RingSafe Infrastructure Brief — Post-Quantum Payments — 22 May 2026
What was announced
NPCI’s engineering team disclosed three concrete milestones:
- Switch infrastructure now supports ML-KEM-768 in hybrid mode alongside X25519 in test environments, using a BoringSSL fork patched with the official NIST FIPS 203 reference.
- A small set of issuing banks are running the ML-KEM-enabled handshake in shadow mode, with handshake telemetry compared against the production X25519 baseline.
- The roadmap calls for full production rollout on switch-to-issuer links by Q4 2027, with switch-to-merchant aggregator links following in 2028-29.
Why this matters now
The conventional wisdom that quantum threats are “10-20 years away” misses two operational realities. First, the harvest-now-decrypt-later attack model means encrypted payment metadata captured today is a future-decryption target the moment a sufficiently large quantum computer is deployed. Second, the migration itself takes years; an institution that waits until quantum is imminent has already lost the window to migrate safely.
NIST finalised the ML-KEM (Kyber), ML-DSA (Dilithium), and SLH-DSA (SPHINCS+) standards as FIPS 203, 204, and 205 in mid-2024, and the federal CNSA 2.0 directive requires NSS systems to migrate by 2033. The payments industry, with its long-lived data and complex interconnects, sensibly moves earlier.
RingSafe analysis
The NPCI announcement is a market signal more than an engineering milestone. Once the central switch supports hybrid PQ-TLS, every bank’s CIO will face a 24-month roadmap conversation about migrating their own internal services. This propagates a quantum-safe expectation across the Indian BFSI tech estate.
The tactical action for Indian CIOs is not to deploy ML-KEM tomorrow, but to inventory their cryptography. Most banks cannot today produce a list of every internal service that uses RSA-2048 vs ECDSA-P256, what library version, what cipher suites, what handshake duration — and you cannot migrate what you cannot enumerate.
CIO action list (next two quarters)
- Run a CBOM (Cryptographic Bill of Materials) discovery scan across the estate — CycloneDX 1.6 adds dedicated crypto-asset support.
- Classify cryptographic uses by lifetime sensitivity: a TLS session is short-lived; a customer document signature lives 7+ years.
- Engage your TLS terminator vendors (F5, Citrix, AWS, Cloudflare) on their PQ-TLS roadmap.
- Update procurement contracts to require crypto-agility clauses for new infrastructure.
RingSafe technical deep-dive: Post-Quantum Cryptography Migration — Engineering Guide for 2026.
Get a DPDP gap assessment
Free 30-minute call. We map your data flows against DPDP §8 obligations and tell you exactly which gaps to fix first. Auditor-defensible output.