RBI urges payment providers to prepare for quantum-proof cybersecurity
RBI Deputy Governor Shirish Chandra Murmu said payment operators, banks and fintechs must build quantum-resistant cyber resilience. The central bank has formed a quantum-security expert committee and is developing a Digital Payments Intelligence Platform to tackle ecosystem-wide fraud risks.
What happened
Reserve Bank of India · RBI Deputy Governor Shirish Chandra Murmu urged Indian payment operators, banks and fintechs to adopt quantum-proof cyber resilience.
Key facts
- More than 14,000 fintech entities
- Around 14% annualised growth
- Over $40 billion cumulative fintech investment over the past decade
- India is the world's third-largest fintech ecosystem
Why this matters
Target partnerships or acquisitions in post-quantum cryptography, payment fraud analytics and secure digital-payment infrastructure before regulatory standards harden.
What to watch
- RBI quantum-security committee publishes recommendations, consultation papers or implementation timelines.
- RBI issues cyber resilience, encryption, key-management or third-party risk requirements specifically referencing quantum-safe or post-quantum standards.
- Launch details, data-sharing rules and participant mandates for the Digital Payments Intelligence Platform.
- NPCI, card networks, major banks or payment aggregators announce post-quantum pilots, certificate changes or revised integration standards.
- A material fraud event or cryptographic vulnerability accelerates supervisory deadlines and raises merchant compliance expectations.
- Create a cryptographic inventory covering payment APIs, POS devices, tokenization systems, customer identity flows, certificates, hardware security modules and archived transaction data.
- Ask acquiring banks, PSPs, gateways and cloud providers for their post-quantum cryptography roadmaps, migration dependencies, contract commitments and expected merchant obligations.
- Prioritize crypto-agility in all payment and identity upgrades so algorithms, certificates and key lengths can be changed without replacing core applications or store hardware.
- Assess exposure to ecosystem fraud controls: likely transaction holds, enhanced merchant KYC, device-risk scoring, mule-account screening and dispute-data sharing.
- Budget for higher security assurance costs in multi-year payments contracts, especially for managed POS, gateway, token vault and fraud-management services.