💻 Quantum
Only 3% of Banks Are Quantum-Ready. $26 Trillion Flows Through the Other 97% Every Year.
A new scan of the world's top 1 million websites found that just 4 out of 145 banks have deployed post-quantum cryptography. Google says a quantum computer could crack their encryption by 2029. We calculated the dollar value at risk and the year banking migration would finish at its current pace: 2058.
Four out of 145. When F5 Labs scanned the world's top 1 million websites earlier this year, probing each site's ability to complete a hybrid post-quantum cryptographic handshake using the NIST-standardized ML-KEM768 algorithm, only four banks out of 145 in their dataset managed to negotiate the connection, placing the banking sector's 2.9% adoption rate dead last among every industry they measured, behind healthcare at 8.5%, government at 7.1%, and even the broader financial services sector at 7.7%.
Meanwhile, $26.89 trillion will flow through global digital payment systems in 2026, according to Statista and CoinLaw, an 11.73% increase from last year. Almost all of it moves through TLS-encrypted connections between browsers, APIs, and banking servers that a sufficiently powerful quantum computer could crack retroactively, reading transaction data, account credentials, and identity documents that were supposed to be confidential forever. Nobody has calculated what this asymmetry means in dollar terms, or how long it would take banks to close the gap at their current migration speed.
We did, and the numbers are bleak.
The Scan: 843,584 Handshakes, One Clear Loser
F5 Labs partnered with Efflux to probe the TLS configurations of every site in the Majestic Top 1 Million, a dataset that spans the world's most-trafficked domains from Google and Facebook at the top to niche regional portals at the bottom. Of 843,584 sites that completed a successful TLS handshake, 72,613 completed a hybrid post-quantum key exchange using ML-KEM768, a figure of 8.6% overall that masks a brutal distribution. At the top, adoption is healthy: 50% of the top 10 sites, 43.8% of the top 100, and 23.1% of the top 1,000 support PQC, with Google, Facebook, Instagram, Reddit, CNN, and the BBC all passing the handshake while Twitter, LinkedIn, Microsoft, Apple, and Baidu did not.
Below rank 1,000, the floor drops out. By the time you reach the full million, the average sits at 8.6%, dragged down by an enormous long tail of sites running on unpatched infrastructure that predates TLS 1.3 entirely, infrastructure where hybrid PQC key exchange is not merely unenabled but physically impossible because the underlying protocol does not support it. A quarter of all scanned sites do not support TLS 1.3 at all.
Industry breakdown tells the rest of the story:
| Sector | PQC Adoption |
|---|---|
| Technology & SaaS | ~15% |
| Media & Entertainment | ~12% |
| Healthcare | 8.5% |
| Financials (overall) | 7.7% |
| Government | 7.1% |
| Banking | 2.9% |
The sectors that handle the most sensitive data, the data with the longest cover time, the data most valuable to nation-state adversaries harvesting it today for future decryption, occupy the bottom of the adoption table. Designing a worse allocation of defensive resources would take deliberate effort.
The Calculation: $26 Trillion Through a Cracking Door
Global digital payments in 2026 total $26.89 trillion, growing at a 7.63% compound annual rate toward $36.09 trillion by 2030, with mobile point-of-sale transactions alone accounting for $18.95 trillion, cross-border payment flows adding another $190 trillion through correspondent banking networks, and real-time payment transactions hitting 428 billion individual transactions this year. The ecosystem is enormous, fast, and overwhelmingly digital.
If 97.1% of banks have not deployed post-quantum key exchange on their customer-facing connections, then roughly $26.1 trillion in annual digital payment value flows through TLS sessions that a sufficiently powerful quantum computer could decrypt after the fact. That is the "harvest now, decrypt later" threat model that the NSA, NIST, and Google all consider credible: adversaries stockpiling encrypted traffic today to read the moment Q-Day arrives.
When is that? Google says 2029, based on Google Quantum AI's May 2025 paper demonstrated that a 2,048-bit RSA key could be broken in under a week by a quantum computer with just one million noisy qubits, a 20-fold reduction from the 2019 estimate of 20 million qubits. In April 2026, VP of security engineering Heather Adkins published the company's target: full PQC migration by 2029, ahead of the NSA's 2031 and the U.S. government's broader 2035 deadline.
Here is the arithmetic that should concern every bank CTO: banking PQC adoption went from effectively 0% to 2.9% in the first year of standardized availability (NIST finalized ML-KEM in August 2024), which means reaching 100% at a linear pace requires approximately 33 additional years, placing full banking PQC migration around 2058.
Google's Q-Day estimate is 2029, and the gap between that date and full banking migration at current pace is 29 years.
Three structural factors explain why banks are last, and none of them are flattering.
First, regulatory compliance cycles create inertia that is almost impossible to overcome quickly. Banks operate under PCI DSS, SOC 2, and national banking regulations that specify approved cryptographic configurations, and adding a new cipher suite, even one that NIST has standardized and Google has deployed across its entire infrastructure, triggers change management processes, security reviews, third-party audits, and approval cycles that routinely consume 12 to 18 months before a single configuration line changes on a production server, which is why healthcare and government, facing similar regulatory constraints, show similarly abysmal adoption rates.
Second, infrastructure age keeps the door locked. Many banks run on middleware stacks, hardware security modules, and load balancers from the 2010s that physically cannot negotiate PQC ciphers without firmware upgrades or outright hardware replacement, and F5's data confirmed the pattern: PQC-enabled sites offered significantly fewer total cipher suites than non-PQC sites, suggesting that organizations deploying PQC are the same ones actively pruning legacy configurations, while banks accumulate cipher suites and rarely retire them.
Third, executive attention is elsewhere. Only 5% of CISOs rank post-quantum cryptography as a "high business priority," according to the ISACA Pulse of Quantum Computing poll, because quantum risk competes for budget and board time with ransomware, zero-day exploits, and AI-generated phishing, threats that are causing losses right now, today, this quarter. A threat that materializes in 2029 or 2035 simply does not command urgency at the C-suite level, even though the "harvest now, decrypt later" exploitation window has already opened.
The Geographic Split
A separate dataset reveals which countries' banks are prepared and which are not, and the answer is uncomfortable for American consumers. The PQ Readiness Index, an independent measurement project tracking 350 hosts across eight sectors and 28 region tags, found that zero out of 11 large U.S. retail bank endpoints negotiated a post-quantum key exchange on probe day.
Zero. Not one.
Several large Asian and European banks passed: HSBC in the UK and Hong Kong, DBS, OCBC, Standard Chartered, ANZ, Westpac, Hang Seng, Santander, and BBVA all completed PQ handshakes, a pattern consistent with F5's TLD analysis showing Australia at 17.38% PQC adoption and New Zealand at 17.06%, while Germany trails at 2.09% and France at 3.74%.
The most revealing finding cuts deeper than geography. The same brand can have different PQC status depending on which regional infrastructure stack serves the request. HSBC's UK site (hsbc.co.uk) negotiated a quantum-resistant connection; HSBC's global site (hsbc.com) did not. PQC enablement happens at the edge, per domain, per CDN configuration, not at the corporate-policy level, which means a bank can announce a comprehensive PQC strategy, issue a press release, brief its board, and still have half its customer-facing endpoints running classical-only cryptography that a future quantum computer could unseal like an envelope.
The Broader Internet Is Doing Better, But Not Well
Beyond banking, the picture is mixed but better. A June 2026 measurement by Forescout Research found that SSH servers supporting PQC grew from 11.5 million to 19 million in 12 months, a 72% increase that still represents only 11.8% of all internet-facing SSH servers, while TLS 1.3 now runs on 30% of servers globally, up from 19% a year ago, leaving 70% without the protocol foundation PQC requires.
An arXiv paper analyzing 32,011 domains found that 49.3% supported hybrid PQ key exchange mechanisms while 50.7% remained fully classical. But here is the number that should stop the conversation cold: 0% of analyzed domains had adopted hybrid post-quantum certificates for authentication, meaning even the domains doing PQ key exchange still rely on classical digital signatures that a quantum computer could forge, creating a world where your encrypted channel is quantum-safe but the certificate proving you are talking to your actual bank is not.
The internet is halfway through one transition, has not started the other, and needs to finish both before 2029.
Methodology and Limitations
Three caveats are essential.
First, public-facing website scans do not measure internal banking infrastructure. Interbank settlement systems like SWIFT, Fedwire, and CHIPS run on private networks with their own cryptographic configurations, and those systems may be considerably further along in PQC migration than the customer-facing web endpoints F5 scanned. Our $26.1 trillion exposure figure applies specifically to consumer-facing digital payment flows, not the full interbank settlement layer, and a bank's internal quantum readiness could be significantly better than its public website suggests.
Second, linear extrapolation is deliberately naive. Adoption curves are typically S-shaped: slow start, rapid middle, slow finish, and if a regulatory mandate or a major quantum-enabled breach accelerates banking PQC adoption, the 2058 projection collapses, and the 33-year number is not a forecast but a mirror held up to the current pace, reflecting back how slowly banks are moving relative to the threat they acknowledge exists.
Third, the "harvest now, decrypt later" threat has different severity for different data types, and we have not estimated the mix. A credit card number that expires in three years has a much shorter cover time than a Social Security number or biometric template, which never expire. The quantum threat to banking is real, but its impact is asymmetric across data categories, and a more granular analysis would weight exposure by data permanence rather than by raw transaction volume.
The Strongest Case for Calm
Q-Day has been "five years away" for at least fifteen years, and skeptics have a point. IBM's largest quantum processor, the 1,121-qubit Condor, remains three orders of magnitude below the one million noisy qubits Google's paper says are required, and IBM's own roadmap does not target a 100,000-qubit system until 2033, with Quantinuum aiming for fault tolerance by 2029 but not at the scale needed for RSA factoring. No organization on Earth can sustain a million qubits with the error rates and coherence times required for week-long continuous computation. Not today.
Moreover, CDNs are doing much of the PQC heavy lifting automatically. Cloudflare enables hybrid PQC by default for every proxied domain, and a bank that puts its website behind Cloudflare gets quantum-resistant key exchange without writing a single line of code, without filing a single change request, without briefing a single board member. As CDN-level PQC spreads, the banking sector's numbers will rise even without deliberate action by bank IT teams, and the rock-bottom 2.9% figure partly reflects banks running their own infrastructure rather than outsourcing to providers who made the switch six months ago.
These are legitimate points that may buy time, but they do not buy safety.
What You Can Do
If you run a bank's IT infrastructure: Check whether your TLS termination points (load balancers, reverse proxies, CDNs) support X25519+ML-KEM768, because many already do: Cloudflare, Nginx Plus R33, and OpenSSL 3.2+ all support it, and enabling the cipher suite is often a configuration change, not a hardware upgrade. If your hardware security modules cannot handle PQC key encapsulation, start the procurement cycle now. HSM replacement takes 12 to 24 months in regulated environments.
If you are a bank regulator: PCI DSS 4.0, finalized in March 2024, does not mention post-quantum cryptography. It should. The next revision should require TLS 1.3 as a minimum and define a timeline for mandatory PQC key exchange on all payment-processing endpoints. Without regulatory pressure, the 5% CISO prioritization figure will not move.
If you are a consumer: Your bank's quantum readiness is not something you can control, but your browser's is. Chrome and Firefox already attempt PQC key exchange by default. If you use Safari, you are not PQC-protected because Apple has not yet shipped PQC support in WebKit. Use a PQC-capable browser for financial transactions until Apple catches up. Beyond that, assume that data you transmit today could be read in 2030. Anything you would not want a nation-state to see in four years should not be sent over a connection you cannot verify is quantum-resistant.
The Bottom Line
The mathematics of post-quantum cryptography are settled: NIST has published the standards, browsers ship the algorithms, CDNs enable them by default, and the engineering work is done. What remains is deployment, and deployment is a human problem: change management, regulatory inertia, and the universal tendency to deprioritize threats that have not yet materialized. Banks are the institutions that hold the most sensitive financial data on the planet, and they are deploying quantum-resistant encryption at a rate that would leave them exposed for three decades past the date Google says the threat becomes real. The gap between knowing what to do and actually doing it has rarely been quantified this precisely. It is 29 years wide, $26 trillion deep, and closing at a pace that suggests the people responsible for closing it do not believe it is real.