Skip to main content
Should You Inventory First or Migrate Fast?Cryptography Fundamentals
4 min readFor Fintech Risk and Compliance Teams

Should You Inventory First or Migrate Fast?

The U.S. Department of the Treasury's new Quantum-Readiness Task Force puts financial institutions in a challenging position. You're being asked to prepare for a cryptographic migration with no regulatory deadline, no enforcement mechanism, and no clear finish line. The question dividing security teams: do you spend months cataloging every cryptographic dependency before touching anything, or do you start migrating critical systems now while the inventory work continues in parallel?

The Case for Inventory-First

The cryptographic inventory argument rests on a simple principle: you can't protect what you can't see. If you don't know where encryption lives in your environment, you'll miss dependencies that break when you swap algorithms.

This view treats inventory as risk management. Your payment processing environment doesn't just use cryptography you wrote. It runs inside vendor platforms, third-party APIs, acquired technology stacks, and infrastructure that may predate the engineers who maintain it. The Financial Services Information Sharing and Analysis Center warned in a September 2025 white paper that firms underestimate the scale of this work, treating quantum risk as distant rather than operational.

Inventory-first advocates point to interoperability requirements. If you migrate your settlement system to post-quantum algorithms before your counterparties do, transactions fail. You need a map of dependencies before you can sequence the work. That means documenting every cryptographic operation: TLS handshakes, certificate chains, API authentication, database encryption, key management systems, and hardware security modules.

The practical argument: most institutions don't control their own migration timeline anyway. Your payment processor, core banking platform, cloud provider, and custodian will migrate on their schedules. If you don't know what you depend on, you can't pressure vendors or plan workarounds when they're late.

The Case for Parallel Migration

The migrate-now argument starts from a different risk assessment: adversaries are already collecting encrypted traffic to decrypt later. Waiting 18 months to finish an inventory means 18 more months of harvest-now-decrypt-later exposure. You don't need a complete map to start protecting your highest-value targets.

This view treats inventory as an ongoing process, not a prerequisite. You identify critical systems, migrate them to quantum-safe algorithms, and continue discovering dependencies as you go. The alternative is what some call "crypto-procrastination," where the perfect inventory becomes the enemy of actual protection.

Parallel-migration advocates point to cryptographic agility as the real goal. If your systems can swap algorithms without architectural changes, inventory becomes less critical. You're not locked into a single migration path. You can move payment authorization this quarter, cardholder data storage next quarter, and keep refining your dependency map throughout.

The practical argument: you'll never finish the inventory. Legacy systems don't document their cryptographic calls. Acquired companies ran their own technology stacks with their own undocumented dependencies. Cloud environments change faster than you can catalog them. If you wait for completeness, you'll still be inventorying when the first quantum computer breaks RSA-2048.

Where Practitioners Actually Land

Financial institutions with dedicated quantum teams have mostly chosen a hybrid path: inventory the core, migrate the critical, and accept that discovery continues.

The largest banks started cryptographic inventories years ago and still haven't finished. They're migrating payment systems and settlement infrastructure in parallel because those systems handle the data adversaries most want to decrypt retroactively. Smaller institutions face a different constraint. Without internal quantum teams, they're waiting on vendors to ship post-quantum-ready versions of core platforms.

This creates a dependency problem the Treasury task force will need to address. As Utkarsh Ahuja, founder and managing partner at Moon Pursuit Capital, told ISMG: "An institution might do everything right internally and still depend on payment processors, cloud providers, custodians, software vendors and counterparties that are moving at completely different speeds."

That vendor dependency changes the inventory question. You're not just cataloging your own cryptography. You're mapping third-party migration timelines, identifying single points of failure, and building contingency plans for when a critical vendor misses its target date.

Deborah Guild, chair of the Financial Services Sector Coordinating Council, described the challenge in Treasury's announcement: "The transition requires organizations to prioritize critical systems and processes, manage dependencies across the financial ecosystem and address implementation challenges." The word "prioritize" implies you're not inventorying everything before you migrate anything.

Our Take

Start with a targeted inventory of payment processing, settlement systems, and cardholder data environments. These systems face the highest harvest-now-decrypt-later risk and the strictest interoperability requirements. Document their cryptographic dependencies, identify vendor timelines, and begin migration planning now.

For everything else, build cryptographic agility into new development and major upgrades. Don't retrofit legacy systems that you're planning to retire. Don't wait for a complete inventory of systems that change faster than you can document them.

The real risk isn't choosing the wrong sequencing. It's treating quantum readiness as a compliance exercise you'll start when regulators issue requirements. U.S. financial regulators haven't issued post-quantum computing mandates, and Treasury's task force announcement doesn't signal that any are coming. You're managing this migration without regulatory deadlines or enforcement mechanisms.

That means the institutions that move first aren't responding to compliance pressure. They're protecting operational resilience and managing cryptographic risk as a security function, not a regulatory one. The question isn't whether to inventory before you migrate. It's whether you're willing to start either one before someone makes you.

Quantum Computing and Cryptography

You Might Also Like