The financial industry is entering a new stage of technological transformation. After years of focusing on ISO 20022 adoption, operational resilience and the modernization of payment systems, a new challenge is emerging with implications across the entire financial ecosystem: the transition to post-quantum cryptography (PQC).
In this context, SWIFT has defined a roadmap that includes the arrival of SwiftNet 8.0, an evolution of its network that will lay the foundations for preparing its infrastructure for the post-quantum transition. According to information published by the organization, SwiftNet 8.0 will be available in 2027, marking the beginning of a new stage in which financial institutions will need to progressively adapt their infrastructure and applications.
While it may appear to be just another technology upgrade, it represents one of the most significant changes of the coming years in terms of security, cryptography and financial messaging.
What is SwiftNet 8.0 and why is it more than a version upgrade?
The evolution towards SwiftNet 8.0 responds to an increasingly important need within the financial industry: preparing today’s cryptographic mechanisms for the future capabilities of quantum computing.
SWIFT has already indicated that this evolution incorporates the foundations required to move towards an infrastructure prepared for the progressive adoption of technologies and cryptographic mechanisms designed to withstand future quantum threats.
Financial institutions will need to review numerous components across their architecture:
- PKI infrastructure.
- Digital certificate management.
- Cryptographic algorithms.
- TLS channels.
- HSMs and cryptographic key custody devices.
- Integration platforms.
- Payment systems.
- Secure information transfer solutions.
- Components connected to the SWIFT network.
The challenge will not simply be to update SWIFT components, but to ensure that the entire technology chain involved in processing financial transactions can evolve towards more advanced cryptographic models designed for the post-quantum era.
The importance of testing environments for critical processes
Alongside this technological transformation, European organizations have increasingly emphasized the importance of validating the adoption of new cryptographic technologies in critical infrastructure at an early stage.
Initiatives such as Project Leap, led by the BIS Innovation Hub together with European central banks, have explored the application of technologies designed to withstand future quantum attacks in financial and payment systems. Its different phases have helped assess the feasibility of introducing post-quantum cryptography into financial environments and analyze areas such as performance, interoperability and crypto-agility.
The direction is clear: financial institutions will need to strengthen their testing and validation capabilities to minimize risk throughout the migration process.
In the context of financial messaging, this makes one recommendation increasingly relevant: having a dedicated environment for validating critical flows.
In practice, organizations should consider implementing a production-like environment that makes it possible to:
- Test SWIFT updates without impacting business operations.
- Validate new cryptographic mechanisms.
- Perform comprehensive regression testing.
- Simulate migration scenarios.
- Assess performance impacts.
- Verify integrations with connected applications.
The more closely this environment reflects production, the greater the ability to anticipate potential issues and ensure a controlled transition to SwiftNet 8.0.
How will post-quantum cryptography impact integration and secure file transfer platforms?
One aspect that is often underestimated is that the transition to post-quantum cryptography will not affect financial messaging platforms alone.
Enterprise integration and Managed File Transfer (MFT) solutions are part of the critical processes supporting international payments, treasury operations, regulatory exchanges and a wide range of banking processes.
The arrival of post-quantum cryptography will require organizations to review:
- Certificates and certificate authorities.
- Secure communication protocols.
- Authentication mechanisms.
- Digital signature schemes.
- Cryptographic dependencies embedded in applications.
- Integrations with payment and messaging platforms.
- Crypto-agility strategies.
Crypto-agility will be one of the key concepts in the coming years. This capability will enable organizations to replace or adapt cryptographic algorithms and mechanisms quickly, securely and in a controlled manner, while minimizing the impact on business services.
Financial institutions that begin identifying their cryptographic dependencies, inventorying their assets and defining migration roadmaps now will be better prepared to respond to future technological and regulatory requirements.
The post-quantum transition has already begun
For a long time, quantum computing was considered a distant threat. Today, that perception is changing.
One of the main risks identified by the cybersecurity community is known as “Harvest Now, Decrypt Later” (HNDL), a scenario in which malicious actors intercept and store encrypted communications today with the aim of decrypting them in the future, once quantum technology becomes sufficiently mature.
For this reason, governments, regulators and national cybersecurity agencies are accelerating the development of specific roadmaps for the migration to post-quantum cryptography.
One particularly relevant example is ANSSI, the French national cybersecurity agency, which has promoted initiatives aimed at accelerating the adoption of technologies resistant to quantum computing and has positioned the transition to PQC as a strategic priority for the coming years.
The conclusion is clear: post-quantum cryptography is no longer simply an innovation exercise, but a matter of technology planning, resilience and risk management.
NEVERHACK as a strategic partner for the transition to SwiftNet 8.0
The transition to SwiftNet 8.0 and the progressive adoption of post-quantum cryptography will require expertise across integration, financial messaging, enterprise architecture and cybersecurity.
In this context, NEVERHACK is positioned as a strategic partner to support financial institutions throughout the different stages of this evolution.
With more than 20 years of experience in Secure MFT & B2B Integration, over 100 specialists globally, and a team of architects, SMEs and consultants with extensive experience in banking and financial services, NEVERHACK helps its clients define, design and implement resilient architectures prepared for the regulatory and technological challenges ahead.
In addition to its capabilities in enterprise integration and secure information transfer, NEVERHACK has extensive experience within the SWIFT ecosystem, providing specialized services across financial messaging platforms, technology modernization, expert support, architecture design and strategic transformation projects.
As a cybersecurity company, NEVERHACK brings together two disciplines that will become increasingly inseparable over the next decade: integration and security.
The transition to the post-quantum era will not simply be a technological challenge. It will also be a challenge of resilience, governance and anticipation. Having a partner capable of combining expertise across both areas will be key to navigating this evolution securely and effectively.