News

The Quantum Roadmap: Moving from Strategic Concept to Market Reality

Authored by Ian Stirling, CEO, Streets Consulting 

Quantum is Operational 

Quantum technology is moving from theoretical research into operational reality, and financial services cannot treat that as a distant science project. The concerns go beyond what a Cryptographically Relevant Quantum Computer, or CRQC, may be able to do in the future. It is also what adversaries may already be collecting today through “Harvest Now, Decrypt Later” attacks, where encrypted financial data is intercepted now in the hope it can be decrypted later.

Whilst no one can say with certainty when that machine will arrive, regional governments and international financial authorities are rapidly formalising transition timelines to post-quantum cryptography to protect the trust on which the global economy is built and depends.


Capital Investment in Quantum is Real

The financial sector’s transition is underpinned by a rapidly consolidating market of quantum technology providers. Global investment in quantum startups reached $12.6 billion in 2025, representing a massive 6.3x increase from 2024. Notably, the funding source has drastically shifted. Public funding accounted for 34% of startup capital in 2024 but dropped to just 3% in 2025, marking a definitive takeover by private capital markets. The commercial maturity is also reflected in revenue generation, with quantum computing companies earning an estimated $750 million in 2024. This figure hit >$1 billion in 2025 and is expected to grow to up to $4.4 billion by 2028.

Concentration Risk Affects Both Capital and Intellectual Property

In 2025, approximately 60% of the total investment, equating to around $7.6 billion in total, was captured by the top ten deals, suggesting that talent and infrastructure are consolidating around a few heavily capitalised leaders, which is perhaps understandable given the complexity of this technology and its applications. But the concentration of capital into a small number of providers indicates that financial institutions could be highly dependent on a restricted vendor supply chain for their cryptographic transitions. 

When we look at national investment figures, the global total reached an estimated $55 billion in 2025, and concentrations emerged. 

  • China leads significantly, with an expected $15.3 billion invested in quantum technologies 
  • Japan is in second with $9.2 billion
  • The US is third with $6 billion
  • The UK takes fourth spot with $5.6 billion
  • Germany is fifth at $5.2 billion. 

Intellectual property ownership is also heavily concentrated geographically. The United States and China filed over 50% of all global quantum technology patent applications in 2025, with China taking the lion’s share of quantum computing IP applications, and the US apparently majoring more on quantum sensing and quantum communication technologies.

Regulation Needs to Keep Pace

The global nature of interconnected financial market infrastructures necessitates borderless regulatory coordination – and the regulators are not procrastinating.

The World Economic Forum, in partnership with the UK Financial Conduct Authority, has identified four guiding principles for global regulatory approaches: reusing existing frameworks rather than creating entirely new legislation, establishing standardised non-negotiable baselines for threat mitigation, increasing transparency regarding threat intelligence, and avoiding cross-border fragmentation. The G7 Cyber Expert Group has published a six-phase roadmap tailored for financial systems. The phases progress through awareness, cryptographic inventory discovery, risk assessment, migration execution, resilience testing, and ongoing validation. The G7 specifies a target window of 2030 to 2032 to complete the transition of the most critical financial systems, acknowledging 2035 as the outer limit for full sector-wide migration.

Jurisdictions are applying distinct regulatory mechanisms to enforce cryptographic resilience.


The United States operates a market-driven approach supported by strict federal mandates.

  • National Security Memorandum 10 establishes a 2035 deadline for the complete migration of federal systems to post-quantum cryptography, serving as a template for private sector adoption.
  • The United States National Institute of Standards and Technology (NIST) finalised the foundational post-quantum encryption standards, FIPS 203, FIPS 204, and FIPS 205, in August 2024 and continued to explore additional standards in the time since
    .

The European Union prioritises digital sovereignty, utilising binding financial regulations to enforce compliance.

  • The Digital Operational Resilience Act (DORA) mandates that financial entities maintain cryptographic agility and update systems against emerging cyber threats.

  • Under the European Commission’s Coordinated Implementation Roadmap, member states must finalise national strategies by the end of 2026, complete the transition for high-risk infrastructure by 2030, and achieve broad adoption by 2035.

The United Kingdom relies on an advisory framework.

  • The National Cyber Security Centre recommends that organisations conduct cryptographic discovery by 2028, execute priority migrations by 2031, and complete the transition by 2035, avoiding rigid legal mandates for the private sector.

In the Asia-Pacific region:

  • Singapore functions as a dual innovator and implementer, with the Monetary Authority of Singapore (MAS) issuing formal advisories for financial institutions to record cryptographic assets and prioritise quantum-resistant migrations.

  • South Korea mandated post-quantum cryptography for government systems by 2027.

  • China drives a state-controlled model aimed at technological independence, deploying sovereign standards outside the track led by the United States.

Cross-Border Efforts are Encouraging

Translating these regulations into operational capability relies on centralised testing hubs and industry consortia. The Bank for International Settlements Innovation Hub operates Project Leap, partnering with the Bank of France and Deutsche Bundesbank to test hybrid cryptographic architectures for secure central bank payment messaging. MAS launched an industry sandbox in 2024 alongside major financial institutions to evaluate Quantum Key Distribution (QKD) for securing sensitive data transfers. 

Dedicated financial groups are also looking to consolidate industry standards. The Quantum Safe Financial Forum, established by Europol, provides prioritisation frameworks combining quantum risk and migration time scores. In the US, the Financial Services Information Sharing and Analysis Center (FS-ISAC) operates a dedicated post-quantum cryptography working group to align timeline expectations and accelerate vendor readiness across the supply chain.

Preparing for Quantum Requires Significant Investments 

Preparing for quantum will require investment across capital, infrastructure, skills and collaboration. For financial institutions, this is not simply a technology upgrade. It means understanding where cryptography sits across the organisation, building comprehensive inventories, testing hybrid models, and preparing systems that can support both classical and post-quantum algorithms without disrupting the networks they rely on.

The 2030 to 2035 timelines now being discussed by regulators may sound distant, but for institutions with complex legacy infrastructure, long data retention requirements and cross-border dependencies, they are closer than they look.

The encouraging sign is that governments, regulators and financial institutions are already moving. Investment is flowing, standards are forming and the work of making the global economy quantum-ready has begun.

For an industry built on trust, waiting for certainty is not much of a strategy.

The quantum clock is ticking.