The State Bank is Modernising Payments on Ageing Cryptography

A conceptual illustration of post-quantum cybersecurity, featuring a golden padlock with a key inserted and surrounded by an interconnected molecular network floating above the State Bank of Pakistan building, set against a dark background with a massive, solid red circle.

Every rule the State Bank of Pakistan writes for the banks it supervises assumes the cryptography underneath will hold. That assumption now has an expiry date the rest of the world has already marked, and nothing in Islamabad’s rulebook acknowledges it.

Each time a salaried worker in Lahore is paid through RAAST, or a shopkeeper in Karachi accepts a QR payment, the transaction is protected by cryptography that the State Bank of Pakistan does not actually name anywhere in its own rulebook. That silence is not an oversight, because SBP governs cryptography the way most central banks do, by pointing at international standards rather than writing algorithms into its circulars. The difficulty this piece examines is narrower and more awkward: the standards it points at are precisely the ones the rest of the world has now scheduled for retirement, and the State Bank has issued nothing that admits the changeover is on its way.

Consider first what the published stack does contain, because it is more thorough than critics usually allow. BPRD Circular No. 05 of 2017, the Enterprise Technology Governance and Risk Management Framework for Financial Institutions, was issued in May 2017 with compliance required by mid-2018, and it binds every commercial bank, Islamic bank, development finance institution, and microfinance bank in the country. Layered on top of it sit the Payment Systems Department circulars, the RAAST participation criteria refreshed in February 2025, the digital onboarding and electronic know-your-customer rules, and a body of digital-payment security guidance. Read together, these documents oblige banks to use strong cryptography, sound key management, and hardened infrastructure, and they lean on PCI-DSS, ISO 27001, and ISO 20022 to supply the technical particulars.

The consequence of governing by reference is that the actual algorithms are inherited rather than chosen. A Pakistani bank meeting PCI-DSS today is running AES-256 for data at rest, RSA and elliptic-curve key exchange inside its TLS, and hardware security modules built around the same families. Every one of those choices is sound against a classical attacker and vulnerable to a sufficiently large quantum one, which is the entire point of the international migration now under way.

That migration is no longer aspirational abroad. The United States wrote it into law through Executive Order 14412 in June 2026, with federal encryption due to move by the end of 2030. The European Union, through the NIS Cooperation Group, wants national strategies and cryptographic inventories completed before the close of this year, high-risk infrastructure migrated by 2030, and everything else by 2035. NIST finalised the replacement standards, ML-KEM and ML-DSA, back in August 2024, and it intends to disallow the current public-key algorithms entirely after 2035. The Global Risk Institute’s 2025 threat report, published this March, put the odds of a cryptographically relevant quantum machine inside a decade at the highest level in the survey’s seven-year run.

None of this appears in the State Bank’s published material. There is no circular, no guidance note, and no working paper mentioning post-quantum readiness, cryptographic inventory, or crypto-agility. The gap matters more here than in most jurisdictions because of what SBP is simultaneously building. RAAST moved 742 million transactions worth over twenty-three trillion rupees in the first quarter of 2026 alone, and the central bank is piloting a digital rupee with the Japanese firm Soramitsu, a project Nikkei Asia reported in August 2025 and which Soramitsu itself calls the largest of its kind it has attempted, covering a population of 250 million. A retail digital currency and a national instant-payment rail are exactly the long-lived, high-value systems that a harvest-now-decrypt-later adversary would target first, copying encrypted traffic today to open it once the hardware arrives.

The remedy is not expensive, and the State Bank’s habit of regulating by reference is the very thing that makes it fast. A single Payment Systems Department circular could require every bank, electronic-money institution, and payment-service provider to complete a cryptographic inventory of its production estate by the end of 2027, using the CycloneDX cryptography bill-of-materials format that overseas regulators have already converged on. You cannot migrate what you have never mapped, and there is no public evidence any Pakistani bank has finished that mapping. The same circular could mandate hybrid ML-KEM-1024 with X25519 for new TLS endpoints and ML-DSA-87 for new signing keys inside RAAST and the digital-rupee pilot, so that the systems being built this year are not obsolete on delivery. A crypto-agility clause folded into the pending amendment of the 2017 framework would carry the principle into the permanent rulebook.

Because SBP steers the whole sector by updating the standards it cites, the day it revises those references is the day the migration begins for every bank at once. That leverage is rare, and at present it is sitting unused. The next piece in this series turns to NADRA, and to the question of whether the biometric records of the entire population are protected against an adversary who is content to wait.

Sourcing:
SBP BPRD Circular 05/2017;
PSD Circular 01/2025 (RAAST);
SBP Annual Payment Systems Review FY2024-25;
SBP Q1 2026 payment data;
Nikkei Asia (Aug 2025) on Soramitsu;
US EO 14412;
EU NIS Cooperation Group roadmap;
NIST FIPS 203/204/205;
GRI Quantum Threat Timeline Report 2025.

Muhammad Shaheer Bin Junaid
Written by

Muhammad Shaheer Bin Junaid is an applied cryptographer and security researcher working on post-quantum encryption, the migration toward it, and the attacks that test whether these systems actually hold. Alongside his research, he builds real systems, and brings an operator’s eye from years of running his own companies. His focus is what quantum-safe security means for the parts of the world the conversation tends to leave out. The author can be reached at contact@mshaheerbjunaid.com.