RBI's Deputy Governor Shirish Chandra Murmu urged payment system operators to begin quantum-proofing India's financial infrastructure at GFF 2026. This shifts the central bank's public stance from studying quantum risks to demanding industry action, despite no immediate threat. The problem is "harvest now, decrypt later"—today's encrypted data becomes readable years from now, making long-cycle infrastructure vulnerable.
How We Got Here
RBI constituted an expert committee on a quantum secure financial ecosystem earlier this year. Deputy Governor Murmu's keynote at the Global Fintech Fest in Mumbai goes beyond that, asking the industry to move from study to action.
The Numbers
- Murmu explicitly named the "harvest now, decrypt later" risk, where attackers store current encrypted data for future decryption by quantum computers.
- India's UPI processed 24,162 crore transactions worth ₹314 lakh crore in financial year 2025-26, making up 85% of the country's digital payments volume.
- India accounts for almost half the world's real-time payment transactions, scaling the quantum resilience challenge globally.
- Murmu cited Project LEAP by the Bank for International Settlements Innovation Hub as a precedent, which replaced traditional digital signatures with post-quantum cryptography.
- He emphasized that quantum resilience must be an "ecosystem capability," requiring banks, payment operators, fintechs, and tech providers to move together.
What Happens Next
🇮🇳 Why This Matters for India
For Indian payment system operators in Bangalore and Pune, this is a multi-year, multi-crore infrastructure overhaul, impacting vendor selection and R&D budgets immediately.
The Take
The call for "ecosystem capability" implies RBI wants private players to solve a collective action problem without clear incentives. This will either force large banks to lead with heavy R&D spends or delay crucial progress until a mandated standard or subsidy appears.
Source:
MediaNama ↗