The Treasury announced a task force this week, and I think it will not move fast enough. Not because the people on it are wrong about the threat, but because a task force is the wrong instrument for a problem with a clock attached.

On August 24, Treasury unveiled the Quantum-Readiness Task Force, a public-private group meant to coordinate the financial sector’s shift to quantum-safe cryptography. “America must lead in securing the technologies that power our economy,” said Treasury Secretary Scott Bessent. “This Task Force will help ensure our financial system remains strong, secure, and competitive as new technologies reshape the global landscape.” Treasury Assistant Secretary for Financial Institutions Luke Pettit framed the stakes plainly: “Quantum computing holds significant promise, but it also presents a serious long-term challenge to the cryptographic tools that underpin the U.S. financial system.” Deborah Guild, who chairs the Financial Services Sector Coordinating Council, put it even more bluntly: “Post-quantum cryptography readiness is no longer a future-proofing exercise, it is a present-day risk control.”

I agree with every word of that. What I do not see anywhere in the release is a date.

Advertisement

Simplified Management — Advertisement

The counter-argument, stated fairly

The case for a task force over a mandate is real and I want to give it its due. Quantum computers capable of breaking today’s RSA and elliptic-curve encryption do not exist yet, by most credible estimates, for years. A rigid compliance deadline imposed today risks locking banks into a specific post-quantum algorithm before the field has settled on the best one, or forcing costly migrations of systems that will need to be re-migrated again once standards mature. The three workstreams Treasury named, sector alignment, third-party vendor readiness, and digital-asset risk, are genuinely the right categories of work: mapping cryptographic dependencies across a bank’s stack is a multi-year discovery exercise before it is ever a migration exercise, and rushing that mapping produces bad inventories, not real readiness. A risk-based, coordinated approach is defensible research policy, of the same kind that has generally served regulators well when rulemaking on genuinely new financial technology moves gradually.

But research policy and infrastructure migration are not the same job, and finance is being asked to do the second one.

Why coordination without a deadline will not hold

Financial institutions do not reprioritize multi-year technology migrations against a voluntary framework at the same rate they reprioritize against a hard compliance date. That is not cynicism about banks, it is how every other cryptographic transition in the sector has actually gone. TLS 1.0 deprecation, SHA-1 retirement, PCI DSS encryption updates: each of those moved from “recommended” to “actually done” only once a regulator, a card network, or an auditor attached a date and a consequence to missing it, the same lesson enforcement patterns elsewhere keep repeating: voluntary good intentions rarely beat a deadline. A coordinating body with three workstreams and no stated timeline gives every institution’s technology budget a reason to fund the next fiscal year’s higher-priority project instead, and to keep doing that every year the task force remains a task force.

Newsletter

Get the week's best tech coverage.

Free. Read by thousands of HR, tech, and business leaders.

The counterpoint I raised above, that premature deadlines risk locking in the wrong standard, does not actually require abandoning deadlines. NIST finalized its first set of post-quantum cryptographic standards years ago specifically so that a target would exist. The gap Treasury’s task force leaves open is not “which algorithm,” it is “by when.” A task force can do the mapping work Guild described, critical-system inventories, vendor-dependency charts, interoperability testing, on a defined clock just as well as an open-ended one. What a defined clock adds is the thing voluntary coordination structurally cannot supply: a reason for a bank’s chief risk officer to win the budget argument this year instead of next year.

None of this means the task force is a bad idea. Bringing government, financial-market infrastructures, and vendors into the same room to map dependencies is necessary work, and Treasury deserves credit for starting it before quantum risk becomes an emergency rather than a planning problem. But necessary is not sufficient. A structure built entirely on coordination and risk-based judgment, with no published date by which critical systems must be migrated, will produce excellent working papers and slow-walked implementation, because that is what every comparable voluntary framework in financial cryptography has produced before. The task force should keep its three workstreams. It should also come back within a year with a date attached to at least the first one.

Source: U.S. Department of the Treasury