Industry Context
Regulated crypto exchanges and custodians sit at the trust centre of digital-asset markets. They hold client assets, settle transactions, produce proof-of-reserves attestations, and generate the audit records that regulators, counterparties, and institutional clients rely on. Trust is not a feature of the business — it is the business. A custodian that cannot demonstrate the integrity of its holdings and its records has nothing to sell. That trust rests almost entirely on public-key cryptography. Wallet infrastructure, transaction signing, settlement rails, and the supporting enterprise stack depend on elliptic-curve and RSA signature schemes. The same schemes secure the compliance artefacts a venue must keep — signed attestations, audit exports, registers — for years after they are created. The exposure extends to the assets themselves: the ECDSA keys securing custodied funds are quantum-vulnerable in exactly the same way as the records they sit alongside. That chain-level exposure is real and partly outside any single venue's control — which is why readiness starts with the surface a venue does control: its records, its signing infrastructure, and its attestations. The operating environment is tightening on every axis. Institutional capital is entering the asset class through regulated venues, not unregulated ones. Licensing regimes are maturing, and with them the expectation that an exchange or custodian can evidence not only that it is secure today, but that the records it produces will remain verifiable into the future. Auditors increasingly ask not just “is this signed?” but “will this signature still mean something in ten years?” This is where long-term cryptographic integrity stops being a technical detail and becomes a governance question. A custody record or a proof-of-reserves attestation is only as durable as the cryptography underneath it. If that cryptography has a known expiry, so does the trust it underwrites — unless the venue has prepared for the transition before the expiry arrives.
Emerging Requirements
The forces driving change here are external, dated, and largely outside any single venue's control. In August 2024, NIST ratified the first post-quantum cryptographic standards — FIPS 203, 204, and 205. The replacement algorithms for the ECDSA and RSA schemes in use across the industry are no longer research proposals; the successor algorithms are now published standards. NIST IR 8547 sets the transition timeline: RSA-2048 and ECC P-256 are to be deprecated for new systems by 2030 and disallowed entirely by 2035. CNSA 2.0 goes further for national-security systems, requiring new acquisitions to support ML-KEM-1024 and ML-DSA-87 from January 2027 — which matters to any venue with sovereign, defence, or government-linked counterparties, because it sets the procurement tone those institutions will carry into the market. The direction of travel is not confined to the United States. In the UK, the NCSC's post-quantum migration roadmap expects organisations to complete discovery and migration planning by 2028, finish their highest-priority migrations by 2031, and complete the transition by 2035. In the EU, DORA's ICT-risk and operational-resilience obligations and MiCA's authorisation regime give supervisors concrete grounds to ask cryptographic-governance questions of exchanges and custodians today. For a regulated venue, the practical near-term deadline is therefore not 2035 — it is the 2028 discovery-and-planning milestone. Alongside the standards, the governance expectations are shifting. Regulators and auditors are beginning to treat cryptographic agility — the ability to change cryptographic primitives without re-architecting — as a control to be evidenced, not assumed. Long-term data retention obligations mean signed records must survive the deprecation of the schemes that signed them. Supply-chain scrutiny extends cryptographic responsibility to inherited dependencies in third-party HSMs, signing services, and vendor platforms. And audit defensibility increasingly requires a venue to show a roadmap, not merely an intention. None of these requirements demands a finished migration tomorrow. What they collectively demand is that a regulated venue can answer, on request, three questions: where is its trust dependent on soon-to-be-deprecated cryptography, what is its exposure, and what is its plan. Today, most cannot.
Business Risk & Exposure
Doing nothing is not a neutral position. It is an accumulating, unquantified liability. That holds even for those who judge a cryptographically relevant quantum computer to be decades away: the exposures below accrue from data captured and records signed today, and the regulatory deadlines are already dated. Neither waits for the hardware. The most immediate exposure is harvest-now-decrypt-later. State-level actors are already capturing encrypted data at scale on the assumption that it can be decrypted once cryptographically relevant quantum capability exists. For an exchange or custodian, the sensitive material — client records, historical transaction flows, and internal communications — has a long shelf life. The decryption deadline is, on any prudent planning horizon, a question of when, not if, and data captured today is exposed against that future date regardless of what the venue does next year. History also says the migration itself takes years: the SHA-1 and 3DES deprecations each took five to ten years or more to work through the industry, so the work has to start well before the threat is imminent — not once it arrives. The second exposure is long-term record integrity. A proof-of-reserves attestation, a compliance export, or a custody confirmation signed today must remain verifiable years later. If the signature scheme behind it is broken or deprecated in the interim, the record's evidentiary value degrades — quietly, and usually unnoticed until it is needed in an audit or a dispute. The third is cryptographic dependency risk. ECC and RSA are buried throughout the stack: in signing services, wallet infrastructure, internal PKI, and vendor platforms a venue does not control. Most exchanges and custodians cannot produce a complete inventory of where they rely on these schemes — which means they cannot scope their own exposure, let alone govern it. This is the governance blind spot: you cannot manage, prioritise, or defend what you have not mapped. The cumulative effect is future scrutiny risk. As deadlines approach, regulators, auditors, and institutional clients will ask for migration plans. The venues that can produce a credible, evidenced roadmap will clear those conversations. The venues that cannot will face the migration as an emergency — under time pressure, with weaker negotiating position and higher cost. The point a board should take from this is simple: post-quantum readiness is a business-risk and governance issue first, and a technical project second.
The Infrastructure Challenge
The reason this is hard is not a shortage of post-quantum algorithms. The standards exist. The challenge is that the infrastructure most venues run today was never built to answer the questions readiness now requires. There is a visibility gap: no authoritative inventory of where cryptographic schemes are relied upon across owned systems and inherited dependencies. There is a governance gap: no clear owner of cryptographic risk, no roadmap, no defined triggers for action. There is a trust gap: attestations and records depend both on classical signature schemes and on the issuer remaining the single, continuous point of trust — if the issuer's keys are compromised or the issuer ceases to exist, the record's integrity is no longer independently provable. Underlying all of these is a capability that is genuinely difficult to maintain over long horizons: the ability to prove that a specific record existed at a known point in time and has not changed since — independently of the issuer, and durably enough to survive the deprecation of whatever cryptography secured it originally. Conventional infrastructure ties that proof to the issuer and to a single signature scheme. Neither assumption holds across a ten- or fifteen-year retention window that crosses a cryptographic transition. The reader should take away that existing infrastructure is not wrong — it is simply not designed for the readiness requirements now arriving, and closing that gap is an infrastructure question, not a patch.
Preparing for the Transition
Readiness is a sequence, not a single decision. Each stage produces value on its own and can be acted upon regardless of what comes next.
- Current State
- Discovery
- Risk Assessment
- Planning
- Migration Preparation
- Trust Infrastructure
- Long-Term Readiness
What organisations should be doing today. The first and most actionable step is diagnosis: a complete cryptographic inventory of where ECC, RSA, and related schemes are relied upon, across both owned systems and inherited vendor dependencies. This is the input every later decision depends on, and it has standalone value — it is the artefact a regulator or auditor will ask for, and it is useful whether or not a single product is purchased afterwards. From there, risk assessment classifies that inventory by exposure — what is harvest-now-decrypt-later sensitive, what carries long-term retention obligations, what is buried in dependencies outside direct control. Planning converts the assessment into a prioritised, NIST-aligned roadmap with owners and sequencing. Migration preparation introduces crypto-agile patterns so that primitives can be changed without re-architecting. Trust infrastructure addresses the integrity gap directly, establishing durable, issuer-independent proof for the records that must outlast today's cryptography. Long-term readiness is the steady state: an evidenced, governed, periodically refreshed posture rather than a one-off project. The organisational requirement running through all of it is ownership. Post-quantum readiness fails when it has no home — when it is treated as a future IT task rather than a present governance responsibility with a named owner and a board-visible roadmap. The venues that approach it as a sequence they have started, rather than a deadline they are waiting for, are the ones that clear it without disruption.
Relevant QF Infrastructure
Quantum Future maps to this readiness journey at the points where regulated venues most need help. Each offering stands on its own; none is a precondition for another. Post-Quantum Discovery & Risk Assessment is the diagnostic. A fixed-scope engagement that produces a cryptographic dependency inventory, a harvest-now-decrypt-later risk classification, and a NIST-aligned migration roadmap. It is deliberately vendor-neutral and benchmarked against NIST standards — its job is to tell a venue the truth about its exposure, not to route it toward a product. The deliverable is complete in itself and is the artefact that answers the questions regulators and auditors are starting to ask. Strategic PQ Advisory supports the planning and governance layer for venues that need board-level or sovereign-grade engagement — sequencing, governance design, and readiness strategy tailored to the institution's regulatory and operational context. PQAS (Post-Quantum Attestation Service) addresses the trust-infrastructure stage. It provides an independent cryptographic integrity layer: a record is hashed locally, the hash is signed with a post-quantum scheme (ML-DSA under FIPS 204 or SLH-DSA under FIPS 205), and the proof is anchored to the Quantum Resistant Ledger (QRL), a public post-quantum blockchain that has run post-quantum signatures in production since 2018. Sensitive documents never leave the venue's infrastructure — only hashes are transmitted — which makes it suitable for regulated and highly sensitive workflows. The result is a proof of “this record existed at this time and is unchanged” that is verifiable independently of the issuer and durable across a cryptographic transition. For an exchange producing proof-of-reserves attestations or a custodian producing audit exports, this is the capability that gives those records integrity that outlasts today's signatures.
Future-State Architecture
A prepared exchange or custodian looks materially different from today's default. It holds a complete, maintained inventory of its cryptographic dependencies and a named owner for them. It runs a NIST-aligned roadmap with crypto-agile signing patterns, so a change of primitive is a configuration decision rather than a re-architecture. Its proof-of-reserves attestations and audit records carry integrity proofs that are independently verifiable against a public post-quantum blockchain — provable without relying on the venue's continued existence or key hygiene. And it can answer a regulator's migration question with evidence rather than intention. The operational improvement is that readiness stops being a looming, undated risk and becomes a governed, business-as-usual posture. The trust improvement is that the venue's most important records — the ones clients and regulators depend on — are durable across the transition that is coming for everyone else.
Next Steps
Discuss Your Readiness Strategy
Start with a conversation about where your cryptographic exposure sits and what a defensible roadmap looks like for your venue.
Explore Relevant Solutions
See how Discovery, Strategy Advisory, and PQAS map to each stage of the readiness journey.
