Post-Quantum Readiness in Digital Assets: An Infrastructure Challenge for Institutions

Institutional digital asset infrastructure is entering a new phase of scrutiny. Security is no longer judged only by custody arrangements, governance frameworks, segregation of duties, or regulatory oversight. Attention is shifting to a broader consideration: can today’s infrastructure adapt as the cryptographic foundations of digital asset markets evolve? 

Post-quantum cryptography (PQC) is not an immediate operational concern. A cryptographically relevant quantum computer capable of breaking widely used public-key systems does not exist today. Yet the discussion has moved beyond theory. The U.S. National Institute of Standards and Technology (NIST) has finalized its first post-quantum standards, and European and Swiss initiatives are encouraging financial institutions to start preparing for an eventual transition rather than waiting for urgency to dictate the response.  

For banks, financial institutions and market infrastructure providers, the immediate concern is less about the timing of quantum computing and more about the long-term durability of today’s infrastructure decisions. Systems introduced now may need to operate through several generations of technological change, including a future shift in cryptographic standards. Post-quantum readiness is, above all, an exercise in infrastructure resilience. 

The Real Risk Is Migration, Not Quantum Capability 

Discussions about post-quantum cryptography often focus on “Q-Day”, the point at which sufficiently advanced quantum computers could compromise parts of today’s public-key cryptography. For many institutions, the relevant timeline begins well before that.

The “harvest now, decrypt later” threat model assumes that sensitive information can be collected today and held until future advances make decryption possible. Client records, strategic communications, authentication materials and other data with long confidentiality requirements may therefore remain exposed long before a practical quantum computer exists

The challenge extends beyond data protection. Replacing cryptography across an institution is rarely a contained technology exercise. Systems, vendors, operating models, and governance processes all become part of the effort, often across environments that have evolved independently over many years. 

Several questions follow naturally: 

  • Where is cryptography embedded across systems and business processes? 
  • Which datasets and functions require protection over long time horizons? 
  • Which suppliers, counterparties and external providers introduce dependencies? 
  • How should emerging standards be tested before they are introduced into production? 
  • Are governance structures capable of supporting a transition that may take years to complete? 

Every new application, integration, and dependency added today has the potential to increase the complexity of future migration. 

The timing of quantum computing remains uncertain. The need to understand dependencies and avoid creating new constraints is already here. Post-quantum readiness begins with ensuring that the infrastructure being built today can accommodate the changes that may follow tomorrow

Why Digital Assets Are Structurally Different 

Digital assets introduce an additional layer of complexity because cryptography is embedded in the functioning of the system itself. Transaction authorization, asset ownership and network trust all rely on public-key cryptography. Changes to cryptographic assumptions therefore affect not only data protection but also the mechanisms that underpin asset control and settlement. 

At the same time, the locus of control is different. Institutions can strengthen many parts of their infrastructure independently, including communications, key management, data protection, and supplier relationships. Changes to public blockchains, however, depend on collective decision-making across networks and cannot be implemented unilaterally by any single participant. Any transition at the protocol layer is therefore likely to progress unevenly across networks and over different time horizons. 

Post-quantum readiness in digital assets is not a binary state. It is a layered condition, shaped as much by external dependencies as by internal capabilities. 

Crypto Finance Perspective: Readiness Under Constraint 

At Crypto Finance, post-quantum readiness is not treated as a future technology milestone or a claim of immediate “quantum-safe” status. It is viewed as a long-term discipline in infrastructure design and operational resilience. 

While no institution can unilaterally determine the quantum readiness of public blockchains, many relevant layers are already within institutional control. These include internal systems, secure communications, partner connectivity, data protection, supplier oversight, and governance frameworks. Strengthening these layers already improves resilience, regardless of when public blockchain networks eventually transition. 

Our roadmap is structured around six priorities: 

  1. Monitor developments in quantum computing, standards, and regulations. 
  2. Identify critical systems, long-lived data, and cryptographic dependencies. 
  3. Assess long-term exposure, including “harvest now, decrypt later” scenarios. 
  4. Prepare migration pathways anchored in crypto-agility principles. 
  5. Review suppliers and third-party dependencies. 
  6. Maintain governance, staff awareness, and continuous policy development. 

This approach aligns with broader Swiss and European guidance, which increasingly emphasizes governance, inventory management, procurement discipline and continuous review as the foundations of post-quantum preparedness. 

Our perspective is shaped by the responsibilities that come with operating as a FINMA and BaFin-regulated institution within Deutsche Börse Group. Resilience, governance, and disciplined risk management shape how we approach long-term infrastructure challenges. 

We do not see readiness as a race to implement post-quantum technology everywhere at once. It is the ability to make changes when they become necessary, without introducing unnecessary operational risk. 

Conclusion: A Test of Cryptographic Agility 

The post-quantum debate is ultimately about more than quantum computing.  

Cryptographic standards will continue to evolve, regardless of when large-scale quantum capability arrives. Yet custody platforms, operating models, and integration frameworks are built to last far longer than the standards on which they currently rely.  

For institutions, resilience is therefore increasingly tied to cryptographic agility: the ability to evolve underlying security mechanisms without disrupting the infrastructure around them. Viewed through that lens, post-quantum readiness is less an end state than an early test of an institution’s capacity to adapt to cryptographic change over time.  

Do you want to unleash the full potential of digital assets?