Key takeaways

  • The address is a policy signal, not a new binding deadline.
  • Implementation evidence matters more than a technology label.
  • Customer protection and operational resilience remain part of the design.

RBI quantum-proof payments planning moved from a distant research topic to an explicit operational call on September 11. Reserve Bank of India Deputy Governor Shirish Chandra Murmu told payment-system providers and network operators to begin preparing for cryptographic migration, while stressing that a quantum attack on today’s systems is not an immediate threat. The distinction matters: this is a direction of travel and a risk-management signal, not a newly issued mandate or compliance deadline.

The speech is important because payment infrastructure changes slowly even when software changes quickly. A bank can update an app in weeks, but replacing keys, certificates, hardware security modules, messaging standards and vendor dependencies across a national payment chain can take years. Everyone else is reporting a warning about quantum computers; we are explaining why the first practical job is a cryptographic inventory and a migration plan that does not interrupt ordinary payments.

What the RBI quantum-proof payments call actually says

Murmu’s primary text says quantum computing could eventually challenge the cryptographic foundations of finance. He identified the “harvest now, decrypt later” problem: an attacker may collect encrypted information now and wait until future computing capacity makes it readable. That risk can exist well before a machine is able to break widely used public-key systems in real time.

The speech asks banks, payment operators, fintech companies, technology providers and standards bodies to move together. That is more than a diplomatic phrase. A payment passes through several institutions, and a single participant may depend on certificates or message signatures issued elsewhere. One firm cannot declare itself quantum-ready if a shared rail, vendor gateway or counterparty still relies on an incompatible protocol.

The Reserve Bank has also constituted an expert committee on a Quantum Secure and Adaptive Financial Ecosystem. The announcement does not publish the committee’s final standards, a transition calendar or a list of approved algorithms. Firms therefore should not present one vendor purchase as proof of compliance. The immediate evidence of readiness is disciplined discovery, testing and governance.

Why payments cannot wait for a cryptographic emergency

Payment infrastructure is designed for continuity. It must authenticate participants, preserve message integrity and settle value under heavy load. Cryptography is woven into each layer, from transport encryption and identity certificates to software signing and secure devices. Changing one primitive can affect message length, processing time, storage, key ceremonies and interoperability.

A rushed migration could create its own operational risk. New algorithms may require larger keys or signatures, older devices may not support them, and tightly timed transaction flows may behave differently under additional computation. Institutions need performance baselines and failure tests before a production change. They also need a rollback strategy that does not silently return the system to a vulnerable state.

Inventory is the unglamorous starting point. Teams need to know which algorithms protect which assets, who owns each dependency, how long the protected data must remain confidential and when each component is due for replacement. This includes code libraries embedded in vendor products, certificates in appliances, backups, archived records and links to third parties. An incomplete inventory turns a migration programme into guesswork.

The scale of UPI changes the risk calculation

Murmu connected future cryptographic risk with the current scale of Indian digital payments. He said UPI processed about 24,162 crore transactions worth roughly ₹314 lakh crore in FY2025-26 and represented around 85% of India’s digital-payment volume. Those figures describe a system that is part of daily commerce, not an optional technical service.

Scale changes the consequence of downtime. A certificate failure or incompatible update can affect merchants, households and businesses at once. Migration planning therefore has to include capacity, redundancy, incident communication and customer recovery. Security cannot be measured only by whether an attacker was stopped; it must also account for whether legitimate users retain access to their money.

The speech also places quantum readiness inside a wider cyber-resilience programme. That framing prevents a common mistake: creating a specialist quantum project disconnected from fraud operations, vendor oversight and business continuity. Cryptographic agility should strengthen the institution’s ordinary ability to replace a weak control, respond to a compromised library and verify that critical services remain available.

What boards and technology leaders should ask now

Boards do not need to select a mathematical standard, but they do need to know whether management can locate critical cryptography and explain the migration exposure. A useful dashboard would show inventory coverage, data-retention horizons, vendor readiness, test environments, exception ownership and the share of critical connections capable of switching algorithms without redesign.

Procurement is a major control point. New contracts should require vendors to disclose cryptographic dependencies, support approved upgrades, provide a software bill of materials where appropriate and cooperate in interoperability testing. Long contracts without upgrade rights can lock an institution into technology that becomes expensive to replace precisely when the industry needs coordinated movement.

Institutions should separate experimentation from production assurance. A laboratory demonstration can establish that two systems exchange a post-quantum-signed message. It does not prove that the same design meets latency, throughput, recovery, audit and key-management requirements at national scale. Test evidence should travel through architecture review, risk acceptance and independent validation.

Accountability remains human in an automated system

The address paired quantum preparation with warnings about increasingly autonomous AI in finance. Murmu argued that responsibility cannot be assigned to an algorithm when a system materially influences a customer. That principle also applies to infrastructure migration: executives cannot outsource accountability to a vendor label such as quantum-safe.

Teams need named owners for decisions, exceptions and customer impact. If an authentication change wrongly blocks a legitimate transaction, a person must be able to investigate and restore service. If a vendor cannot explain how a control works or how it will be updated, the institution needs a documented risk decision rather than an assumption that technical complexity removes responsibility.

This links with the broader India fintech policy debate over AI and credit and with the operational controls described in the Know-Your-Agent framework. In each case, more capable technology increases the need for traceable authority rather than reducing it.

A practical migration sequence

A credible programme can begin with four streams. First, classify data and transactions by sensitivity and required protection lifetime. Second, map every cryptographic dependency and external connection. Third, build a test environment for hybrid and post-quantum approaches. Fourth, define governance for standards changes, vendor exceptions, rollback and customer communication.

Hybrid designs may allow existing and post-quantum methods to operate together during transition, but they are not automatically safer. They add complexity, and the combined implementation must be tested as a system. Institutions should measure latency, message size, device support, logging and recovery under realistic peak conditions rather than relying on theoretical comparisons.

Coordination is essential because payment rails are networks. Standards bodies and operators need common profiles so participants do not choose mutually incompatible configurations. Regulators can help by clarifying expectations and sequencing, while institutions contribute evidence from pilots. A staged approach should make room for smaller banks and fintech providers that lack the engineering capacity of the largest firms.

What the speech does not establish

The address does not say that current encryption has been broken, that a production quantum computer can defeat Indian payment systems today or that one product has been approved by RBI. It does not prescribe a vendor, mandate an algorithm or attach a deadline. Any sales claim that presents the speech as a certificate of immediate compliance goes beyond the published evidence.

It also does not eliminate ordinary cyber priorities. Identity controls, patching, network segmentation, monitoring and incident response remain necessary. Post-quantum cryptography cannot stop social engineering, account takeover or a poorly configured access system. The strongest programme treats quantum migration as one part of layered resilience.

Audit evidence should survive leadership and vendor changes. Architecture decisions, test results, key-management procedures and accepted exceptions need durable records that another team can understand. Regulators and operators will also need a common vocabulary for readiness, because a percentage without a defined inventory denominator can create false confidence. Transparent measures make dependencies visible early, when institutions still have time to coordinate remediation.

The central message is operationally modest and strategically important: start before urgency removes choice. RBI quantum-proof payments planning will become credible when institutions can show what they protect, how they will migrate, which partners are ready and how customers remain served during the change.

Facts at a glance

Event RBI deputy governor keynote at Global FinTech Fest
Date 11 September 2026
Core call Begin moving payment systems toward quantum-proof security
Threat timing Not immediate; migration may take years
Named risk Harvest now, decrypt later
Institutional step Expert committee on a Quantum Secure and Adaptive Financial Ecosystem
UPI scale cited About 24,162 crore transactions worth about ₹314 lakh crore in FY2025-26

RBI quantum-proof payments implementation path 1A three-stage path from policy signal through controlled testing to evidence-based production decisions.Policy signalscope the problemControlled pilottest failure modesEvidencedecide and governRBI quantum-proof payments implementation path 2A three-stage path from policy signal through controlled testing to evidence-based production decisions.Policy signalscope the problemControlled pilottest failure modesEvidencedecide and governRBI quantum-proof payments implementation path 3A three-stage path from policy signal through controlled testing to evidence-based production decisions.Policy signalscope the problemControlled pilottest failure modesEvidencedecide and govern

Frequently asked questions

Did RBI set a quantum-security deadline?

No. The address urged preparation but did not announce a binding deadline or a completed standard.

What does quantum-proofing payments mean?

It means inventorying cryptography, testing post-quantum alternatives and planning a controlled migration across payment infrastructure.

Why begin if the threat is not immediate?

Payment systems have long replacement cycles, and encrypted data stolen today might be decrypted by more capable future computers.

This report is informational and is not legal, financial or investment advice.

Get the day’s top stories in your inbox

One concise email. No spam, unsubscribe anytime.