Quantum Security & PQC

Mastercard’s PQC White Paper Says Signatures, Not HNDL, Are the Real Payments Problem

November 20, 2025 — Mastercard has published a comprehensive position paper outlining the payments industry’s path to post-quantum cryptography, offering the clearest guidance yet from a major payment network on timeline estimates, migration strategies, and technical requirements for quantum-safe systems. The white paper, written by Mastercard R&D with researchers from NTU Singapore and PQStation, presents a detailed assessment of quantum computing threats to payment systems while advocating for immediate planning, even though its authors place cryptographically relevant quantum computers (CRQCs) no closer than 10 years away and more likely 20.

The document marks a significant milestone as the second-largest global payment network explicitly addresses quantum threats to financial infrastructure. Mastercard’s analysis aligns with recent government mandates while providing payment-specific context for implementation timelines and technical requirements. The paper emphasizes that reactive cybersecurity approaches to quantum threats “no longer suffice” and financial organizations must begin planning quantum-safe practices now.

Central to Mastercard’s position is the endorsement of post-quantum cryptography (PQC) over quantum key distribution (QKD) for practical implementation across payment systems. The paper specifically recommends NIST’s standardized algorithms: ML-KEM for key establishment, ML-DSA and SLH-DSA for digital signatures, following the August 2024 publication of these standards. Mastercard advocates for hybrid implementations that combine classical and post-quantum schemes during the transition period, echoing European regulatory approaches rather than the direct migration path mandated for U.S. federal systems.

On timeline estimates, Mastercard cites recent quantum resource calculations suggesting RSA-2048 could be broken with approximately 900,000 physical qubits operating for 4.63 days, or 20 million qubits in 8 hours. With current quantum computers possessing only hundreds of physical qubits, the paper positions the threat as distant but inevitable. The analysis references Google’s Willow processor achieving 105 qubits in 2024, noting that at current progress rates, reaching cryptographically relevant scales could take 90-125 years, though breakthrough developments could accelerate this timeline.

The white paper addresses the “Harvest Now, Decrypt Later” (HNDL) threat with nuanced analysis specific to payment systems. While acknowledging HNDL as a legitimate concern for long-lived data, Mastercard notes that EMVCo-based smart card transactions use dynamic cryptograms that quickly lose value after use. For backend systems storing credit histories, investment records, and loan documents, the paper recommends immediate adoption of quantum-resistant encryption, specifically mentioning OpenSSL 3.5’s support for quantum-resistant hybrid KEM.

Two positions in the paper cut against the urgency most vendors sell. For the financial sector, it argues, migrating digital signatures is “the real problem” and more relevant than countering harvest-now-decrypt-later attacks. And setting regulations and mandates aside, it judges the risk of delaying migration by several years while PQC standards are battle-tested to be “reasonably low”. What it says every institution should invest in now, regardless of timeline, is cryptographic inventory tooling.

Mastercard’s migration recommendations include crypto-agility as a core principle, enabling systems to transition between cryptographic standards as threats evolve. The paper emphasizes performance considerations, noting that some PQC algorithms require larger key sizes and increased computational overhead compared to current RSA and ECC implementations. Financial institutions are advised to begin inventory assessments of cryptographic dependencies and develop migration roadmaps aligned with regulatory timelines.

My Analysis

When the world’s second-largest payment network drops a 40-page technical white paper on quantum threats, that’s your Monday morning wake-up call. This publication effectively sets migration expectations for thousands of financial institutions, payment processors, and technology vendors across Mastercard’s ecosystem. I’ve been tracking the payments industry’s quantum preparedness, and this document represents a critical shift from awareness to action planning.

What strikes me most about Mastercard’s position paper is its careful balance between urgency and pragmatism. They’re telling the industry to start planning now while simultaneously acknowledging that quantum computers capable of breaking current encryption are likely decades away. This apparent contradiction actually makes perfect sense when you understand payment system lifecycles. Payment infrastructure doesn’t change overnight. Terminal upgrades, processor migrations, and security standard updates typically operate on 5-10 year cycles.

The paper’s timeline estimates deserve scrutiny. Mastercard cites the 900,000 qubit figure for breaking RSA-2048, down from earlier 20 million qubit estimates. Progress in quantum error correction could further reduce these requirements. While they project 90+ years at current development rates, I believe this dramatically underestimates the acceleration we’ll see once quantum advantage becomes commercially valuable. The jump from hundreds to thousands of qubits will be hard. The jump from thousands to hundreds of thousands might happen surprisingly fast once key engineering challenges are solved.

Most significantly, this white paper creates what I call “soft deadlines” for the payments ecosystem. When Mastercard publishes migration guidance, it becomes de facto policy for their network participants. Payment processors will update their roadmaps. Acquiring banks will adjust security budgets. Technology vendors will prioritize PQC features. This cascading effect transforms theoretical quantum threats into concrete business requirements with real timelines.

The connection to existing regulatory frameworks amplifies this effect. BIS quantum readiness guidelines already establish expectations for financial institutions. PCI DSS v4.0.1 introduced cryptographic agility requirements that align perfectly with Mastercard’s recommendations. FS-ISAC’s Post Quantum Cryptography Working Group has published guidance for the payment card industry. Mastercard’s paper ties these threads together, providing payment-specific context that transforms general guidance into actionable requirements.

I find their skepticism about QKD for payment applications justified. QKD requires specialized hardware, point-to-point connections, and offers no digital signature capabilities. Payment systems need scalable, software-based solutions that work across existing networks. PQC delivers exactly that. Mastercard’s endorsement of NIST standards over proprietary alternatives also sends a clear message: the payment industry will follow established cryptographic standards, not vendor-specific solutions.

The hybrid approach recommendation interests me particularly. Unlike U.S. federal mandates requiring direct migration to PQC, Mastercard advocates for combining classical and quantum-resistant algorithms during transition. This pragmatic stance acknowledges that payment systems can’t flip a switch overnight. Hybrid implementations allow gradual migration while maintaining backward compatibility. Smart approach for an ecosystem processing billions of transactions daily.

Their HNDL analysis for payments provides valuable perspective. Dynamic cryptograms in card transactions, one-time tokens, and short-lived session keys reduce harvesting value for most payment data. But Mastercard correctly identifies backend systems as the real vulnerability. Credit bureaus, loan portfolios, and customer databases contain information valuable for decades. These systems need quantum-resistant protection now, not when quantum computers arrive.

Mastercard is more relaxed about timing than most of its readers can afford to be. Setting mandates aside, the paper judges the risk of waiting several years to be low. Regulators have not set mandates aside, and the paper itself lists target dates of 2030–2033 from various regulatory frameworks. Factor in typical payment system development cycles, testing requirements, and certification processes, and you’re looking at 2027-2028 start dates for serious migration efforts. That’s 2-3 years from now for multi-year projects.

I see three immediate implications for payment stakeholders. First, every organization touching payment data needs a cryptographic inventory. You can’t migrate what you don’t know exists. Second, new systems should implement crypto-agility from day one. Building flexibility now costs far less than retrofitting later. Third, vendor selection criteria must include PQC roadmaps. If your payment processor or HSM provider lacks clear quantum-safe plans, start asking hard questions.

The white paper also reveals interesting dynamics in global regulatory approaches. Mastercard’s endorsement of European-style hybrid migration over U.S. direct migration suggests the payment industry will follow the more conservative path. This makes sense given international operations and diverse regulatory requirements. Payment networks can’t afford fragmented security standards across regions.

Performance concerns get appropriate attention without becoming showstoppers. Yes, some PQC algorithms require larger keys and more computation. Modern payment infrastructure can handle this overhead. The real challenge lies in legacy systems, embedded devices, and resource-constrained environments. Mastercard’s emphasis on early planning gives organizations time to identify and address these bottlenecks.

Reading between the lines, I detect careful positioning regarding timeline uncertainty. Mastercard acknowledges that breakthrough developments could accelerate quantum computing progress while maintaining that current evidence suggests decades-long timelines. This measured tone avoids both quantum FUD and dangerous complacency. They’re essentially saying: prepare for the worst while expecting reasonable timelines.

The publication timing itself sends a message. Releasing this guidance now, shortly after NIST standard finalization and amid increasing regulatory attention, positions Mastercard as proactive rather than reactive. They’re shaping the conversation rather than responding to it. Other payment networks will likely follow with their own guidance, but Mastercard has set the baseline expectations.

For security teams in financial services, this white paper provides powerful ammunition for budget discussions. When Mastercard says quantum threats require action now, that carries weight with executives and boards. The comprehensive technical analysis, complete with qubit calculations and algorithm recommendations, demonstrates serious due diligence. This isn’t vendor FUD; it’s systematic risk assessment from a major market participant.

As I noted in my analysis of Q-Day deadlines already being set, the quantum threat has transformed from abstract future risk to concrete present planning requirement. Mastercard’s white paper accelerates this transformation for the payments industry. Every issuer, acquirer, processor, and technology vendor in their ecosystem now has documented notice that quantum-safe migration is expected. The clock isn’t ticking toward Q-Day itself but toward compliance deadlines that arrive much sooner.

The bottom line for payment security professionals: Mastercard’s paper tells you to build the cryptographic inventory now and to treat signatures as the harder migration. The timetable itself will come from regulators, not from Mastercard.

Marin Ivezic

I am the Founder of Applied Quantum (AppliedQuantum.com), a research-driven consulting firm empowering organizations to seize quantum opportunities and proactively defend against quantum threats. A former quantum entrepreneur, I’ve previously served as a Fortune Global 500 CISO, CTO, Big 4 partner, and leader at Accenture and IBM. Throughout my career, I’ve specialized in managing emerging tech risks, building and leading innovation labs focused on quantum security, AI security, and cyber-kinetic risks for global corporations, governments, and defense agencies. I regularly share insights on quantum technologies and emerging-tech cybersecurity at PostQuantum.com.