FINMA Guidance 05/2026: From Quantum-Risk Awareness to a PQC Roadmap

ByYannick Hänggi,Samuel Egger
Time to read: 4 minutesBanking, Article
OverView

In its Guidance 05/2026 of 9 July 2026, FINMA is signaling how existing governance, operational-risk and resilience requirements should be applied to quantum-related cryptographic risks. FINMA recommends that Swiss financial institutions develop a PQC roadmap by mid-2027 at the latest. This requires board-level support, cross-functional mobilization, cryptographic and business transparency, and a prioritized migration roadmap toward quantum-safe cryptography and crypto-agility.

FINMA makes quantum risk a management topic

FINMA’s Guidance 05/2026 of 9 July 2026 on quantum computing sends a clear message to the Swiss financial sector. Post-quantum cryptography (PQC) risks are no longer a distant technology topic. They are becoming a governance, resilience and cyber-risk management issue.

As discussed in Horn & Company’s earlier article on quantum computing and business-model analysis, the technology affects both future opportunities and today’s security assumptions. In the context of the recent FINMA communication, the urgent management question now is whether the awareness of PQC risks has been translated into a practical roadmap for post-quantum security.

FINMA’s survey results show the gap clearly. From November 2025 to January 2026, FINMA surveyed 60 Swiss financial institutions. Over two thirds expect quantum-related cyber risks to become directly relevant for their institution within seven years. Around two thirds of respondents also expect that a cryptographically relevant quantum computer could compromise RSA-2048 within 24 hours. According to the same respondents, the technology required to do so is expected to be available within ten years at the latest. At the same time, most institutions are still at the beginning of the transition. According to FINMA, 72% have not yet planned or taken concrete measures for post-quantum security. The remaining 28% can be split into two groups. 8% have made strategic decisions at the executive board or board of directors levels. 20% state that a corresponding project is already ongoing.

This is the core tension: awareness exists, but structured approach is still missing in most cases.

“Harvest now, decrypt later” makes the risk immediate

Quantum risk does not begin only when a cryptographically relevant quantum computer becomes available. Under a “harvest now, decrypt later” (HNDL) scenario, attackers can collect encrypted data today and retain it until quantum capabilities allow them to compromise the mechanisms used for encryption. This is particularly relevant for financial institutions holding information that must remain confidential for many years. Institutions should therefore identify data whose required protection lifetime, combined with the expected migration lead time, could extend beyond the plausible arrival of a cryptographically relevant quantum computer. Potentially exposed assets and processes must be prioritized accordingly, requiring an immediate, risk-based assessment.
However, it is important to note that the transition to quantum-safe cryptography does not necessarily entail an immediate, comprehensive shift of all information assets and cryptographic methods from classical cryptography to PQC. For critical systems, institutions can initially combine established cryptography with new PQC methods. This can reduce transition risk, although it may make systems more complex to operate. The U.S. National Institute of Standards and Technology (NIST) has published the first standards for PQC. These include ML-KEM for securely exchanging encryption keys and ML-DSA and SLH-DSA for digital signatures. Institutions should assess where and when to use them based on the importance of the data, the readiness of their systems and the support available from technology providers.

FINMA expects a roadmap by mid-2027 at the latest

Given the urgency of the topic, FINMA recommends that institutions base their migration to quantum-safe cryptography on a strategy approved by their highest governing body. This strategy should define an implementation plan with clear milestones, priorities and target dates for the migration of critical business processes. FINMA specifically suggests developing such a PQC roadmap by mid-2027.

This makes PQC a management topic, not only a cybersecurity task. In our view, institutions need board-level sponsorship and clear accountability before technical planning can become executable. Decision rights, ownership and escalation paths must be defined across business, risk, legal, compliance, IT, cyber security, architecture and vendor management.

The roadmap itself should be built on two foundations: a view of critical information assets and flows, and a cryptographic inventory showing which cryptographic methods are used where. Only by combining both perspectives can institutions identify which processes require priority treatment, where quantum-vulnerable dependencies exist, and which external providers need to be involved early.

A PQC roadmap starts with transparency

Together with qubit-lab.ch and Adnovum, Horn & Company support institutions in this transition. Our approach translates FINMA’s expectations into a structured management and implementation agenda.

The starting point is mobilization. Creating a shared understanding of quantum-related risks is a prerequisite for aligning the relevant functions, assigning ownership and establishing the governance required to steer the migration. This ensures that PQC is not treated as an isolated inventory exercise, but as a cross-functional resilience program.

The next step is transparency. In a joint approach with our partners, we assess the cryptographic methods used across systems, applications, infrastructure, signatures, authentication and key management. In parallel, we analyze business processes and information assets according to confidentiality, integrity and long-term protection requirements.

The decisive step is to connect both views. A combined business and cryptographic inventory creates the basis for a prioritization matrix that clarifies which assets are most critical, which cryptographic dependencies are most exposed, and where migration should start. The result is a pragmatic PQC roadmap with clear priorities, governance requirements and implementation steps.

From roadmap to crypto-agile resilience

The FINMA survey shows that many Swiss institutions understand the topic, but few have turned it into a controlled management agenda. This is where the real gap lies.

A credible PQC roadmap must connect business ownership, cyber expertise, IT architecture, vendor management, legal, risk and compliance. It must identify which assets need to become quantum-safe first, where vulnerable cryptography is used, which third parties are involved, and which migration steps need to be sequenced before Q-Day is reached, the point at which quantum computers can break today’s widely used encryption.

But the roadmap is only the first step. The long-term objective is crypto-agility: the ability to replace cryptographic algorithms flexibly when standards evolve, vulnerabilities emerge, or today’s secure algorithms need to be exchanged again. For Swiss financial institutions, post-quantum security is therefore not a one-off migration project. It is a new capability for resilient, future-proof digital trust.

Sources
  • (1) https://www.finma.ch/en/news/2026/07/20260709-mm-am-05-26/
  • (2) https://csrc.nist.gov/pubs/fips/203/final
  • (3) https://csrc.nist.gov/pubs/fips/204/final
  • (4) https://csrc.nist.gov/pubs/fips/205/final

//About the authors

//You might also be interested in

03. June 2026
AI in Asset Management – From RFP Automation to Operating Leverage
Discover how Swiss asset managers can use AI to automate RFPs, reduce manual effort, improve proposal quality, and create operating leverage.
Read more
20. March 2026
Private Banking at Cantonal Banks: How to Scale Systematically
Cantonal banks are increasingly focusing on non-interest income. We outline the three key elements necessary for successfully expanding private banking.
Read more
19. March 2026
It's Not Just About Crypto: Why Banks Should Take Stablecoins Seriously
Stablecoins are emerging as a central payment infrastructure. Why banks need to act now, and what strategic roles are emerging.
Read more