PREPARING FOR MIGRATION / ADVANCED

Post-Quantum Readiness For PCI DSS Teams: Card Payments, POS And E-Commerce

Where quantum risk sits in card payments, why point-of-sale migration needs early planning, and the practical work PCI DSS teams can start now.

Checked against primary sources and independently reviewed on . Sources are listed at the end.

Teams responsible for PCI DSS already track a great deal of cryptography: the protocols protecting cardholder data in transit, the keys in hardware security modules, the certificates on payment pages. That makes them well placed to lead post-quantum readiness for the payment estate. It also raises a practical question: which parts of card payments are actually exposed to a future quantum computer, and which can wait?

This article answers that question using the most detailed public analysis available as of October 2026, Europol’s 2026 report on prioritising post-quantum migration in financial services, which is published under a CC BY 4.0 licence.1 It then sets out work PCI DSS teams can start now. For what PCI DSS itself requires on cryptography, see the PCI DSS cryptographic inventory article in the Cryptography Compliance section, which covers the requirement text and dates.

Where Public-Key Cryptography Sits In A Card Payment

Card payments mix two kinds of cryptography. Symmetric cryptography, where both sides share a secret key, is not broken by quantum computers in the same way. NIST’s draft transition guidance treats approved symmetric algorithms with at least 128-bit security, such as AES-128 and above, as meeting its lowest post-quantum security category.2 Public-key cryptography, used for signatures and key agreement, is the part at risk. The Europol report describes how each is used in a typical point-of-sale transaction.1

  1. Card Presented

    The customer presents a card at the terminal to start the transaction.

  2. Online Or Offline

    Online, card details go to the merchant’s bank for authorisation protected by symmetric cryptography. Offline, the terminal checks the card with public-key signatures, decides locally and stores the transaction to send on later.

  3. Routing (Online)

    The merchant’s bank sends the request through the card scheme to the issuing bank.

  4. Authorisation (Online)

    The issuing bank checks the details and returns a response.

  5. Completion (Online)

    The response travels back to the terminal, which approves or declines the payment.

A card transaction at the point of sale, adapted from Europol's 2026 financial services report (CC BY 4.0). Steps three to five describe online authorisation; the quantum-relevant step is offline authentication.

Citing EMVCo, which maintains the EMV chip specifications, the report identifies the main quantum threat to cards as recovery of a payment system or issuer private key. That would let an attacker produce counterfeit cards accepted for offline payments.1 Online authorisation, the dominant case, relies on symmetric cryptography and is not exposed in the same way. EMVCo’s own analysis, updated on 24 August 2026, takes the same view of where the exposure lies, says it does not expect quantum computing to threaten EMV infrastructure until at least 2040, and says it is considering how to reduce the risk for offline transactions.3

E-commerce is different. Payment pages and banking websites use TLS, whose key exchange is exposed to harvest now, decrypt later attacks. The report notes that data sent through such sites may be subject to retention requirements of several years, giving seven years in some jurisdictions as an example, which raises its shelf life.1

Why Point Of Sale Needs Early Planning

Europol’s report scores offline card authentication at the point of sale with its prioritisation framework, which the prioritisation article explains in full.

FactorScoreReason given
Shelf life3Issuer keys back cards that stay valid for several years
Exposure3Cards and terminals are publicly accessible
Severity1Limited to fraudulent offline payments; online payments unaffected
Quantum Risk Score2 (medium)Average of the three factors, rounded
Solution availability3At publication, EMVCo had not announced plans or a roadmap to add post-quantum cryptography to its specifications
Execution cost and time3Huge terminal fleets on typical 5 to 7 year upgrade cycles
External dependencies3Many parties, including PCI, EMV, CPACE, payment service providers and card and terminal makers
Migration Time Score3 (high)Average of the three factors, rounded
Europol's scoring of offline card authentication at the point of sale, adapted from its 2026 financial services report (CC BY 4.0).

The result is a medium-risk use case that the report still rates as high priority, because of its long dependencies and the cost of replacing terminals before the end of their planned life.1 Considering post-quantum hardware requirements early means new terminals bought in normal refresh cycles can be ready, rather than replaced again later.

For public websites, the same report finds the opposite pattern: medium risk but low migration time, because hybrid post-quantum key exchange is already widely supported.1 The no-regret moves article covers how to enable it.

Practical Work For PCI DSS Teams

The report recommends several immediate actions for point of sale.1 Combined with the general inventory and website guidance in this section, they give PCI DSS teams a concrete work list.

  1. Inventory the public-key infrastructure in card payment processes. Record which keys and certificates support offline authentication, terminal management and connections to acquirers and processors, with owners and expiry dates. The inventory article describes what to capture.
  2. Assess your reliance on offline payments. Understand where offline authorisation is used, including as a fallback during outages, and the impact a compromised signing key would have.
  3. Map the supply chain. List terminal makers, payment service providers, acquirers and processors, and track each one’s post-quantum roadmap.
  4. Consider interim controls. The report suggests evaluating mitigations such as enforcing online verification or adding detective controls for offline fraud.
  5. Join industry coordination. The report calls for a shared transition timeline across financial institutions, vendors and standards bodies.
  6. Pilot hybrid TLS on e-commerce front ends. Check the roadmaps of web servers, proxies, firewalls and CDNs in front of payment pages, test on a non-critical site, then roll out.
  7. Add post-quantum requirements to procurement. Terminals, HSMs and network appliances bought in the next refresh cycle may still be in service in the 2030s, when official timelines expect migration to be finished. As of January 2026, CISA lists hardware security modules and networking equipment among product categories still transitioning to post-quantum standards, so ask suppliers for dated roadmaps.4

How This Fits With Compliance

Post-quantum readiness and PCI DSS compliance share the same foundation: knowing which cryptography protects cardholder data, where it runs and who maintains it. Building the inventory once and using it for both purposes avoids duplicated effort. The exact PCI DSS requirements, and other financial sector rules such as DORA, are covered in Cryptography Compliance, with dates in the Regulatory Deadline Tracker.

Footnotes

  1. Europol, “Prioritising Post-Quantum Cryptography Migration Activities in Financial Services”, Publications Office of the European Union, 2026. Contributing authors: Oscar Covers, Thibaud Ecarot, Rebecca Gibergues, Jaime Gómez García, Francis Gorman, Imran Khan, Ivan Makarov, Sarah McCarthy, Michele Mosca, Iván Soto, Leila Taghizadeh and Jelena Zelenovic. Licensed under CC BY 4.0. The transaction flow and scoring table are adapted from it, with changes. europol.europa.eu ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8

  2. NIST, IR 8547 (initial public draft), “Transition to Post-Quantum Cryptography Standards”, 12 November 2024. csrc.nist.gov ↩

  3. EMVCo, “Quantum Computing and EMV Chip: What’s the Threat?”, 3 June 2025, updated 24 August 2026. emvco.com ↩

  4. CISA, “Product Categories for Technologies That Use Post-Quantum Cryptography Standards”, 23 January 2026. cisa.gov ↩

Knowledge Hub content is general information. It is not legal advice, a compliance certification, a guarantee of security or a substitute for an assessment of your own systems. Standards and rules change; check the sources for the latest position.