01

FINMA and quantum computing: key points

  • FINMA expects banks, insurance companies, asset managers and financial market infrastructures to have a roadmap for quantum-safe encryption by mid-2027 at the latest.
  • The basis is not a new law but existing technology-neutral governance and risk-management requirements.
  • A FINMA survey shows that 72% of the institutions surveyed have not yet taken concrete action.
  • Five measures are central: strategy, risk analysis, protection of critical data, cryptographic agility and the involvement of external service providers.

02

Does my institution really need to act now?

Yes. FINMA officially put the issue on the agenda with Guidance 05/2026 on 9 July 2026 and expects institutions to address it early. Legally, FINMA relies not on a new provision but on the existing technology-neutral requirements for governance and risk management — the same principles that apply to every other operational risk. Institutions taking these obligations seriously cannot avoid addressing quantum computing, irrespective of whether capable quantum computers already exist.

03

By when must a roadmap be in place?

By mid-2027 at the latest, according to FINMA’s clear expectation. The roadmap does not have to be a standalone strategy and may form part of an existing cyber-risk strategy. What matters is the existence of an implementation plan adopted by the supreme governing body, whether the board of directors or executive management, with milestones and target dates for complete migration and the priority migration of critical business processes.

04

How far have Swiss financial institutions progressed?

Not far. Between November 2025 and January 2026, FINMA surveyed 60 authorised institutions. Seventy-two per cent had not yet planned or implemented measures for quantum-safe encryption, and only 8% had a concrete roadmap. At the same time, two-thirds of the institutions expected to be directly affected by the relevant cyber risks within seven years. There is therefore a clear gap between risk awareness and action, and FINMA intends the Guidance to close that gap.

05

What is a “harvest now, decrypt later” attack?

An attacker steals encrypted data today without being able to decrypt it immediately and waits until a sufficiently powerful quantum computer becomes available to break it later. This makes the risk real now, not only when cryptographically relevant quantum computers exist. Data requiring long-term protection, including client data, contracts and trade secrets that must remain confidential for years, is already exposed. FINMA recommends prioritising the migration of such data, often using hybrid encryption during the transition by combining a traditional algorithm with a quantum-safe one.

06

What does FINMA expect in concrete terms?

The Guidance identifies five areas for action:

  • Strategy and roadmap: adopted by the supreme governing body, with target dates for complete and priority migration.
  • Risk analysis and inventory: analyse all business processes, ICT systems and applications for the encryption, signature and authentication methods they use, including outsourced and externally procured services.
  • Protection of critical data: identify data requiring long-term protection and migrate it as a priority, taking “harvest now, decrypt later” into account.
  • Cryptographic agility: the ability to replace encryption algorithms flexibly in future, established as a requirement for all new ICT systems.
  • External service providers: embed cryptographic agility contractually in new outsourcing agreements; responsibility for outsourced functions always remains with the outsourcing institution.

07

What applies to outsourced IT services?

Responsibility remains with the outsourcing institution, as FINMA makes clear by referring to the existing Circular 2018/3 on outsourcing. Institutions should therefore engage actively with their software and data service providers, include cryptographic agility as a requirement in new contracts and add it promptly to existing outsourcing arrangements. Because migration projects generally need to be integrated into providers’ regular release cycles, early and long-term coordination with these partners is worthwhile.

08

Frequently asked questions

Does this affect me even though capable quantum computers do not yet exist? Yes. Because of “harvest now, decrypt later”, data transmitted or stored today that requires long-term protection is already exposed to risk.

Do I need to develop an entirely new strategy? No. The post-quantum cryptography roadmap can be integrated into an existing cyber-risk strategy, provided it contains milestones and target dates adopted by the supreme governing body.

What is a cryptographic inventory? A complete overview of all encryption, signature and authentication methods used across all systems, applications and infrastructure, whether operated internally, outsourced or procured as a service.

Is quantum-safe encryption alone sufficient, or is a hybrid solution required? Because there is limited long-term experience with post-quantum cryptography algorithms, specialist organisations currently recommend hybrid solutions combining traditional and quantum-safe methods, particularly for highly sensitive data.

What happens if I miss the mid-2027 deadline? The Guidance expresses FINMA’s expectations under existing governance and risk-management obligations. Failure to observe it may be addressed in ongoing supervision and when the adequacy of risk management is assessed.

Primary sources

Official sources for this article