up:: The Mandates MOC
G7 Cyber Expert Group Quantum Roadmap
The G7 Cyber Expert Group (CEG) is the body that advises G7 Finance Ministers and Central Bank Governors on cybersecurity matters affecting the security and resilience of the financial system. In January 2026 it published a statement titled “Advancing a Coordinated Roadmap for the Transition to Post-Quantum Cryptography in the Financial Sector,” which sets out six migration phases, three continuous lines of effort, and a target time range for the sector. It matters for the transition because it is the shared reference point national financial authorities are now building on: the U.S. Treasury’s Quantum-Readiness Task Force, announced August 24, 2026, cites it by name as the roadmap its own work builds upon.
The single most important thing to know about it is what it declines to be. In its own words: “This statement does not set guidance or regulatory expectations.”
The short version:
- The G7 CEG advises G7 Finance Ministers and Central Bank Governors, and its January 2026 statement is a roadmap for post-quantum migration across the financial sector.
- It is advisory by design, and says so twice in its own text.
- It sets out six migration phases, each split into what a financial entity does and what a public authority does, with three continuous lines of effort running alongside.
- It names 2035 as an overall target range and 2030 to 2032 for the most critical systems, and labels both non-authoritative.
- The U.S. Treasury’s Quantum-Readiness Task Force, announced August 24, 2026, cites it as the roadmap its own work builds on, which makes it the structure a supervisor is likely to organize around.
What does the G7 CEG roadmap actually say?
Five things carry the document.
- It is advisory by design. The purpose section states that it “does not set guidance or regulatory expectations” and is “intended to inform and provide context to support migration activities, outline key considerations, and suggest approaches.” A later section repeats it: “The roadmap and associated timelines are not intended to be prescriptive.”
- It builds on a September 2024 CEG statement on the benefits and risks of quantum computing, which noted that sufficiently advanced quantum computers will be capable of breaking widely used cryptographic protocols.
- It was written by a dedicated CEG task force of experts from financial authorities and industry across G7 jurisdictions, with consultation including NIST, FS-ISAC, the Canadian Forum on Digital Infrastructure Resilience, the UK NCSC, and the European Quantum-Safe Financial Forum.
- It is aimed past the individual firm. The stated audience includes financial authorities, financial entities, providers of critical services, cryptographic and security technology vendors, infrastructure operators, national cyber agencies, and standard-setting bodies.
- It treats third-party dependency as a first-order problem, on the grounds that financial institutions are “often highly dependent upon and interconnected with information technology products, vendors and other third-party providers,” with a footnote naming limited vendor-roadmap transparency as a barrier to planning.
Source: G7 Cyber Expert Group, “Advancing a Coordinated Roadmap for the Transition to Post-Quantum Cryptography in the Financial Sector,” January 2026, TLP: CLEAR, G7-CEG-Quantum-Roadmap.pdf.
What are the six phases?
The roadmap organizes migration activities into six phases, and gives each one a column for financial entities and a separate column for public authorities, because the two have different jobs at the same stage.
| Phase | For a financial entity | For a public authority |
|---|---|---|
| 1. Awareness and Preparation | Executive-level risk awareness, an initial post-quantum resilience strategy, defined roles, and mapped critical systems, functions, sensitive data and communication protocols | Executive-level awareness, and clear communication of risks and expectations to stakeholders |
| 2. Discovery and Inventory | A comprehensive inventory of cryptographic assets, communication protocols and relevant third-party dependencies, plus identified gaps in people, process, organization and technology | Assessment of system-wide post-quantum maturity across financial institutions and the public sector |
| 3. Risk Assessment and Planning | Tailored migration plans for critical and less critical functions, covering tools, standards and interoperability, with adapted internal governance | Communication that guides migration, and coordination toward consistent regulatory approaches |
| 4. Migration Execution | Quantum-resistant solutions deployed progressively, starting with priority functions, at a pace adapted to the threat landscape | Monitoring or oversight of progress, removing barriers, and capacity-building support |
| 5. Migration Testing | Migrated functions tested, and ecosystem-oriented quantum-resilience exercises performed | Quantum-resilience considerations folded into testing and crisis-coordination exercises |
| 6. Validation and Monitoring | Continuous validation, ongoing improvement, and incorporation of new cryptographic standards | Adaptive policy frameworks, and continued support for industry capability refinement |
The document is explicit that these are not a rigid sequence: “Many activities may occur in parallel or be revisited iteratively.” Three lines of effort run continuously alongside all six: governance and risk management, management of external dependencies, and stakeholder dialogue.
Source: G7 Cyber Expert Group, January 2026, the migration-activities table and the ongoing-activities list, G7-CEG-Quantum-Roadmap.pdf.
What dates does it give, and how binding are they?
Two figures, and both carry heavy qualifiers in the source.
2035 is the overall target range for the sector. The CEG describes it as “a challenging but prudent target time range,” arrived at by noting that “current guidance from several jurisdictions, standards-setting bodies, and multilateral bodies often points to 2035.” It is presented as consistent with expert opinion on when a CRQC might arrive, and with the harvest now, decrypt later problem, under which “data may be at risk even if it is intercepted well before the emergence of a CRQC.”
2030 to 2032 is the range for the most critical systems. The wording is a parenthetical example: “prioritizing systems determined to be the most critical (for example, by addressing them in 2030-32) will limit the downside risk of the risks being realized early.” Footnote 9 says the range “is reflective of the variety of envisaged approaches taken across G7 jurisdictions on the migration of critical systems,” which makes it a description of what member states are already doing rather than a new deadline.
Both are labeled non-authoritative. The source says the time range “is non-authoritative and will need to evolve with the risk landscape,” and that “target dates are subject to change based on changes in the risk environment.”
⚠️ This is the most misreported thing in the document. Coverage of the January 2026 release described the CEG as setting a 2035 deadline for financial services. The statement declines to set expectations at all, twice, in its own text. Quoting either figure without its qualifier converts a planning reference into a mandate that does not exist. The binding dates for U.S. entities live in Executive Order 14412 and OMB M-26-15 rather than in this statement.
Source: G7 Cyber Expert Group, January 2026, “Considerations for Potential Timelines for Transition to Quantum-Resistant Cryptography,” G7-CEG-Quantum-Roadmap.pdf.
How does the roadmap relate to the binding mandates?
It sits underneath them and reaches further sideways.
Executive Order 14412 and OMB M-26-15 bind U.S. federal agencies and, through the FAR rulemaking and the FedRAMP shared-responsibility model, the vendors selling to them. The G7 CEG roadmap binds nobody, and its audience is the financial sector across seven jurisdictions plus the vendors and infrastructure operators that sector depends on.
The connection is now concrete. Treasury’s Quantum-Readiness Task Force, launched under EO 14412 on August 24, 2026, states that it builds on the G7 CEG roadmap, and its three workstreams map onto the roadmap’s own emphases: sector alignment, third-party and vendor readiness, and digital assets. So a financial institution reading the CEG document is reading the structure its national supervisor is likely to organize around, some time before any of it becomes an expectation.
The practical read for an entity outside the G7 financial sector: phase 2, discovery and inventory, is where every one of these frameworks converges, and it is the phase that takes longest and can begin without waiting for a mandate. See Cryptographic Discovery and Cryptographic Bill of Materials (CBOM).
Questions people ask
Is the G7 CEG roadmap a regulation? No. It is a statement from an advisory group to G7 Finance Ministers and Central Bank Governors, and it says twice in its own text that it sets neither guidance nor regulatory expectations.
Does it apply outside banking? Its stated audience is the financial sector and the vendors, infrastructure operators and standard-setting bodies that support it. The six phases are generic enough to be useful anywhere, and the document makes no claim on other sectors.
Where did 2035 come from? From the CEG’s observation that other jurisdictions and standards bodies already converge on it, rather than from a fresh assessment. The document presents it as a communication aid for aligning planning across jurisdictions.
Which document actually obliges a U.S. entity to do something? For federal agencies and their contractors, Executive Order 14412 and OMB M-26-15. For the financial sector, whatever a supervisor issues, which as of September 2026 is a task force rather than a rule.
Where to go next
- Executive Order 14412 for the binding U.S. federal deadlines and the Treasury task force stood up under it
- OMB M-26-15 for the agency-level execution schedule
- Cryptographic Discovery for the phase 2 work that every framework converges on
- Crypto-Agility for the capability the roadmap names as the end state alongside migration itself
Last verified 2026-09-01 · Updated 2026-09-01 · Maintained by Addie LaMarr, LaMarr Labs.