Cookie Preferences

    We use cookies to ensure our website functions properly and to improve your experience. Essential cookies are always active. You can choose to enable other categories below. Learn more

    Sector Guide · Financial Services

    Credit Union & Community Bank PQC Guide

    Post-quantum cryptography (PQC) readiness for NCUA-regulated credit unions and community banks — written for compliance officers, CIOs, and supervisory committees who need a defensible, vendor-aware roadmap before the next IT exam cycle.

    The Short Answer

    Credit unions do not run their own cryptography — they inherit it from core, digital banking, card, and MSP vendors. Quantum risk is a third-party risk problem, and NCUA's existing vendor management and information security rules already require boards to address it. The work in 2026 is inventory, vendor PQC roadmaps, and a board-reported plan aligned to the federal 2035 migration deadline.

    Why Credit Unions Are a Distinct PQC Problem

    Large national banks have in-house cryptography teams and direct relationships with FIPS-validated vendors. Most credit unions and community banks do not. Their quantum exposure surfaces in five places that the board ultimately owns:

    • Core processor (Fiserv, Jack Henry, FIS, Corelation, etc.): TLS/ECC for inter-system communication and at-rest encryption of member records.
    • Digital banking and mobile vendors: Session encryption, MFA tokens, and signed app/JWT chains that today rely on RSA/ECC.
    • Card networks and payment processors: EMV cryptograms, 3-D Secure, ATM key exchange — all on ECC-family primitives.
    • Wire, ACH, and FedNow integrations: Long-lived signing keys and TLS endpoints exposed to harvest-now-decrypt-later (HNDL) interception.
    • Member PII and loan files: 7–30 year retention requirements mean data stolen today is still sensitive when a cryptographically relevant quantum computer arrives.

    The NCUA & Regulatory Picture

    There is no PQC-specific NCUA rule yet — but several existing obligations already require credit unions to address quantum risk in 2026.

    NCUA Part 748 Appendix A

    Information security program must address foreseeable internal and external threats. Quantum decryption of member data is now a foreseeable threat under published NIST and CISA guidance.

    NCUA Part 749 / Vendor Due Diligence

    Boards must oversee third-party risk. Vendor PQC roadmaps, crypto agility clauses, and migration timelines belong in vendor reviews and contract renewals from 2026 onward.

    ACET / FFIEC CAT Successor

    Cybersecurity maturity assessments increasingly include cryptographic inventory and post-quantum readiness as control expectations. Examiners are asking.

    NSM-10 & OMB M-23-02

    Federal systems must migrate to PQC by 2035. Credit unions that interface with Treasury, FedNow, or federal data flows inherit this deadline through their counterparties.

    Why Member Data Is Already At Risk

    Harvest-now-decrypt-later (HNDL) attacks intercept and store encrypted member data today, waiting until a cryptographically relevant quantum computer can decrypt it. For a credit union, the data that matters has a long shelf life:

    • SSNs and government IDs: Effectively permanent — useful to an adversary 10+ years from now.
    • Mortgage and loan files: 15–30 year terms with sensitive income and asset disclosures.
    • Member authentication material: Password hashes, MFA seeds, and recovery answers that members rarely rotate.

    Read more on HNDL →

    A 2026–2033 Credit Union PQC Roadmap

    Aligned to NIST PQC standards (FIPS 203/204/205, finalized 2024) and the federal 2035 migration deadline, with a two-year buffer for community-sized institutions.

    2026 — Inventory & Governance

    • Cryptographic inventory across core, digital banking, card, and back-office vendors
    • Add quantum risk to ERM register and supervisory committee reporting cadence
    • Designate a board-accountable PQC owner (CIO, CISO, or vCISO)

    2027–2028 — Vendor Roadmaps & Contracts

    • Request written PQC roadmaps from every critical vendor (core, digital, card, MSP)
    • Add crypto-agility and PQC-readiness clauses to all renewals and new contracts
    • Begin pilot migrations on lowest-risk, highest-leverage systems (e.g. internal TLS)

    2029–2031 — Member-Facing Migration

    • Migrate digital banking, mobile, and member portal TLS to hybrid PQC
    • Rotate long-lived signing keys to ML-DSA (CRYSTALS-Dilithium)
    • Re-encrypt archival member data with PQC-protected keys

    2032–2033 — Completion & Attestation

    • Full PQC coverage across in-scope systems with documented exceptions
    • Board attestation and examiner-ready evidence package
    • Two-year buffer before the federal 2035 deadline for residual cleanup

    Five Questions To Ask Every Critical Vendor

    Copy these into your next vendor management cycle. A vendor that cannot answer them is a finding in your next IT exam.

    1. What is your published PQC roadmap, and which NIST-finalized algorithms (ML-KEM, ML-DSA, SLH-DSA) are on it?
    2. Which of your systems that touch our members or our data are still on RSA or ECC today, and when will they migrate?
    3. Do you support hybrid (classical + PQC) TLS, and on what timeline?
    4. How do you guarantee crypto agility — can you swap algorithms without a major re-platforming?
    5. Will you contractually attest to PQC readiness before the federal 2035 deadline, and how will you evidence it to our examiners?

    Get the Credit Union PQC Briefing

    The Credit Union & Community Bank PQC Briefing is a bi-weekly publication covering NCUA developments, vendor PQC readiness, and compliance milestones — written for compliance officers and CIOs at member-owned institutions.