AI Briefing
KO

Why Toss Payments Introduced PQC 10 Years Before Quantum Computers Arrive

·2026.04.27 17:46

Key point

Toss Payments upgraded its security protocols over 4 years and fully adopted PQC in 2026.

Details

Toss Payments, considering its 20-plus-year-old PG legacy and tens of thousands of merchant environments, pushed forward security enhancements step by step rather than all at once.

In 2022, it became the first in the industry to introduce HTTP/3, boosting both performance and security together, and from 2022 to 2025, it classified weak TLS cipher suites by merchant, then sequentially removed them after prior notice and technical support.

During the same period, TLS 1.3 was also expanded endpoint by endpoint, completing full application in 2025. Clients that supported the new protocol were made to automatically use the safer channel, while existing merchants were not required to make any separate changes.

The background concerns stem from the worry that quantum computers could nullify existing public-key cryptography such as RSA and ECDSA. The author explains that preparations must be made against Harvest Now, Decrypt Later attacks, where encrypted data is stored now and decrypted later.

As the final step in this process, Toss Payments laid the groundwork for PQC adoption in 2025, and completed full rollout in April 2026. It provided the latest security channel as the default without requiring any merchant configuration changes, and also completed private-sector preemptive verification in step with the government's Post-Quantum Cryptography Transition Master Plan.

This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.

Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.