Treasury Launches Financial Sector's Quantum-Readiness Task Force
The first government task force to treat harvest-now-decrypt-later as present-day risk control: financial-sector technology vendors now face near-term cryptographic inventory demands from every downstream customer.
TL;DR
The Treasury Department established a Quantum-Readiness Task Force to coordinate the financial sector's migration to post-quantum cryptography, operationalizing President Trump's June executive order and the G7 Cyber Expert Group's January roadmap. The group will assess technology vendor readiness and identify critical dependencies across three work streams: sector-wide PQC coordination, third-party assessment, and digital-asset risk. For primes, subcontractors, and managed service providers in the financial supply chain, cryptographic inventory and migration planning are now near-term expectations: the task force treats harvest-now-decrypt-later as present-day risk control, not a 2035 planning exercise.

The Treasury Department's new Quantum-Readiness Task Force marks the first formal government body charged with operationalizing post-quantum cryptography migration for an entire critical infrastructure sector. The task force brings together government officials, financial institutions, market infrastructure operators, and technology providers under a single coordinating umbrella, and the framing couldn't be clearer. Deborah Guild, chair of the Financial Services Sector Coordinating Council, said it plainly: "Post-quantum cryptography readiness is no longer a future-proofing exercise, it is a present-day risk control." That's not marketing. It's the first time a formal Treasury body has classified harvest-now-decrypt-later as a current operational risk, not a speculative future threat.
Three work streams, one accelerating clock
The task force's work divides into three streams: coordinating the financial sector's broader PQC transition, assessing the readiness of technology vendors and other third parties, and examining risks involving digital assets and emerging technologies. Treasury also charged the group with identifying critical dependencies, improving interoperability, and promoting cryptographic agility, the ability to swap encryption methods as standards and threats evolve. The effort builds on the G7 Cyber Expert Group's January roadmap, which called on financial institutions to inventory cryptographic usage, assess sensitive systems, develop migration plans, and test quantum-resistant technology. That roadmap points to 2035 as a nonbinding transition target, but the task force's existence suggests the operational timeline is considerably shorter.
Vendors inherit the migration mandate
For vendors and contractors, the task force sits inside a larger regulatory stack that's been building all summer. President Trump's June 22 executive order directed CISA to publish a list of PQC-supporting product categories, which the agency delivered in January 2026. OMB followed on June 25 with a memo requiring federal agencies to inventory cryptographic systems, submit migration plans within 120 days, and ensure vendor-supplied software meets PQC requirements by referencing CISA's product categories list. The Treasury task force extends that logic into the financial sector specifically, and, critically, into third-party technology provider assessment. For primes, subcontractors, and managed service providers touching financial-sector systems, the message is the same: start your cryptographic inventory now, because your downstream customers are about to start asking for it as a condition of doing business.
What Treasury didn't say
What's missing from Monday's announcement is as significant as what's in it. Treasury hasn't specified which cryptographic systems get Phase 1 priority, what enforcement mechanisms or penalties apply to non-compliant vendors, or how the task force will assess third-party technology providers operating across the financial ecosystem. The 2035 G7 target remains nonbinding, and no agency has yet published binding compliance deadlines for private-sector financial entities. But the direction of travel is unmistakable: the federal government is building the scaffolding for PQC compliance across critical infrastructure sectors, and Treasury just claimed the financial sector as its first formal pilot. The harvest-now-decrypt-later threat isn't waiting for 2035, and neither is the regulatory apparatus.
Published ·Deep Fathom