SWIFT’s next mandatory release is post-quantum, and there is no upgrade path to it from the version many banks are running. For context, SWIFT is the secure global messaging system used by banks to coordinate international wire transfers and transactions.
Quantum computing gets discussed as a thing that arrives in ten years, in a lab, in a headline.
It arrived on your calendar through a Belgian cooperative, with a version number.
The Signal
SWIFT publishes its release schedule in public. Anyone can read it. Almost nobody outside a bank’s operations team has.
Alliance and SwiftNet Release 7.9 exists to lay the foundations for release 8.0 and for post-quantum cryptography readiness. Release 8.0 is mandatory and is planned to be available at the end of July 2027. End of support for 7.9 lands 15 months after 8.0 ships. And there is no upgrade path from release 7.7 to release 8.0, which is why SWIFT says the majority of the community needs to deploy 7.9.
Read that last part again if you are a bank and your institution is on 7.7. The public date is 2027. Your date is now, because you have to land somewhere in between first.
This is not a law and no regulator is behind it. It is a network telling its participants what version they will be running. The distinction matters, because it changes who the deadline belongs to and how fast it moves.
The same shape is showing up elsewhere. The NSA’s CNSA 2.0 requires post-quantum algorithms in new acquisitions for national security systems starting in January 2027, which turns every defense supplier into a company with a cryptography deadline. NIST’s own guidance deprecates RSA and elliptic curve cryptography in 2030 and disallows them in 2035. In January 2026 the G7 Cyber Expert Group, working out of the US Treasury and the Bank of England, published a coordinated roadmap for the financial sector: awareness through 2026 and 2027, cryptographic inventory and risk assessment, migration of critical systems between 2030 and 2032.
Seven countries wrote that roadmap. A bank in Montevideo, Bogotá or São Paulo sits in none of those rooms and gets the same end of July 2027 anyway. The calendar was set somewhere else and delivered as a version number.
I spent 25 years selling migrations. I learned something in those years that I did not like at the time. The argument that moved a company was never the technology’s date. It was the end-of-support date on the invoice. I watched entire infrastructures move because a vendor stopped answering the phone, after years of security arguments that moved nothing.
This is that. Quantum computing has not broken any encryption. It has already changed a release schedule, a procurement rule, and the contents of a purchase order.
There is one more piece, and it is the part that makes 2027 late rather than early. Encrypted traffic captured today can be stored and opened later, when the machine exists. If a contract has to stay confidential for fifteen years and the machine arrives in eight, that contract is exposed now, not in eight years. Nothing you do in 2030 fixes what was copied in 2026.
The five forces do not arrive the way they get described. Quantum is not coming for your bank. It came for your version number, and the version number has a date on it.
The Application
SWIFT. Release 7.9 is available and is the required step toward 8.0. Release 8.0 is mandatory, planned for the end of July 2027. Support for 7.9 ends 15 months after that. Institutions running 7.7 cannot jump.
US national security supply chain. CNSA 2.0 requires post-quantum algorithms in new acquisitions of national security systems from January 2027. Vendors get the requirement before the law reaches anybody else.
NIST. RSA and elliptic curve cryptography deprecated in 2030, disallowed in 2035. That is the outer boundary, and every other date in this edition sits inside it.
G7 Cyber Expert Group. January 2026, a coordinated roadmap for the financial sector. Inventory first, migration of critical systems between 2030 and 2032. It sets no regulatory expectation and it is already functioning as the sector’s clock.
BBVA. Announced in late 2025 as the first European bank with a full strategy for the transition, built on a crypto-agility architecture it started developing in 2017. Nine years of work before the deadline was public.
The Noise
The debate about when a quantum computer will break RSA.
It is a real scientific argument and it is loud. In August, three researchers classically simulated IBM’s doped Clifford sampling experiment in 37.3 minutes, using a tensor 256 times smaller than IBM’s own estimate. Milestones keep getting walked back. Estimates move by decades depending on who is talking.
Now run the test. Take the last quantum hardware headline you read. Name one decision of yours that would have gone differently without it.
Nothing comes, and nothing should. The date of the machine is not your date. Your date is on a release note from your payments provider, and it did not move when that simulation was published.
The Question
Which of your systems is protected by encryption that has to hold for longer than your migration will take?
Now What?
Four things to go find out. Write down the answer each one gives you.
Which Alliance release your institution is running today, and the month it plans to be on 7.9. Ask operations, not the vendor. If the answer is 7.7, your window is shorter than the 2027 headline suggests.
Where RSA and elliptic curve cryptography actually live in your stack. Including mobile apps, third-party connections and anything embedded in hardware. NIST’s own migration project puts discovery alone at 12 to 24 months for a large enterprise, before migration starts.
What your critical suppliers will answer, in writing, about their post-quantum date. This is arriving as a procurement requirement well before it arrives as a regulation. Being out of a tender comes earlier than being out of compliance.
Which of your data has to stay secret past 2035. Contracts, custody records, personnel files, medical data. That is the list that harvest-now-decrypt-later is aimed at, and it is the only part of this that cannot be fixed later.
That is four questions and two meetings. The reason they have not been asked is that quantum computing sounds like somebody else’s subject.
What I’m Watching
Post-quantum requirements in commercial tenders. Defense already has them. The week they show up in a routine supplier questionnaire, the migration stops being a security project and becomes a sales problem.
The certification gap. As of early 2026 no hardware security module vendor had completed a FIPS 140-3 Level 3 validation with post-quantum algorithms inside the validated boundary. Banks can be ready and still be blocked by paperwork.
The bill. Nobody has published what the 15-month window actually costs an institution. The first one to publish it will set the number everybody else budgets against.
This is the Javier D’Ovidio Newsletter. Emerging tech without the hype. Real signals for strategic decisions.
If this edition helped you see something you were not seeing before, forward it to one leader who needs to be in the conversation.
Subscribe at newsletter.javierdovidio.com so you catch the next edition. Follow Javier D’Ovidio on LinkedIn for daily signals on the convergence.
Javier D’Ovidio Javier D’Ovidio Newsletter
How I make this
The judgment in this newsletter is mine. Every edition is the output of a framework I have built over 25 years in technology. I map what is happening across five forces. Then I filter signal from noise, and run each thing through one question: how does this serve life.
I use AI as a tool in that process. It helps me sweep sources across the five forces and draft. It does not decide anything. I choose the topic. I verify every figure and claim against primary sources before it goes out. I call what is signal and what is noise, and that call rests on having watched several technology waves arrive and get dismissed. I edit every edition against my own writing standards. The framework and the final call are mine, and I am accountable for every claim here.
That is the point of this newsletter. AI is a tool a person uses. The person stays responsible for what it produces.


