M10 / Payment cryptography

ISO 8583/20022 and the Turkey-specific scope

Advisor

After this lesson you can

  • Distinguish the ISO 8583 and ISO 20022 message structures and which is used for which kind of transaction
  • Explain the Turkey-specific BDDK/TCMB/TROY/FAST scope with real dates, and where the PQC position in this area stands today (an honest gap)

Before thisEMV, DUKPT and the payment HSM

Mental model

In M10’s previous two lessons you saw payment surfaces and EMV/DUKPT/payment HSMs. This last lesson covers message formats (ISO 8583/20022) and the context specific to this course’s primary learner’s own country (BDDK, Turkey’s banking regulator; TCMB, the central bank; TROY; FAST). Here too you will apply the course’s “if you don’t know, say so” discipline, because there is a real gap in this area.

ISO 8583 and ISO 20022: two generations, two formats

ISO 8583 is an old (since 1987) message format still dominant in card transactions (POS, ATM, card-issuer messaging); its fields are numbered, positional and binary. ISO 20022 is a newer, XML-based, structured message schema that is increasingly becoming the standard for interbank fund transfers (including FAST itself). Both have versions that include signatures; from a PQC point of view, the difference is that ISO 20022’s structured, schema-based nature makes adding the OID of a new signature algorithm (such as ML-DSA) relatively easier than ISO 8583’s more rigid, positional field structure.

Turkey’s payment infrastructure: real institutions, real dates

TROY is Turkey’s domestic card scheme, founded and operated by the Interbank Card Center (BKM), with TCMB as majority shareholder. A BDDK regulation requires card schemes licensed in Turkey to be used for domestic transactions. FAST (Fonların Anlık ve Sürekli Transferi, instant and continuous funds transfer) is TCMB’s 24/7 instant money transfer system; according to TCMB’s own announcement (2020-67) the pilot started on 18 December 2020SOURCED, and according to a separate announcement (DUY2021-01) it opened to customers on 8 January 2021SOURCED (two different dates, two different announcements; do not attribute both to one source). FAST uses the ISO 20022 message structure, which makes it one of the “really need PQC” surfaces (signed messaging) you saw in M10’s earlier lesson.

An honest gap: no specific regulatory position today

While preparing this lesson, the announcement and regulation pages of BDDK and TCMB were searched for a specific, published post-quantum cryptography position for payment systems; none was found. This is another application of the “when you find a gap, don’t invent figures, say there is a gap” discipline you saw in M7 and M9: we do not claim that BDDK/TCMB have said nothing about PQC (a regulation may come in the future, or work may be going on behind closed doors), only that no public, searchable position was found today. When presenting this gap to a bank, the right frame is: “the local regulator has not given a date, but that does not mean the PQC requirements of your international counterparties (European banks, card schemes) won’t reach us indirectly; instead of waiting for local regulation, we should base our own risk planning on the international timelines you will see in M11.”

Numbers to know

  • FAST (Fonların Anlık ve Sürekli Transferi, instant and continuous funds transfer), TCMB's instant payment system: the pilot started on 18 December 2020, and it opened to customers on 8 January 2021
  • TROY is Turkey's domestic card scheme, operated by the Interbank Card Center (BKM) with TCMB as majority shareholder; a BDDK regulation requires card schemes licensed in Turkey to be used for domestic transactions

Lab: Search for BDDK/TCMB's own PQC position

[not run] This is a verification and gap-finding exercise, not a runnable command

Requires: internet access. Check your setup

shell
# Search the announcement and regulation pages of bddk.org.tr and tcmb.gov.tr for 'post-kuantum' or 'kuantum'
Recorded output
While preparing this lesson (September 2026), no specific, published PQC position for payment systems from BDDK or TCMB was found; this is a gap, meaning 'not found', not 'not searched'

At the table

How to say this in a bank meeting.

To an executive
No specific PQC requirement has yet been published by BDDK/TCMB for our payment infrastructure in Turkey (TROY, FAST); that does not mean we need not prepare, but that we should do our own risk assessment proactively, based on international standards (EMVCo, ISO, CNSA 2.0).
To an architect
ISO 8583 (still dominant in card transactions, with numbered, positional message fields) and ISO 20022 (in interbank transfers, XML/ISO 20022 message schemas, used by FAST) are different generations; the versions of both that use asymmetric signatures are affected by PQC, but ISO 20022's structured, extensible design makes adding new algorithm OIDs easier than in ISO 8583.
Objection
“"Turkish regulators haven't said anything about PQC. So there's no need to hurry, right?"”
Answer
Regulatory silence does not mean the absence of risk; as you will see in M11 (the EU coordinated roadmap, CNSA 2.0), international pressure and counterparty requirements can create a real timeline even without local regulation (a Turkish bank dealing with a European bank may be indirectly subject to that bank's PQC requirements). The defence 'the regulator said nothing' is not enough for a bank working with international counterparties.

Sources

Checkpoint

Answer first, then compare with the model answer and score yourself against the rubric. Saved in this browser only.

  1. 01Recall

    What is the difference between ISO 8583 and ISO 20022, and which one does FAST use?

  2. 02Recall

    When were TROY and FAST founded or launched, and who operates them?

  3. 03Scenario

    A board member says 'BDDK hasn't given us a PQC date, so why prepare now?' How do you answer?

  4. 04Hostile

    An auditor asks 'Is there an official PQC requirement for Turkey's payment systems?' Answer honestly, stating what you searched.

Project linkContributes to the Turkey-specific regulatory context sections of Project 3 (crypto inventory and prioritization) and Project 4 (capstone), as an honest gap finding.