The G7 Cyber Expert Group (CEG) advises G7 Finance Ministers and Central Bank Governors on cybersecurity matters of importance for the security and resilience of the financial system.
Due to the cryptographic risks that quantum computers may introduce to financial systems, the CEG has published a roadmap to encourage a coordinated approach for financial entities’ migration to quantum-resistant cryptography and to ‘transition to cryptographic agility’.
The statement does not set guidance or regulatory expectations, but is intended to inform and provide context to the threat and preparatory actions in relation to it.
The statement describes the following ‘potential activities for financial entities’:
Awareness & Preparation
- Executive-level risk awareness and initial post-quantum resilience strategy, and defined key roles.
- Mapped critical systems, functions, sensitive data, and communication protocols.
Discovery & Inventory
- Comprehensive inventory of cryptographic assets, communication protocols, and relevant third-party dependencies.
- Identified gaps in people, processes, organization, and technology capabilities.
Risk Assessment & Planning
- Tailored migration plans for critical and less critical functions, including tools, standards, and interoperability.
- Adapted internal processes for capability building, governance, and risk management.
Migration Execution
- Quantum-resistant solutions progressively deployed, starting with priority functions.
- Transition pace adapted to the evolving quantum threat landscape.
Migration Testing
- Migrated functions are tested.
- Ecosystem-oriented quantum-resilience exercises performed.
Validation & Monitoring
- Continuous validation and ongoing improvement.
- Incorporation of new cryptographic standards.
In terms of timescales, the statement sees Awareness & Preparation as being completed by the end of 2027, Discovery & Inventory by the end of 2028, and Risk Assessment & Planning by the end of 2029, with Migration Execution complete by the end of 2034.
Comments received
In response to the publication of the CEG statement, Simon Pamplin, CTO of Certes, told Resilience Forward:
“The G7 guidance is a timely and welcome move, particularly for the financial sector, which holds vast amounts of long-life, high-value data. One of the biggest challenges businesses face is the growing gap between the pace of quantum cryptography research and the speed at which organizations actually update their production systems.
“Attackers do not need a fully functioning quantum computer today to create risk. Many are already collecting encrypted data, storing it, and waiting for the point at which it can be decrypted. That turns financial records, personal information, and intellectual property into a liability with a countdown attached.
“Too many organizations still assume the encryption they rely on today will protect them indefinitely. It will not. Moving to post-quantum cryptography is complex and often slower than expected, particularly once you factor in legacy systems, third-party integrations, and long-established data flows that depend on algorithms unlikely to stand up in the future.
“That is why preparation needs to start now, not later. Organizations should understand where sensitive data actually travels, prioritise protection for long-life data, and isolate critical data streams so a single weakness does not expose everything. This is not something you bolt on at the last minute. It is a phased transition.
“The idea that quantum is five or ten years away misses the point. The data that will be valuable then is being harvested today. Without quantum-resilient protections in place now, that data becomes someone else’s financial asset. This guidance is an important step in helping organizations act before the damage is done.”






