October 1, 2026
Sumanth Srirangam

When a Central Bank Says "The Time Has Come," It Is Not a Suggestion

TL;DR

  • On 11 September 2026, RBI Deputy Governor Shirish Chandra Murmu told the Global FinTech Fest in Mumbai that the time has come for Indian payment system providers and network operators to begin quantum-proofing their systems.
  • The RBI's own Q-SAFE Expert Committee, constituted in May 2026, is tasked with mapping the financial sector's cryptographic estate and recommending a quantum-safe roadmap within six months.
  • The BIS, the Bank of France, Deutsche Bundesbank and Swift have already proven it is technically feasible. The question for India's BFSI sector is not whether to start. It is whether starting now leaves enough time.

On the morning of 11 September 2026, at the Global FinTech Fest in Mumbai, RBI Deputy Governor Shirish Chandra Murmu said something that is worth reading exactly as he said it.

"The time has therefore come for Indian payment system providers and network operators to begin moving towards quantum-proofing our payment systems."

And then: "Banks, payment operators, FinTechs, technology providers and standard-setters will need to move together, because quantum resilience is an ecosystem capability, not an institutional one."

This was not a research paper. It was not a committee report. It was a Deputy Governor of the Reserve Bank of India, at the country's largest fintech gathering, telling the assembled leaders of India's banking and payments ecosystem that the preparation needs to begin now.

What the RBI Actually Said, and What It Did Not

Murmu was precise about what kind of threat he was describing. Quantum computing can also challenge the cryptographic foundations on which today's financial system rests, he noted. He explicitly named harvest now, decrypt later, the attack strategy in which encrypted information collected today can become readable in the future as quantum computing capability advances. MEDIANAMA

He was also precise about the lesson from international experience. He referred to Project Leap, an initiative of the BIS Innovation Hub with partner central banks, which replaced traditional digital signatures with post-quantum cryptography in a liquidity transfer experiment. "Its lesson is about timing: this work takes longer than institutions expect and cannot be done alone," Murmu said. The Tribune

It is important to be accurate about what this statement was and was not. As MediaNama reported, Murmu's remarks remain an exhortation from a Deputy Governor rather than a direction: no timeline, no standard and no compliance mechanism was attached. But the direction of travel is unambiguous. The RBI has moved publicly from studying quantum risk to asking the industry to act on it. Institutions that wait for a mandatory circular to be issued before beginning will find themselves behind a migration timeline that has already been demonstrated internationally to take longer than expected.

Why India's Payment System Has a Specific Quantum Risk Profile

India's digital payment ecosystem operates at a scale that makes the quantum exposure concrete rather than abstract. In August 2026, the National Payments Corporation of India recorded over 20 billion UPI transactions. Each transaction involves authentication, key exchange and digital signatures built on public-key cryptography: RSA and elliptic-curve cryptography that Shor's algorithm, running on a sufficiently capable quantum computer, would break.

The RBI's Q-SAFE Expert Committee, constituted in May 2026 and chaired by Professor Anil Prabhakar of IIT Madras, has been tasked with evaluating the financial sector's cryptographic inventory through a Cryptographic Bill of Materials, assessing crypto-agility, identifying systems most vulnerable to quantum threats, and recommending a roadmap to quantum-secure India's financial system, with its report due within six months of its first meeting.

That committee's work will produce a roadmap. But institutions that wait for the roadmap before beginning their own cryptographic inventory will have lost months that the committee's own findings are likely to identify as critical.

What the BIS Already Proved

While India's ecosystem is beginning its quantum preparedness journey, the international evidence base is already in place.

BIS Project Leap Phase 2, completed in December 2025 by the BIS Innovation Hub alongside the Bank of Italy, Bank of France, Deutsche Bundesbank, Nexi-Colt and Swift, replaced traditional digital signatures with post-quantum cryptography while executing liquidity transfers in the Eurosystem's TARGET2 real-time gross settlement system. All test scenarios were successfully completed. The BIS confirmed it is technically feasible to migrate payment systems to post-quantum cryptography without breaking how money moves.

The BIS was also clear about what the project revealed: "Migrating payment systems to quantum-safe solutions is a complex and high-stakes process that affects the entire financial ecosystem. Project Leap Phase 2 highlighted the importance of timely preparation and close collaboration across institutions to ensure long-term financial stability in the face of emerging quantum threats." RemoteUA

That is the global central banking community telling the financial sector three things simultaneously: it can be done, it takes longer than you expect, and you cannot do it alone.

Murmu's reference to Project Leap at GFF 2026 was not incidental. It was the international evidence base for why India needs to start now.

The Migration Challenge No One Is Talking About

The technical feasibility is established. The political will at the regulatory level is visible. The challenge that the industry has not yet fully absorbed is the operational one.

Most financial institutions do not have a complete picture of where RSA and ECC live across their estate. Payment gateways, authentication layers, API security, HSMs, certificate infrastructure, core banking system integrations, third-party vendor APIs, and mobile SDK implementations all use public-key cryptography. A cryptographic inventory is the first deliverable of any migration programme, and for most institutions it will surface significantly more dependencies than the initial estimate.

The BIS Project Leap finding that performance differences exist between traditional and post-quantum algorithms also signals that this is not a configuration change. It is a migration programme that requires testing, interoperability work, vendor coordination and staged rollout. For institutions processing billions of transactions, that work cannot be compressed into a short window.

Murmu's phrase "this work takes longer than institutions expect" is not a warning about the future. It is a description of what every institution that has started has already discovered.

Banks do not get a second chance at customer trust. Neither does their cryptography.  

See what quantum-safe banking infrastructure looks like in practice.

Sources

  1. ANI via Tribune India, Time Has Come to Quantum-Proof India's Payment Systems, Says RBI Deputy Governor Murmu (11 September 2026) : https://www.tribuneindia.com/news/cryptography/time-has-come-to-quantum-proof-indias-payment-systems-says-rbi-dy-governor-murmu
  2. MediaNama, RBI Asks Payment Operators to Start Quantum-Proofing at GFF 2026 : https://www.medianama.com/2026/09/223-rbi-payment-operators-quantum-proofing-gff-2026/
  3. ANI via Daily Prabhat, Time Has Come to Quantum-Proof India's Payment Systems (Project Leap reference, harvest-now-decrypt-later) : https://www.dailyprabhat.com/time-has-come-to-quantum-proof-indias-payment-systems-says-rbi-dy-governor-murmu/
  4. Reserve Bank of India, Q-SAFE Expert Committee Press Release (May 2026) : https://fintech.rbi.org.in/FS_PressRelease?prid=62803
  5. Bank for International Settlements, Project Leap Phase 2: Quantum-Proofing Payment Systems (December 2025) : https://www.bis.org/publ/othp107.htm
  6. Finextra, BIS and Central Banks Test Post-Quantum Cryptography in Payments (Project Leap Phase 2 technical findings) : https://www.finextra.com/newsarticle/47042/bis-and-central-banks-test-post-quantum-cryptography-in-payments
  7. NIST, Post-Quantum Cryptography and Migration Guidance : https://csrc.nist.gov/projects/post-quantum-cryptography

‍

Frequently asked questions

What exactly did the RBI Deputy Governor say about quantum proofing?
What is the RBI Q-SAFE Expert Committee?
What is BIS Project Leap and why does it matter for India?
What should a bank or fintech do first?

More blogs