In the previous two lessons you saw the US and EU/global regulatory timelines; these are general purpose (for all sectors). This lesson covers three sources aimed specifically at the financial sector: a methodology (Europol/FS-ISAC/CFDIR), real measured performance data (BIS, which you remember from M8), and a finance-specific technical standard (X9.146, not yet mature).
Europol/FS-ISAC/CFDIR: risk-based prioritization
On 21 January 2026, the Quantum-Readiness Working Group of Europol, FS-ISAC (Financial Services Information Sharing and Analysis Center) and CFDIR (Canadian Forum for Digital Infrastructure Resilience) published a joint report: “Prioritising Post-Quantum Cryptography Migration Activities in Financial Services.” The report’s main contribution is not a new technical standard but a methodology: it recommends that financial institutions build a crypto inventory, identify their most sensitive systems, and prioritize by weighing quantum risk (how sensitive a system is, how long its data must be protected) against migration time (how long moving that system to PQC will take). This is Mosca’s inequality from M1 (X: how long data must stay secret, Y: migration time, Z: time until a quantum computer arrives; if X+Y>Z there is risk) applied at institutional scale, to a bank’s entire crypto inventory rather than a single system; in M12 (discovery and inventory) you will see the practical application of this methodology.
BIS: reuse M8’s correct frame here
In the last lesson of M8 (signature-verify-performance) you saw the raw data of BIS’s Project Leap Phase 2 report (PQC verification 209.9 msSOURCED, RSA verification 28.1 msSOURCED) and the ratio derived from it (7.47×DERIVED, loosely inconsistent with BIS’s own “at least an order of magnitude” wording). This lesson does not explain that again; it only makes clear where it sits in the context of finance-specific guidance: BIS’s data is the kind of concrete performance measurement that can be an input to the Europol/FS-ISAC/CFDIR prioritization methodology, not a regulatory requirement. When presenting the two to an architect, the right frame is not “BIS tells us to do X” but “BIS’s data informs our prioritization decision”.
X9.146: finance-specific, but not yet mature
ASC X9 (Accredited Standards Committee X9, the official standards body of the US financial sector) is working on X9.146 (Q-TLS, Quantum TLS), a quantum-resistant TLS standard specific to the financial sector. While preparing this lesson, X9.org’s own pages showed active working group activity, but no clear, public finalization date was found. This is another application of this course’s “when you find a gap, don’t invent figures” discipline: instead of claiming X9.146 will be ready “soon” or “in 2027”, say openly that it is uncertain as of today. It is another application of the lesson you saw for FN-DSA in M4, “at a pre-draft status, tying production decisions to it is premature”: until X9.146 is finalized, a bank’s architecture should rest on general standards that are already final (FIPS 203/204/205).
Numbers to know
Europol/FS-ISAC/CFDIR report (21 January 2026): signed jointly by three institutions, it proposes a prioritization methodology that weighs quantum risk against migration time, with an emphasis on crypto-agility
BIS Project Leap (seen in M8): PQC verification 209.9ms, RSA verification 28.1ms (SOURCED), ~7.47x (DERIVED, loosely inconsistent with BIS's own 'at least an order of magnitude' wording)
X9.146 (Q-TLS) is still at working group/draft stage as of September 2026; no clear finalization date was found while preparing this lesson, which is recorded as an honest gap
Lab: Look up X9.146's current status yourself
[not run] This is a live verification and gap-finding exercise, not a runnable command
# Search x9.org's own pages for the current status of X9.146
Recorded output
What was found while preparing this lesson: active working group activity, but no clear publication or finalization date; this may have changed when you check again
At the table
How to say this in a bank meeting.
To an executive
There are three sources specific to the financial sector: the Europol/FS-ISAC/CFDIR methodology (which tells us how to prioritize), the real performance data BIS measured (which you saw in M8), and X9.146 (a finance-specific technical standard, but not ready yet). Together they answer 'how', 'how much slower' and 'against which standard', but all three are at different levels of maturity.
To an architect
The Europol/FS-ISAC/CFDIR methodology frames the PQC transition not as one big project but as a prioritization exercise comparing quantum risk with migration time; it is an institutional, multi-system application of Mosca's inequality (X+Y>Z) from M1. BIS's performance data (which you framed correctly in M8) is an input to that prioritization; X9.146 is not yet mature, and no architecture can be built on it today.
Objection
“"X9.146 is a standard specific to the financial sector. Should we wait for it and build to it?"”
Answer
X9.146 is real, active work, but no clear finalization date was found while preparing this lesson; the 'still a draft, tying production decisions to it is premature' discipline you saw in M2/M4 applies here too. Today's architecture should rest on standards that are already final (FIPS 203/204/205, seen in M3/M4), in a way that can adapt once X9.146 is finalized.
Europol, FS-ISAC, Canadian Forum for Digital Infrastructure Resilience (CFDIR), 2026. The source of a financial-sector-specific, risk-based prioritization methodology published jointly by three institutions
Accredited Standards Committee X9, 2026. The source of the real, honestly uncertain current status of X9.146 (a quantum-resistant TLS standard specific to the financial sector)
quantum computing page / 10 min
Checkpoint
Answer first, then compare with the model answer and score yourself against the rubric. Saved in this browser only.
01Recall
What does the Europol/FS-ISAC/CFDIR report's prioritization methodology compare against what?
Model answer
It prioritizes by weighing a system's quantum risk (how sensitive it is, how long its data must be protected) against migration time (how long moving that system to PQC will take); an institutional, multi-system application of Mosca's inequality from M1.
02Recall
Why does the ~7.47x ratio derived from BIS's raw data not fully match BIS's own wording (recall M8)?
Model answer
Dividing BIS's raw data (209.9ms/28.1ms) gives the ~7.47x ratio, but BIS's own prose says 'at least an order of magnitude' (at least 10 times); since 7.47x is below 10, the two statements are loosely inconsistent.
03Scenario
A project team plans to build its architecture to X9.146, which is not final yet. What do you say about this plan?
Model answer
It is premature: X9.146 (Q-TLS) is still at working group/draft stage, and no clear finalization date was found. Today's architecture should rest on general standards that are already final (FIPS 203/204/205) and be built to adapt once X9.146 is finalized; tying production decisions to an immature draft is premature.
A complete answer includes
Your score: 0/2
04Hostile
An auditor asks 'Is there guidance specific to the financial sector, or are you applying general PQC advice?' Explain, naming Europol/FS-ISAC/CFDIR and BIS.
Model answer
Yes, there is finance-specific guidance: the joint Quantum-Readiness Working Group of Europol, FS-ISAC and CFDIR published a risk-based prioritization methodology on 21 January 2026. In addition, BIS's Project Leap Phase 2 report provides real measured performance data (PQC verification 209.9ms, RSA verification 28.1ms), an input that informs our prioritization decisions. These are finance-specific sources, separate from general-purpose advice.
A complete answer includes
Your score: 0/3
Project linkA template for the finance-specific guidance sections of Projects 3 and 4, for presenting the contributions of the three institutions (Europol/FS-ISAC/CFDIR, BIS, ASC X9) in the right frame.