# Fedwire and Post-Quantum Cryptography: Federal Reserve Direction

**Source**: https://quantumsequrity.com/blog/fedwire-pqc
**Category**: Industry & Use Cases

---

[← Back to Blog](../../blog.html) Industry & Use Cases

# Fedwire and Post-Quantum Cryptography: Federal Reserve Direction

11 min read

Fedwire Funds Service is the Federal Reserve's real-time gross settlement system. It is the wire transfer rail that moves dollars between US depository institutions one transaction at a time, with finality, in seconds. Fedwire processed roughly 200 million transfers worth around 1.1 quadrillion dollars in 2024 across roughly 9,000 participating institutions. When a bank says "wire transfer," it usually means Fedwire (for US dollars) or CHIPS (for high-value international clearing through The Clearing House).

Fedwire's cryptography is the responsibility of the Federal Reserve Banks. The system runs on a private network called FedLine that authenticates participants using digital certificates. Like SWIFT, Fedwire is migrating to ISO 20022 message formats. And like every other piece of critical financial infrastructure, the Fed is on the clock for a post-quantum cryptography migration before any cryptographically relevant quantum computer arrives.

## What Fedwire Is

Fedwire Funds is one of two main settlement rails operated by the Federal Reserve. The other is FedACH, which handles batch ACH credit and debit transfers, and FedNow, which provides instant payments. Read more on [ACH transfers and PQC here](ach-transfers-pqc.html).

Fedwire Funds is unique because every transfer is gross (not netted) and settles immediately with finality. There is no clawback, no provisional credit, no batch window. When the Fed posts a Fedwire credit to your account, the funds are yours. This is why Fedwire is used for the most sensitive or time-critical payments: real estate closings, securities settlements, large corporate disbursements, and central bank operations.

Participating institutions connect through FedLine. There are several FedLine access methods (FedLine Direct, FedLine Advantage, FedLine Web, FedLine Command), each with different cryptographic and operational requirements. All require certificate-based authentication.

## Fedwire ISO 20022 Migration

In March 2025 the Federal Reserve completed the migration of Fedwire Funds Service from a proprietary message format to ISO 20022. The migration was originally planned for 2023 and was delayed multiple times. The new format uses the ISO 20022 pacs.008 (FI to FI customer credit transfer), pacs.009 (financial institution credit transfer), camt.054 (bank-to-customer debit/credit notification), and other standard message types.

The migration was a major undertaking for participating banks. Every payment hub that touched Fedwire had to be upgraded to read and produce the richer ISO 20022 schemas. The richer data is one of the main benefits: structured remittance information, more flexible address formats, enhanced AML and sanctions screening data.

The migration to ISO 20022 did not change the cryptography. Fedwire continued to authenticate participants and sign messages using classical algorithms. RSA and ECDSA in TLS, certificate-based mutual authentication, and traditional key wrapping. Read more in our [NIST FIPS guide](nist-fips-guide.html).

The PQC migration is the next step, separate from but enabled by the ISO 20022 work.

## Federal Reserve Direction on Post-Quantum Cryptography

The Federal Reserve has been publicly engaged on quantum risk since at least 2022. Federal Reserve staff have spoken at NIST workshops, at the BIS Innovation Hub, and at industry conferences about the importance of crypto-agility in financial infrastructure.

Three documents matter most:

1. **OMB Memorandum M-23-02** (November 2022). This is a White House Office of Management and Budget memo that requires all federal agencies, including the Federal Reserve System, to inventory their cryptographic systems and report on migration timelines. The Fed is technically not under OMB but follows the same direction.
2. **Federal Reserve Working Paper series.** Several papers from 2023 and 2024 explored quantum risk to financial market infrastructure, including a 2024 paper from the New York Fed staff that explicitly called out Fedwire and the broader RTGS rails.
3. **NIST IR 8547** (January 2025). NIST's transition to post-quantum cryptography standards. This document gives the operational guidance that the Fed and other agencies use for migration planning.

The Fed has not published a hard deadline for Fedwire PQC migration. The implicit deadline is the same one that NSA CNSA 2.0 sets for federal cryptographic systems: full migration by 2035, with hybrid mode in place earlier.

## The Specific Risks to Fedwire

**Authentication forgery.** If an adversary breaks RSA or ECDSA, they can forge FedLine certificates and impersonate a Federal Reserve Bank or a participating institution. Internal four-eyes controls and reconciliation would catch this within minutes, but a sophisticated attack with privileged access could move funds before reconciliation closes the window.

**Confidentiality of message content.** Fedwire messages include details about the originator, beneficiary, amount, purpose, and any structured remittance data. This is highly sensitive commercial information. A harvest-now-decrypt-later adversary collecting Fedwire traffic today could decrypt it after Q-Day and obtain a multi-decade record of US dollar wholesale payments.

**Long-term settlement records.** Federal Reserve records are subject to retention requirements under multiple statutes. The data sits in archives for many years, encrypted under TLS session keys that are themselves protected by RSA or ECDH. Once the asymmetric algorithm breaks, every archived session key is recoverable.

Read more in [Harvest Now, Decrypt Later](harvest-now-decrypt-later.html) and [Why RSA-2048 Will Break](why-rsa-2048-will-break.html).

## What FedLine Direct Looks Like Today

FedLine Direct is the highest-tier connection method. Banks that move large volumes typically use it. The connection is a VPN tunnel to a Federal Reserve data center using IPsec with classical key exchange. The participant authenticates using a hardware token and a USB-attached HSM-style device that stores the participant's private key.

The operational requirements include:

- TLS 1.2 minimum, TLS 1.3 preferred.
- Cipher suites limited to AES-256 and AES-128 in GCM mode.
- Key exchange via ECDHE on NIST P-256 or P-384 curves.
- RSA-2048 minimum for participant certificates, RSA-4096 for some connection profiles.
- Certificate revocation checking via OCSP stapling.

The PQC migration target is hybrid TLS using ML-KEM-768 alongside X25519, with ML-DSA-65 alongside ECDSA P-256 for participant certificates. This matches the IETF draft for hybrid TLS (draft-ietf-tls-hybrid-design and the published RFC 9295 successor). Read more in [Hybrid Encryption](hybrid-encryption.html).

## What Banks Should Be Doing

If you are an operations or security lead at a Fedwire participant, the to-do list looks like:

1. **Cryptographic inventory.** Every system that touches FedLine. Every certificate. Every key. Map it.
2. **HSM vendor roadmap.** Talk to your HSM vendor (Thales, Utimaco, Futurex, Atos, IBM) about ML-KEM and ML-DSA support timelines. Most have shipped FIPS 203 / 204 firmware in 2025.
3. **Payment hub vendor roadmap.** Vendors like Volante, ACI Worldwide, Finastra, Bottomline. Ask when their Fedwire connector will support hybrid PQC.
4. **Test the test environment.** The Fed operates a Fedwire test environment for participants. Once the Fed enables hybrid signatures in test, the participant has to be ready to follow.
5. **Internal audit and reporting.** OMB M-23-02 requires inventorying cryptographic systems and reporting progress. Even non-federal banks should adopt similar discipline because regulators (OCC, FRB, FDIC) are starting to ask about it in supervisory exams.

## CHIPS, FedNow, and the Bigger Picture

CHIPS, the privately operated The Clearing House Interbank Payments System, settles around 1.6 quadrillion dollars annually in international dollar payments. It runs on its own private network with similar cryptography to Fedwire. The Clearing House has its own PQC migration plan and roughly the same timeline.

FedNow, the Fed's instant payments service launched in July 2023, was designed with crypto-agility in mind from day one. The Fed has confirmed in public communications that FedNow's cryptographic stack will support hybrid PQC at the same time as or before Fedwire Funds.

State and regional payment networks (Visa, Mastercard, regional ACH switches) have their own timelines, generally trailing the Fed by one to two years.

## NIST IR 8547 and Federal Agency Guidance

NIST IR 8547, "Transition to Post-Quantum Cryptography Standards," published in January 2025, is the practical reference document for federal agencies and federally regulated institutions. The document spells out:

- The expected timeline for retiring classical algorithms.
- Hybrid mode as the recommended transition strategy.
- Algorithm-by-algorithm guidance on which classical primitives to deprecate first (RSA-1024 first, RSA-2048 next, ECC P-256 around the same time).
- Specific guidance for high-assurance applications including financial market infrastructure.

The Federal Reserve System, while technically independent, follows NIST IR 8547 as the de facto standard for its own systems. Fedwire, FedNow, and FedACH all fall under this guidance.

## Crypto-Agility as the Operational Goal

Beyond simply migrating to ML-KEM and ML-DSA, the Federal Reserve and other operators of financial market infrastructure are working toward "crypto-agility": the ability to swap cryptographic algorithms with minimal disruption when new attacks emerge or new standards are published. Crypto-agility is itself a multi-year effort because it requires:

- Clean separation between cryptographic logic and application logic.
- Versioned protocol envelopes that can negotiate algorithm choices.
- Automated certificate management infrastructure that can issue under multiple algorithm OIDs.
- Test harnesses that exercise every algorithm path.

A Fedwire participant that achieves crypto-agility before Q-Day is positioned to handle whatever comes next, not just the current PQC migration.

## Bank Supervisory Expectations

Although the Federal Reserve has not issued a formal PQC mandate to commercial banks, supervisors at the OCC, FRB, and FDIC have begun asking about cryptographic inventory and post-quantum migration plans during examinations. The questions are typically:

- Does the bank maintain a current inventory of cryptographic algorithms and protocols in use?
- Does the bank have a written plan to migrate from RSA and ECC to NIST-standardized post-quantum algorithms?
- Does the bank track third-party vendor PQC roadmaps for systems the bank depends on (HSMs, payment hubs, software vendors)?
- Does the bank have a key ceremony procedure that supports hybrid PQC migration?

Banks that cannot answer these questions affirmatively are not yet in violation of any specific regulation, but supervisors view this as a gap that will tighten over time. Forward-looking banks are building the inventory and migration plan now, not in 2030.

## Operational Resilience and the Fedwire Outage History

Operational resilience is the framework banking regulators use to evaluate whether a bank can continue critical operations through disruption. The OCC, Federal Reserve, and FDIC published joint operational resilience guidance in 2020 that explicitly includes cybersecurity events as a category of disruption that banks must plan for. Cryptographic compromise, including a future quantum break of classical algorithms, fits inside this framework.

Fedwire itself has had operational outages, including a notable February 2021 incident that disrupted Fedwire Funds for several hours during the late afternoon settlement window. The Fed published a post-incident report and tightened its operational procedures. The cryptographic posture of Fedwire is one input into the broader resilience picture: a system that depends on classical cryptography that will eventually fail to a quantum adversary is, by definition, less resilient over the long term than a system that has migrated to PQC.

For banks subject to operational resilience expectations, documenting a credible PQC migration plan is part of the broader resilience case. Examiners reviewing the operational resilience program for a Fedwire participant should be able to see how the cryptographic stack will hold across the next two decades, not just the next two years. The migration plan, vendor commitments, and contingency arrangements all become evidence in this conversation.

## FAQ

**Has the Federal Reserve named a PQC migration deadline?**
Not publicly. The implicit deadline tracks NSA CNSA 2.0 and OMB M-23-02, both of which target 2035 for full migration of public-key cryptography in federal systems.

**Is Fedwire's PQC migration tied to the ISO 20022 migration?**
They are independent. ISO 20022 changed the message format. PQC will change the cryptographic envelope. The two layers can be migrated separately. The ISO 20022 work, completed in March 2025, did not include PQC.

**What about FedNow?**
FedNow was designed with crypto-agility in mind. The Fed has indicated FedNow will receive PQC support concurrently with or ahead of Fedwire Funds.

**Are participating banks required to do anything yet?**
Federal banking regulators have not issued a formal mandate. Supervisory questions have started appearing in exams. OMB M-23-02 applies to federal agencies; banks should adopt similar inventory and reporting discipline voluntarily.

**Can I use QNSQY for Fedwire-related data?**
QNSQY is a general-purpose post-quantum cryptography tool. It is appropriate for archives, backups, and out-of-band data exchange. It does not connect to Fedwire and is not a substitute for FedLine.

**How does the Fedwire migration relate to SWIFT's PQC work?**
SWIFT has its own PQC roadmap, published in part through SWIFT Operational Bulletins and the SWIFT Customer Security Programme. SWIFT messaging touches Fedwire indirectly because cross-border dollar payments often use SWIFT instructions that settle through Fedwire or CHIPS. SWIFT has indicated alignment with NIST FIPS 203 and 204 and a hybrid migration approach. Banks operating in both networks should coordinate their migration timelines so that the SWIFT-to-Fedwire handoff remains cryptographically consistent.

**What does FedLine Solutions Suite include for PQC?**
FedLine Solutions Suite is the umbrella for the FedLine connection products. As of early 2026 the FedLine product documentation does not mention PQC by name, but the Federal Reserve has confirmed in industry briefings that FedLine endpoints will support hybrid TLS once the Fed completes its internal validation. Participating banks should monitor Federal Reserve Financial Services bulletins and FRB Operating Circular 5 amendments for FedLine cryptographic updates.

## How QNSQY Fits

QNSQY does not connect to Fedwire and does not produce Fedwire messages. But banks generate vast quantities of supporting data that feeds into and out of Fedwire: reconciliation reports, sanctions screening hits, AML alerts, audit trails, and quarterly call reports. Many of these need to be retained for multiple years and contain the same kinds of sensitive content as the wire messages themselves.

QNSQY uses ML-KEM-512/768/1024 in hybrid with X25519 for key encapsulation, ML-DSA-44/65/87 in hybrid with Ed25519 for signatures, AES-256-GCM for content encryption, and Argon2id for password-based key derivation. The .qs polyglot file format is designed to be readable for decades and to survive cryptographic algorithm transitions. Banks can use QNSQY to encrypt the offline archives that support their Fedwire compliance reporting. Read more in [Encrypt Before Cloud Upload](encrypt-before-cloud-upload.html).

## Sources

- Federal Reserve, "Fedwire Funds Service" — https://www.federalreserve.gov/paymentsystems/fedfunds_about.htm
- Federal Reserve, "Fedwire ISO 20022 Migration" — https://www.federalreserve.gov/paymentsystems/fedwire-iso20022-implementation.htm
- OMB Memorandum M-23-02, "Migrating to Post-Quantum Cryptography" — https://www.whitehouse.gov/omb
- NIST IR 8547, "Transition to Post-Quantum Cryptography Standards" — https://csrc.nist.gov
- NIST FIPS 203 (ML-KEM) and FIPS 204 (ML-DSA), August 2024 — https://csrc.nist.gov
- Federal Reserve, "Operating Circular 5: Electronic Access" — https://www.frbservices.org/resources/rules-regulations/operating-circulars.html

## Related Articles

- [What Is Post-Quantum Cryptography](what-is-post-quantum-cryptography.html)
- [Harvest Now, Decrypt Later](harvest-now-decrypt-later.html)
- [Why RSA-2048 Will Break](why-rsa-2048-will-break.html)
- [Hybrid Encryption](hybrid-encryption.html)
- [NIST FIPS Guide](nist-fips-guide.html)

---

### Protect Your Data Before Q-Day Arrives

QNSQY's NIST-standardized post-quantum encryption protects files against both current and quantum-era threats.

[Try QNSQY](../../pricing.html)
