ATHENS — The European Union Agency for Cybersecurity published guidance Monday urging banks, payment providers and blockchain platforms to migrate to post-quantum cryptography by 2030 for critical systems.

The recommendation follows recent warnings from EU regulators that advances in quantum computing could eventually break the cryptographic algorithms securing Bitcoin and other digital assets. ENISA highlighted the threat of "harvest now, decrypt later" attacks, in which encrypted data is stored today for future decryption, as justification for immediate planning.

The agency directed institutions toward standards finalised by the US National Institute of Standards and Technology, including the ML-KEM and ML-DSA algorithms. Financial firms should complete an inventory of vulnerable systems within a year and prioritise long-lived data and high-value transaction infrastructure.

ENISA's guidance aligns with the European Commission's coordinated roadmap on the transition to post-quantum cryptography, which sets 2030 as the deadline for high-risk use cases and 2035 for the wider economy. The agency stressed that migration timelines for large banks could span several years.

Industry groups, including the European Banking Federation, have warned the shift will require significant investment and coordination across payment networks. ENISA acknowledged the complexity but cautioned that delay would leave sensitive financial and personal data exposed once large-scale quantum computers mature.