Are You Ready to Witness the Future of Data Security?
Platform
Resources
©2026 QuNu Labs Private Limited, All Rights Reserved.

TL;DR
On the morning of 11 September 2026, at the Global FinTech Fest in Mumbai, RBI Deputy Governor Shirish Chandra Murmu said something that is worth reading exactly as he said it.
"The time has therefore come for Indian payment system providers and network operators to begin moving towards quantum-proofing our payment systems."
And then: "Banks, payment operators, FinTechs, technology providers and standard-setters will need to move together, because quantum resilience is an ecosystem capability, not an institutional one."
This was not a research paper. It was not a committee report. It was a Deputy Governor of the Reserve Bank of India, at the country's largest fintech gathering, telling the assembled leaders of India's banking and payments ecosystem that the preparation needs to begin now.
Murmu was precise about what kind of threat he was describing. Quantum computing can also challenge the cryptographic foundations on which today's financial system rests, he noted. He explicitly named harvest now, decrypt later, the attack strategy in which encrypted information collected today can become readable in the future as quantum computing capability advances. MEDIANAMA
He was also precise about the lesson from international experience. He referred to Project Leap, an initiative of the BIS Innovation Hub with partner central banks, which replaced traditional digital signatures with post-quantum cryptography in a liquidity transfer experiment. "Its lesson is about timing: this work takes longer than institutions expect and cannot be done alone," Murmu said. The Tribune
It is important to be accurate about what this statement was and was not. As MediaNama reported, Murmu's remarks remain an exhortation from a Deputy Governor rather than a direction: no timeline, no standard and no compliance mechanism was attached. But the direction of travel is unambiguous. The RBI has moved publicly from studying quantum risk to asking the industry to act on it. Institutions that wait for a mandatory circular to be issued before beginning will find themselves behind a migration timeline that has already been demonstrated internationally to take longer than expected.
India's digital payment ecosystem operates at a scale that makes the quantum exposure concrete rather than abstract. In August 2026, the National Payments Corporation of India recorded over 20 billion UPI transactions. Each transaction involves authentication, key exchange and digital signatures built on public-key cryptography: RSA and elliptic-curve cryptography that Shor's algorithm, running on a sufficiently capable quantum computer, would break.
The RBI's Q-SAFE Expert Committee, constituted in May 2026 and chaired by Professor Anil Prabhakar of IIT Madras, has been tasked with evaluating the financial sector's cryptographic inventory through a Cryptographic Bill of Materials, assessing crypto-agility, identifying systems most vulnerable to quantum threats, and recommending a roadmap to quantum-secure India's financial system, with its report due within six months of its first meeting.
That committee's work will produce a roadmap. But institutions that wait for the roadmap before beginning their own cryptographic inventory will have lost months that the committee's own findings are likely to identify as critical.
While India's ecosystem is beginning its quantum preparedness journey, the international evidence base is already in place.
BIS Project Leap Phase 2, completed in December 2025 by the BIS Innovation Hub alongside the Bank of Italy, Bank of France, Deutsche Bundesbank, Nexi-Colt and Swift, replaced traditional digital signatures with post-quantum cryptography while executing liquidity transfers in the Eurosystem's TARGET2 real-time gross settlement system. All test scenarios were successfully completed. The BIS confirmed it is technically feasible to migrate payment systems to post-quantum cryptography without breaking how money moves.
The BIS was also clear about what the project revealed: "Migrating payment systems to quantum-safe solutions is a complex and high-stakes process that affects the entire financial ecosystem. Project Leap Phase 2 highlighted the importance of timely preparation and close collaboration across institutions to ensure long-term financial stability in the face of emerging quantum threats." RemoteUA
That is the global central banking community telling the financial sector three things simultaneously: it can be done, it takes longer than you expect, and you cannot do it alone.
Murmu's reference to Project Leap at GFF 2026 was not incidental. It was the international evidence base for why India needs to start now.

The technical feasibility is established. The political will at the regulatory level is visible. The challenge that the industry has not yet fully absorbed is the operational one.
Most financial institutions do not have a complete picture of where RSA and ECC live across their estate. Payment gateways, authentication layers, API security, HSMs, certificate infrastructure, core banking system integrations, third-party vendor APIs, and mobile SDK implementations all use public-key cryptography. A cryptographic inventory is the first deliverable of any migration programme, and for most institutions it will surface significantly more dependencies than the initial estimate.
The BIS Project Leap finding that performance differences exist between traditional and post-quantum algorithms also signals that this is not a configuration change. It is a migration programme that requires testing, interoperability work, vendor coordination and staged rollout. For institutions processing billions of transactions, that work cannot be compressed into a short window.
Murmu's phrase "this work takes longer than institutions expect" is not a warning about the future. It is a description of what every institution that has started has already discovered.
Banks do not get a second chance at customer trust. Neither does their cryptography.
See what quantum-safe banking infrastructure looks like in practice.
Sources
At GFF Mumbai on 11 September 2026, RBI Deputy Governor Shirish Chandra Murmu stated the time has come for Indian payment system providers to begin quantum-proofing their systems. He named harvest-now, decrypt-later as a specific risk and cited BIS Project Leap as evidence that migration is feasible but takes longer than institutions expect.
Constituted in May 2026 and chaired by Professor Anil Prabhakar of IIT Madras, Q-SAFE is tasked with mapping the financial sector's cryptographic inventory through a CBOM, assessing crypto-agility, identifying quantum-vulnerable systems, and recommending a migration roadmap, due within six months.
Project Leap Phase 2, completed in December 2025 by the BIS with the Bank of France, Deutsche Bundesbank and Swift, successfully replaced classical digital signatures with post-quantum cryptography in the Eurosystem's TARGET2 payment system. It proved migration works but requires significant preparation time across multiple system components.
Start with a cryptographic inventory: every algorithm, key, certificate and protocol across payment gateways, authentication layers, HSMs, core banking integrations and vendor APIs. Most institutions find far more dependencies than estimated. That inventory is the prerequisite for everything that follows.