RBI urges payment providers to prepare for quantum-proof cybersecurity

RBI Deputy Governor Shirish Chandra Murmu said payment operators, banks and fintechs must build quantum-resistant cyber resilience. The central bank has formed a quantum-security expert committee and is developing a Digital Payments Intelligence Platform to tackle ecosystem-wide fraud risks.

— Source publishedFri, 11 Sept, 2026, 19:55 IST·First seen Fri, 11 Sept, 2026, 20:05 IST·Source Financial Express · BrandWagon

What happened

Reserve Bank of India · RBI Deputy Governor Shirish Chandra Murmu urged Indian payment operators, banks and fintechs to adopt quantum-proof cyber resilience.

Key facts

  • More than 14,000 fintech entities
  • Around 14% annualised growth
  • Over $40 billion cumulative fintech investment over the past decade
  • India is the world's third-largest fintech ecosystem

Why this matters

Target partnerships or acquisitions in post-quantum cryptography, payment fraud analytics and secure digital-payment infrastructure before regulatory standards harden.

What to watch

  • RBI quantum-security committee publishes recommendations, consultation papers or implementation timelines.
  • RBI issues cyber resilience, encryption, key-management or third-party risk requirements specifically referencing quantum-safe or post-quantum standards.
  • Launch details, data-sharing rules and participant mandates for the Digital Payments Intelligence Platform.
  • NPCI, card networks, major banks or payment aggregators announce post-quantum pilots, certificate changes or revised integration standards.
  • A material fraud event or cryptographic vulnerability accelerates supervisory deadlines and raises merchant compliance expectations.
  • Create a cryptographic inventory covering payment APIs, POS devices, tokenization systems, customer identity flows, certificates, hardware security modules and archived transaction data.
  • Ask acquiring banks, PSPs, gateways and cloud providers for their post-quantum cryptography roadmaps, migration dependencies, contract commitments and expected merchant obligations.
  • Prioritize crypto-agility in all payment and identity upgrades so algorithms, certificates and key lengths can be changed without replacing core applications or store hardware.
  • Assess exposure to ecosystem fraud controls: likely transaction holds, enhanced merchant KYC, device-risk scoring, mule-account screening and dispute-data sharing.
  • Budget for higher security assurance costs in multi-year payments contracts, especially for managed POS, gateway, token vault and fraud-management services.