← Back to Home News · SGP

Decoding MAS's Mandate for Quantum Resilience Before 2030

Make RegTech.com preferred on Google
Decoding MAS's Mandate for Quantum Resilience Before 2030

The Monetary Authority of Singapore (MAS) released its FY2025/2026 Annual Report, showcasing a resilient financial sector with S$6.7 trillion in Assets Under Management (AUM) and a strong 6% GDP expansion in H1 2026.

Hidden amidst the headline growth figures and monetary policy shifts is a strategic directive tucked inside the Innovative and Resilient Financial Sector roadmap:

“MAS will set out supervisory expectations to guide FIs’ phased migration towards achieving quantum resilience before the end of this decade.”

While the industry has been consumed with AI-enabled fraud and real-time AML monitoring, Singapore’s regulator is already laying the operational groundwork for the next existential threat to institutional infrastructure: quantum computing.

What Is Quantum Resilience?

Quantum Resilience (or “Quantum Safety”) refers to an organisation’s capability to defend its digital infrastructure, encryption keys, and sensitive data against attacks powered by Cryptographically Relevant Quantum Computers (CRQCs).

Today’s global financial system, from SWIFT wire transfers and digital banking logins to blockchain smart contracts, relies on asymmetric cryptography (such as RSA and Elliptic Curve Cryptography / ECC) to secure communication and prove identity. A sufficiently powerful quantum computer running Shor’s algorithm can crack RSA-2048 or ECC encryption in seconds, a task that would take classical supercomputers thousands of years.

The "Harvest Now, Decrypt Later" Threat

The risk is not just a future problem; it is an active operational threat today known as “Harvest Now, Decrypt Later” (HNDL). Hostile actors and cybercriminal syndicates are already harvesting encrypted financial records, corporate disclosures, and transaction logs. They do not need to break the code today; they simply store the ciphertext until a quantum computer becomes operational, instantly exposing historic financial transactions.

The Three Pillars of MAS’s Quantum Mandate

MAS’s decision to set explicit supervisory expectations before 2030 transitions quantum risk from an IT research project to a core board governance metric. To achieve true quantum resilience, financial institutions (FIs) must execute across three core pillars:

1. Achieving “Crypto-Agility”

FIs cannot replace their entire tech stack overnight. Crypto-agility means designing software architectures so that cryptographic algorithms, signatures, and key lengths can be swapped dynamically via configuration or API updates, without breaking core banking systems or requiring complete code overhauls.

2. Migrating to Post-Quantum Cryptography (PQC)

Post-Quantum Cryptography refers to new mathematical algorithms (shortlisted by NIST) designed to run on standard computers while remaining computationally impossible for both classical and quantum computers to break. Compliance functions will need to ensure that vendor software, core ledgers, and API endpoints adopt these PQC standards.

3. Inventorying Cryptographic Assets

You cannot protect what you do not catalogue. MAS’s supervisory expectations require FIs to audit and inventory every single cryptographic asset across their environment, identifying where legacy RSA/ECC keys are stored, which third-party IT vendors rely on vulnerable hardware security modules (HSMs), and which data carries a high-value decay life. Regulators treat quantum resilience as a systemic risk issue rather than a technical detail.

Quantum Resilience Control Matrix
  • Vendor & Supply Chain Contagion: FIs are rarely compromised at the core; they are compromised through third-party vendors. If your custody software, cloud provider, or KYC API relies on legacy encryption, your institution remains vulnerable. Compliance functions must begin demanding PQC-readiness roadmaps in vendor RFPs immediately.
  • Director and Officer Liability: As MAS codifies supervisory expectations, “we didn’t know quantum computing was coming” will no longer serve as a legal defence. Boards and senior executives will need to attest explicitly that cryptographic migration plans have been approved, funded, and stress-tested.
  • The 2030 Migration Horizon: Upgrading cryptographic infrastructure across complex tier-1 financial systems takes an average of 5 to 7 years. Setting a 2030 target means the migration cycle must begin now.

MAS’s FY2025/2026 report demonstrates that building a resilient financial hub requires preparing for long-term technological shifts alongside immediate operational needs. Just as institutions that delayed building compliance-by-design frameworks are now struggling under modern regulatory pressures, those that treat quantum resilience as a distant problem will face severe operational and regulatory hurdles when supervisory audits begin.

Compliance and risk functions must shift their perspective: Quantum resilience is not a future IT upgrade. It is a core pillar of modern institutional governance.

Read the full MAS article here.
Link copied to clipboard
AI Bot
AI Bot
Hi! I'm the RegTech.com assistant. How can I help you today?
Ask me anything — top trending news, latest regulatory changes in the EU, or simply search for topics.