Skip to content

Banking

HNDL for banking: transaction archives and Mosca

Transaction records, wire audit logs, and M&A diligence materials often require confidentiality for 7–25 years — making Mosca inequality a present-day planning question.

Banking data shelf-life chart.

Key terms

Mosca inequality, HNDL, crypto agility — see the HNDL hub.

Why banks face HNDL pressure

Data classTypical shelf-life (X)Collection risk
Wire transfer archives7–15 yearsBackup exfiltration
M&A diligence10–25 yearsData room copies
Core banking backups15+ yearsRansomware targets
API transaction logs3–7 yearsCloud misconfiguration

When X + Y > Z (migration 5–8 years, quantum timeline ~10 years), HNDL exposure exists today.

PCI-DSS 4.0 connection

PCI-DSS 4.0 emphasizes crypto agility — knowing what algorithms protect cardholder data and planning migration before QSAs ask. Inventory TLS, JWKS, and email STARTTLS; map to IR 8547 tiers.

See PCI-DSS 4.0 guide and banking HNDL framework.

90-day plan for regional banks

  1. Baseline scan on external TLS + JWKS (bank scenario)
  2. Mosca score on longest-retained transaction archives
  3. Export CBOM for QSA review
  4. Pilot hybrid TLS on member-facing API gateway

Banking solutions · Free mini-assessment

Continue on the Q-Day hub: Harvest now, decrypt later guide

References & further reading

Authoritative primary sources cited in this article. Summaries are our own — follow links for full context.

Last verified 2026-06-04

See your exposure with evidence

Run a live PQC inventory scan, export a CBOM, and verify signed reports independently.