India’s payment companies and network operators will need to begin “quantum-proofing” their systems before powerful quantum computers make today’s encryption vulnerable, Reserve Bank of India Deputy Governor Shirish Chandra Murmu has warned.
Speaking at the Global Fintech Fest 2026, Murmu said quantum security must become an ecosystem-wide capability involving banks, fintech companies, payment networks, technology vendors and regulators.
The warning is not that UPI, cards or internet banking are suddenly unsafe today.
The concern is about preparing financial infrastructure years in advance for a technology capable of challenging some of the mathematical protections currently securing digital payments, customer information and communication between financial institutions.
Proposal for Conducting Cyber Crisis Drill, Tabletop Exercise (TTEx) & CCMP Readiness Exercise
Why quantum computing worries banks
Modern banking relies heavily on encryption.
When money is transferred, a customer logs into an account or two financial systems communicate, cryptography helps establish that the parties are genuine and prevents outsiders from reading or altering sensitive information.
Today’s strongest encryption schemes depend on mathematical problems that ordinary computers would take an impractical amount of time to solve.
A sufficiently powerful quantum computer could change that calculation.
Quantum computers process information differently from conventional machines and could eventually solve certain mathematical problems much faster. That creates a risk that some widely used public-key encryption systems may no longer provide adequate protection.
This is why the problem has to be addressed before such machines become available.
The US National Institute of Standards and Technology says migration to post-quantum encryption needs to begin now because changing cryptography across complex systems can take 10 to 20 years.
What does “quantum-proofing” actually mean?
Quantum-proofing does not mean putting a special shield around a data centre.
It generally means replacing vulnerable cryptographic systems with post-quantum cryptography, or PQC — new encryption algorithms designed to remain secure even if attackers gain access to powerful quantum computers.
For a bank or payments company, that can be a huge exercise.
Encryption may be built into mobile applications, payment switches, ATMs, databases, cloud systems, authentication tools and communication links with other institutions.
Before anything can be replaced, organisations first need to know exactly where cryptography is being used.
That is why RBI’s Q-SAFE committee has specifically been asked to create what is known as a Cryptography Bill of Materials, or CBOM.
Think of it as an inventory of every important cryptographic lock inside the financial system.
Once those locks have been identified, banks can determine which ones may eventually need replacement and whether systems can switch algorithms without major disruption.
RBI has already started mapping the transition
RBI created the Q-SAFE expert committee on May 25.
The eight-member panel is convened by IIT Madras professor Anil Prabhakar and includes representatives from the Department of Science and Technology, SBI, NPCI, MeitY, the Data Security Council of India and RBI.
Its mandate goes beyond simply studying quantum computers.
The committee has been asked to assess India’s existing cryptographic infrastructure, examine international regulatory approaches, measure the maturity of quantum-safe products and recommend a roadmap for securing the country’s financial system.
Murmu’s latest remarks suggest payment infrastructure will be an important part of that transition.
India’s digital-payment architecture operates at enormous scale. A cryptographic change therefore cannot simply be pushed through like an ordinary software update.
Banks, UPI operators, payment gateways, card networks and other institutions will need compatible systems so that transactions can continue moving securely between them.
“Harvest now, decrypt later” creates a risk before quantum computers arrive
Another reason regulators are acting early is a strategy known as “harvest now, decrypt later”.
An attacker may steal encrypted information today even if it cannot currently decode it.
The data can then be stored for years. If sufficiently powerful quantum computers eventually become available, the attacker could attempt to decrypt the information later.
NIST says this is one of the reasons organisations holding long-lived sensitive information should not wait until quantum computers arrive before migrating to stronger algorithms.
Financial institutions hold exactly that kind of information.
Customer identity records, long-term transaction histories, confidential agreements and institutional communications can remain sensitive for many years.
Murmu therefore argued that quantum readiness should form part of broader cyber resilience rather than being treated as a distant research project.
India is also pursuing quantum technology itself.
The Union Government’s National Quantum Mission has an approved outlay of ₹6,003.65 crore from 2023-24 to 2030-31, covering quantum computing, communication, sensing and materials. One objective is developing secure quantum communication networks.
The challenge for the financial system is therefore two-sided.
Quantum technology could eventually improve modelling, optimisation and communications. At the same time, its computing power may force banks to rebuild some of the security foundations on which digital finance currently depends.
What this means for you: There is no need to stop using UPI, cards or mobile banking because of quantum computing. The issue is long-term preparedness: banks and payment companies need to upgrade encryption before quantum capability becomes powerful enough to threaten today’s security standards.
The420 Insight: The quantum threat is unusual because waiting for the first successful attack may already be too late. India’s payment ecosystem is so interconnected that replacing cryptography will require years of coordinated work — making preparation today part of protecting transactions a decade from now.
Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics