory curiosity to a subject of boardroom conversation. India is moving quickly on this incredible opportunity with the National Quantum Mission (NQM, 2023 to 2031), which seeks to build sovereign capabilities in quantum computing, communication, sensing, and materials to position the nation among the world’s top quantum economies by 2035.
The same technology that creates this huge opportunity also threatens the foundations of a highly regulated financial services industry. Quantum computing puts at risk the encryption standards that secure payment transactions today. UPI alone now processes more than 23 billion transactions a month, and that volume, along with card payments and inter-bank messaging, all rides on encryption that today looks unbreakable but won’t stay that way forever.
At some point in the coming decade, a sufficiently powerful quantum computer will be able to break the cryptography that underpins nearly every payment rail in use. However, only 5% of organisations globally report having a defined quantum readiness strategy as found by ISACA’s global Quantum Computing Pulse Poll.
For an industry that runs on real time processing, digital signatures and certificate checks, this is a governance and infrastructure challenge that belongs to the agenda now, not later.
A national mission that reaches into payments engine
India’s response has been to treat quantum technology as strategic infrastructure. The National Quantum Mission (NQM, 2023 to 2031) is building sovereign capability in quantum computing, communication, sensing and materials. With this mission, India became the seventh nation, after the US, China, Finland, Austria, France and Canada, to launch a dedicated national quantum programme.
The mission’s own framing names financial sector data security as a strategic priority. RSA and Elliptic Curve Cryptography (ECC), the mathematics that secures UPI transactions, card payments and inter-bank messaging alike, are acknowledged to be vulnerable once quantum computers reach sufficient scale. That is what connects this programme so directly to a bank’s payment engine roadmap.
The central bank is already taking steps
India’s central bank has been quite proactive. In May 2026, the Reserve Bank of India established the Q-SAFE Committee where top leaders from the State Bank of India and the National Payments Corporation of India are looking to quantify cryptographic inventory across the sector, assessing crypto agility, ascertaining vendor readiness, and creating a roadmap for quantum safe systems.
This initiative builds on an earlier one by the RBI Innovation Hub, whose whitepaper “Securing the Indian Banking Sector in the Age of Quantum Computing” already urged banks to transition to Post-Quantum Cryptography (PQC). The paper did not specify a binding timeline of its own, something that the Q-SAFE Committee’s roadmap is expected to do.
Why payments are exposed, and where it shows up
The threat does not begin with a working quantum computer but with “Harvest Now, Decrypt Later,” where adversaries capture encrypted payment data now to decrypt later. Long shelf-life data such as KYC records and transaction archives becomes more urgent to protect than day to day processing. From there, exposure runs across the stack:
Transport security – TLS/mTLS secure every API call and inter-bank link; their key exchange can be broken by Shor’s algorithm. Hybrid TLS (classical plus ML-KEM/Kyber) is the top priority fix, with negligible latency impact per BIS’s Project Leap.
Digital signatures – Schemes like ML-DSA (Dilithium) raise a size problem more than a speed one, straining ISO 8583, ISO 20022, UPI QR codes and POS/IoT terminals.
Infrastructure – HSMs and certificates need PQC ready vendor roadmaps (IDEMIA is already shipping PQC chips) and automated renewal.
Card and EMV rails – This need coordinated migration with EMVCo, Visa, Mastercard and RuPay, since no single bank can move alone.
Alongside this defensive picture, there is a genuine upside worth watching. Quantum computing itself is being explored for fraud detection and portfolio optimisation, serving as a reminder that quantum is worth building toward as well as defending against.
What banks and payments teams specifically should do now
The direction of travel is clear even before regulation catches up, and it follows the same order as the exposure itself:
Upgrade transport security first. Hybrid TLS carries a small latency cost relative to the risk it removes, making it the easiest place to start.
Re-encrypt long shelf-life data next. KYC documents, account records and transaction archives sit at the centre of Harvest Now, Decrypt Later exposure and deserve priority ahead of processing systems.
Start vendor conversations now. PQC ready HSMs, tokenization and certificate infrastructure involve long procurement cycles, so waiting for mandates will cost time.
Track the Q-SAFE Committee’s roadmap. It will likely set the scope and pace for the rest of the industry.
Underlying all four steps is one durable objective to achieve cryptographic agility, the ability to change algorithms without redesigning core payment applications. PQC replaces vulnerable public key mathematics, but PKI, certificates and HSMs still need to evolve alongside it.
As classical and post-quantum methods will coexist for years, platforms built to run into the 2030s should avoid embedding today’s algorithms so deeply that migration later means rewriting business logic instead of simply changing keys
A transition, not a crisis
Quantum computing’s arrival carries real opportunity alongside the risk, from fraud detection to optimisation. Opportunities of this scale tend to reward those who prepare early. Financial institutions that treat quantum readiness as a governance priority today, classifying data by confidentiality life, building crypto agility into new platforms and engaging regulators and vendors ahead of mandates, will be the ones best placed to make the most of the quantum era instead of scrambling to catch up with it.