Introduction
Financial institutions depend on cryptography for transactions, identity, signing, APIs, payment ecosystems and long-term data protection. QSD research explores practical transition patterns that preserve resilience, auditability and interoperability while institutions modernise cryptographic foundations under DORA-driven operational-resilience expectations.
2026 Research Context
Financial institutions are now operating under DORA while simultaneously preparing for longer-term cryptographic change. DORA does not prescribe specific PQC algorithms, but its governance, testing, third-party and resilience model provides a natural operating structure for cryptographic transition. Research priorities therefore include HSM and PKI migration, payment and API interoperability, supplier readiness, high-volume performance, evidence and rollback. The goal is to understand how quantum-safe change can be introduced without weakening transaction integrity, availability or the control environment that regulated institutions already maintain.
Research Focus
- Core banking and payment cryptographic dependencies
- HSM and key-management migration paths
- Digital signatures and non-repudiation use cases
- API, messaging and ISO 20022 security dependencies
- Third-party ICT and cloud-provider readiness
Expected Research Outputs
- Financial-sector transition models
- HSM / PKI migration patterns
- Resilience and rollback scenarios
- Supplier assessment criteria
- Q-TR finance-sector controls and evidence models
Standards & Sector Context
DORA · PCI DSS context · ISO 20022 security dependencies · NIST PQC standards
Collaboration Model
QSD is interested in research partnerships with banks, insurers, payment providers, HSM/PKI vendors and financial-technology organisations. Joint work can focus on high-assurance trust services, DORA-aligned resilience, transaction and messaging dependencies, supplier readiness and controlled migration of cryptographic infrastructure.