Payment Security Compliance / Cryptographic Compliance
·
September 23, 2026

The Quantum Countdown | Taiwan's FSC Guidelines Land, PCI DSS Follows — How Should Businesses Get Ahead on PQC?

Taiwan's FSC has issued its PQC migration guidelines, and the PCI SSC is now tracking cryptographic inventory too. Understand the HNDL and TNFL quantum threats, how to build a CBOM, and the four preparatory steps for getting ahead of PQC migration.

Over the past few years, quantum computing has moved from science-fiction plot device to a standing item on government and boardroom agendas. Once quantum processing power crosses its critical threshold — the moment commonly called Q-Day — the classical public-key cryptography we rely on today, RSA and ECC among it, collapses at a stroke.

If you assume this is a problem for American and European technology giants alone, it is worth reassessing. Taiwan's Financial Supervisory Commission (FSC) formally issued its Reference Guidelines for Post-Quantum Cryptography Migration in the Financial Industry in June 2026, recommending that financial institutions begin planning their PQC migration early. In parallel, the PCI Security Standards Council (PCI SSC) has begun tracking the same trend (see "Aligning with international standards" below). The message of the guidelines is unambiguous: the wait-and-see period is over, and the action period has begun. This reaches well beyond financial services — any organisation handling sensitive personal data, payment flows, or inter-institutional connections should confront this shift in the cybersecurity paradigm sooner rather than later.

Moving from classical cryptography to post-quantum cryptography (PQC), however, is nothing like "updating a software package." Before adopting PQC in production, how should an organisation prepare against the official guidance?

Why Prepare Now? The Dual Threat of HNDL and TNFL

A common question: "Quantum computers are not in general use yet — do we really need to act today?"

The FSC guidelines identify two risks that are already live:

  1. Harvest Now, Decrypt Later (HNDL): Attackers are already intercepting and stockpiling high-value encrypted data — trade secrets, transaction records — and waiting for quantum computers to mature so they can decrypt it retroactively. If your data must stay confidential for five to ten years or longer, it is at serious risk today.
  2. Trust Now, Forge Later (TNFL): Attackers may use quantum computing to break digital signatures and forge legitimate certificates and identity credentials. Should that happen, it would dismantle the non-repudiation that financial transactions rest on.
The two attack paths of the post-quantum era: HNDL, harvest now and decrypt later; and TNFL, trust now and forge later

HNDL and TNFL Compared

  • HNDL (Harvest Now, Decrypt Later)
    When the attack lands: stolen now, decrypted later
    What it compromises: the confidentiality of long-lived sensitive data
    Where to respond first: migrate key exchange (for example ML-KEM) and channel encryption
  • TNFL (Trust Now, Forge Later)
    When the attack lands: trusted now, forged later
    What it compromises: the non-repudiation of digital signatures and certificates
    Where to respond first: migrate signature algorithms (for example ML-DSA) and the PKI trust chain

Following the FSC Guidelines: Four Preparatory Steps for PQC Migration

To meet the quantum era on its own terms, treat PQC migration as a strategic programme rather than a maintenance task. The official guidance recommends four preparatory steps.

PQC migration roadmap: build a CBOM, adopt crypto-agility, prioritise by risk, and coordinate across the ecosystem

1. Build Your Cryptography Bill of Materials (CBOM)

You cannot protect what you cannot see. The FSC recommends that organisations inventory their use of cryptography and build a Cryptography Bill of Materials (CBOM).

  • Scope of the inventory: Servers are not enough. It must also cover network equipment, hardware security modules (HSMs), third-party applications, and externally facing TLS endpoints.
  • Aligning with international standards: The PCI Security Standards Council (PCI SSC) has begun examining what quantum threats mean for the payment industry, urging organisations to inventory cryptographic systems early and build crypto-agility. PCI DSS v4.0.1 itself also added Requirement 12.3.3 (an inventory of cipher suites and protocols, reviewed at least annually) and Requirement 4.2.1.1 (an inventory of trusted keys and certificates used to protect PAN during transmission) — both closely aligned with the CBOM approach. Building a CBOM is therefore not only PQC preparation; it also helps satisfy international payment security requirements, and the resulting inventory is one of the items a QSA will review at assessment.
Four-phase CBOM discovery: network traffic analysis, host and endpoint scanning, source and binary discovery, and certificate and key lifecycle

2. Adopt Crypto-Agility and Clear Out Cryptographic Anti-Patterns

PQC standards are still evolving. The FSC notes that the priority right now is not simply swapping in a new algorithm, but raising the crypto-agility of the system itself.

  • What is crypto-agility? It is the assurance that your architecture can swap cryptographic algorithms and parameters quickly and flexibly, without rewriting the application wholesale.
  • Clear the cryptographic anti-patterns first: Find and remediate designs that hardcode cryptographic algorithms or keys into source code, and introduce automated certificate lifecycle management.

3. Set Migration Priority by Risk

Resources are finite, so migration has to proceed in phases. Assess each system's data sensitivity lifespan and the severity of business impact to identify what to address first. Systems involved in interbank clearing, highly sensitive authorisation data, or transaction evidence that must remain verifiable over the long term all belong in the high-priority tier of phase one.

4. Coordinate Across the Ecosystem and Manage Supply Chain Risk

The FSC is explicit that PQC migration touches a wide range of commercial products and outsourced services, and that no organisation can complete it alone. That is especially true in the tightly interconnected payment card industry.

  • Your PQC readiness work has to extend outward: engage your cloud service providers (CSPs), payment gateways, POS and ATM terminal manufacturers, and software vendors directly.
  • In future procurement contracts, make PQC readiness and crypto-agility mandatory acceptance criteria, so that one vendor falling behind cannot break the entire chain of transaction trust.

Preparing for PQC Is a Marathon — You Do Not Have to Run It Alone

PQC migration is complex and demanding. It tests not only IT execution but compliance posture and operational continuity across the business. The FSC guidelines have fired the starting gun.

Facing a sprawling estate of cryptographic assets and strict payment security requirements, and unsure where to start building your CBOM? Secure Vectors' security consulting team brings deep experience in compliance advisory and payment security protection — from CBOM inventory and crypto-agility assessment through to designing a PCI-aligned PQC migration roadmap. Talk to us and we will work out the migration sequence that fits where your organisation actually stands today.

Frequently Asked Questions

Q: Are the FSC guidelines mandatory? Are there penalties for not adopting PQC immediately?
A: The Reference Guidelines for Post-Quantum Cryptography Migration in the Financial Industry are advisory rather than binding regulation, and carry no stated penalties at present. They do, however, signal where the regulator's attention is directed, and preparing early reduces the pressure of future assessment and conversion work.

Q: Quantum computers are not in general use yet. Why start preparing now?
A: Because of the Harvest Now, Decrypt Later (HNDL) attack pattern: data can be stolen today and decrypted retroactively once quantum computers mature. If your data must remain confidential for more than five years, it is already at risk.

Q: Do the guidelines only concern financial services?
A: Financial institutions are the direct addressees, but the PCI SSC has also begun examining what quantum threats mean for the payment industry. Any organisation involved in payments, personal data, or inter-institutional connections should understand the direction of travel early.

Q: Where should we start when building a CBOM?
A: Begin with the cryptographic algorithms, keys, and certificates used by externally facing TLS endpoints, servers, and third-party applications; then widen the scope to internal systems. Treat it as a living inventory, not a one-off exercise.

Q: With limited resources, how do we set priorities?
A: Work from two angles — data sensitivity lifespan and business impact severity. Address systems involved in interbank clearing, highly sensitive personal data, or long-term verification first, and schedule the rest behind them.

References

  • FSC press release, "FSC Issues Reference Guidelines for Post-Quantum Cryptography Migration in the Financial Industry to Guide Financial Institutions in Strengthening Quantum Risk Readiness," 18 June 2026
  • PCI Security Standards Council blog, "The Quantum Leap: Preparing for Post-Quantum Cryptography," 9 September 2026
  • PCI Security Standards Council: PCI DSS v4.0.1 standard, available from the Document Library

Glossary

  • Q-Day: the point at which quantum computing power is sufficient to break today's public-key cryptography
  • PQC (Post-Quantum Cryptography): the next generation of cryptographic algorithms, designed to resist attack by quantum computers
  • HNDL (Harvest Now, Decrypt Later): stealing encrypted data today and decrypting it retroactively once quantum computers mature
  • TNFL (Trust Now, Forge Later): using quantum computers to forge digital signatures and certificates that are trusted today
  • CBOM (Cryptography Bill of Materials): an inventory recording every cryptographic algorithm, key, and certificate an organisation uses
  • Crypto-Agility: the ability to swap cryptographic algorithms and parameters quickly, without rewriting the application wholesale
  • PCI DSS: the Payment Card Industry Data Security Standard, set by the PCI SSC and applicable to organisations that handle cardholder data