Stickybit.← Post-quantumPortuguêsRegulatory analysis · Apr 2026, revised Sep 2026
Analysis · the central bank and the lock switch

Why the central bank should require the switch before 2028.

Brazil’s central bank (BACEN) has not yet published any rule on post-quantum cryptography. But open banking, Pix, the privacy law and Drex all depend on the locks a quantum computer opens, and other central banks have already moved. This page is our projection, not an announcement. Its point is practical: the switch takes 24 to 36 months, and the window is shorter than that.

projection · not a BACEN announcement
Specimen · will you make it in time?

—ready between
0months of margin to the 2028 requirement
0fronts that affect you
Start with

    The timeline milestones are our April 2026 projection, based on the pace at which BACEN has followed other international recommendations. The 24-to-36-month duration is our estimate for a sizeable institution. Check the dates against BACEN’s official communications.

    In everyday terms

    The stamp that loses its evidentiary value.

    A Pix payment receipt is digitally signed. The signature works like a notary’s stamp: years later, in a dispute or a lawsuit, it proves that the transfer happened, that way, at that time.

    Once a quantum computer exists, that stamp faces two risks. Backwards: whoever recovers the private key from the public one can fabricate "old" receipts that look legitimate, and then no old receipt proves anything on its own. Forwards: every new signature must be made with the new lock from day one.

    The second risk is solved by switching the signature algorithm (ML-DSA, the NIST standard). The first is harder: it requires re-signing or time-stamping the old archive before the key falls. None of this is quick, and none of it starts without a list of what exists.

    signature made today works as evidence TODAY the computer arrives the key can be recovered "old" receiptscan be fabricated
    A signature made today works as evidence until the day its key can be recovered. After that, "old" receipts can be fabricated.
    The five fronts

    Where the requirement should land first.

    1. Open banking: the country’s largest surface

      Statements, balances, investments and credit data travel between institutions with today’s connection padlock (TLS with elliptic curves). Whoever records those connections now can open them when the computer arrives: harvest now, decrypt later.

      Example: a 12-month statement shared today with a fintech, with consent, becomes readable to whoever recorded the connection.

    2. Pix and DICT: signatures that must hold for years

      Institutions authenticate to the Pix key directory with ICP-Brasil certificates (elliptic curve or RSA), and queries and receipts are signed. Their evidentiary value must last for years.

      Example: a receipt disputed in 2031 must still prove that the 2026 transfer happened.

    3. Privacy law: "suitable technical measures"

      Article 46 of Brazil’s data protection law (LGPD) requires suitable technical measures to protect personal data. With NIST standards published in 2024 and experts warning publicly, keeping long-lived data under the old lock alone becomes hard to defend later.

      Example: the question in a 2030 class action will be "you knew in 2026, what did you do?".

    4. Drex: sophisticated but classical cryptography

      Brazil’s digital real uses zero-knowledge proofs for confidentiality between participants, on elliptic curves. There is no ready post-quantum drop-in: migrating Drex means rethinking the project’s cryptography, and that drags the whole supplier chain along.

      Example: a custody supplier to a participating bank must be ready before the announcement, not after.

    5. Other central banks have moved

      According to our April 2026 survey, the BIS, the ECB, the Fed, Singapore’s authority and the Bank of Canada had published studies, pilots or guidance on the subject. BACEN had no specific public document yet.

      Example: a regulator known as technically strong is unlikely to be last in the G20.

    regulatedinstitution1 · Open banking2 · Pix and DICT3 · Privacy law4 · Drex5 · other central banks
    The five fronts around a regulated institution.
    Other regulators

    Who has already moved.

    AuthorityWhat it didStatus
    BIS (the central banks’ bank)Study on post-quantum cryptography for central bankspublished in 2024
    ECB (euro area)Pilot with the Bundesbank and Banque de Franceactive in 2024–2025
    Federal Reserve (US)Task force and guidance for banksin development
    MAS (Singapore)Guidance on quantum readiness for financial institutionspublished in 2024
    Bank of CanadaTechnical study on migration in settlementpublished in 2023
    BACEN (Brazil)No specific public documentpending as of Apr 2026

    Survey from the original version of this analysis (April 2026). Check each item against each regulator’s primary source before citing it.

    The projected timeline

    When the rule should arrive.

    BACEN tends to adopt international recommendations with an 18-to-24-month lag, and open banking took about 18 months from consultation to resolution. At that pace, and with the BIS study in 2024, the projection below is our reading.

    It could come 6 to 12 months earlier after a major cryptographic leak, a quantum breakthrough announcement or a rushed rule from another G20 regulator. It could also slip, but every year of delay shortens the window for whoever has not started.

    WhenWhat we expect
    Q2–Q3 2026BACEN technical notice on emerging risks in cryptography, no obligation.
    Q4 2026Public consultation on cryptographic inventory at institutions.
    Q1–Q2 2027Resolution with a mandatory inventory schedule and migration plan.
    H2 2027New certificates with hybrid support.
    2028Mandatory switch on critical open-banking and DICT channels.
    2029End of old locks in new services; the quantum computer enters the window of possibility.
    What to do now

    Four things before the first notice.

    1. Cryptographic inventory

      Where RSA, elliptic curves and Diffie-Hellman appear: certificates, SSH keys, signed tokens, ICP-Brasil certificates, API keys, key vaults (HSMs), payment modules. Automated, not a spreadsheet.

    2. Exposure score

      For each system, how long the data must stay secret: 7 years of transactions, 20 of medical records, contracts valid in 2040. What must stay secret beyond 2029 is already exposed today.

    3. Hybrid exchange

      Agree on keys with the old lock and the new one (ML-KEM) at the same time, as Google, Cloudflare and iMessage already do. It protects against the quantum computer and against a flaw in the new lock.

    4. Key governance

      Which keys exist, where they live, who has access, when they were rotated, with which algorithm and validity. Most institutions do not know, and that is the first debt to pay.

    The inventory and exposure score in 24 hours.

    The free assessment delivers the critical inventory, a 90-day roadmap and an investment estimate, as a PDF.

    Ask for the assessment →
    Three words on this page
    Cryptographic inventory

    The list of where cryptography is used and of which kind. Nothing gets switched without it, and it is what the regulator should ask for first.

    Evidentiary value

    An old signature’s ability to keep proving something. It disappears once its key can be recovered.

    Hybrid exchange

    Two locks on the same door: the old one and the new one. Opening one is not enough.

    Limits

    Where this could be wrong.

    It is a projection

    None of the dates on this page was announced by BACEN. It is our reading of precedents, and it could be wrong either way.

    The 18-to-24-month pace is our observation

    We took it from earlier cases (Basel, open banking, privacy law in the financial sector). It is not a written rule.

    The international survey needs checking

    The table of other regulators comes from the April 2026 version of this analysis. Check the primary sources before using it in an official document.

    24 to 36 months is for a sizeable institution

    A small institution with fewer systems may switch faster. A large one, with legacy systems and suppliers, may take longer.

    See also

    ← Post-quantum · stickybit.com.br

    Sources