FINMA Guidance 05/2026: From Quantum-Risk Awareness to a PQC Roadmap

FINMA makes quantum risk a management topic
FINMA’s Guidance 05/2026 of 9 July 2026 on quantum computing sends a clear message to the Swiss financial sector. Post-quantum cryptography (PQC) risks are no longer a distant technology topic. They are becoming a governance, resilience and cyber-risk management issue. As discussed in Horn & Company’s earlier article on quantum computing and business-model analysis, the technology affects both future opportunities and today’s security assumptions. In the context of the recent FINMA communication, the urgent management question now is whether the awareness of PQC risks has been translated into a practical roadmap for post-quantum security. FINMA’s survey results show the gap clearly. From November 2025 to January 2026, FINMA surveyed 60 Swiss financial institutions. Over two thirds expect quantum-related cyber risks to become directly relevant for their institution within seven years. Around two thirds of respondents also expect that a cryptographically relevant quantum computer could compromise RSA-2048 within 24 hours. According to the same respondents, the technology required to do so is expected to be available within ten years at the latest. At the same time, most institutions are still at the beginning of the transition. According to FINMA, 72% have not yet planned or taken concrete measures for post-quantum security. The remaining 28% can be split into two groups. 8% have made strategic decisions at the executive board or board of directors levels. 20% state that a corresponding project is already ongoing. This is the core tension: awareness exists, but structured approach is still missing in most cases. |
“Harvest now, decrypt later” makes the risk immediate
| Quantum risk does not begin only when a cryptographically relevant quantum computer becomes available. Under a “harvest now, decrypt later” (HNDL) scenario, attackers can collect encrypted data today and retain it until quantum capabilities allow them to compromise the mechanisms used for encryption. This is particularly relevant for financial institutions holding information that must remain confidential for many years. Institutions should therefore identify data whose required protection lifetime, combined with the expected migration lead time, could extend beyond the plausible arrival of a cryptographically relevant quantum computer. Potentially exposed assets and processes must be prioritized accordingly, requiring an immediate, risk-based assessment. |

| However, it is important to note that the transition to quantum-safe cryptography does not necessarily entail an immediate, comprehensive shift of all information assets and cryptographic methods from classical cryptography to PQC. For critical systems, institutions can initially combine established cryptography with new PQC methods. This can reduce transition risk, although it may make systems more complex to operate. The U.S. National Institute of Standards and Technology (NIST) has published the first standards for PQC. These include ML-KEM for securely exchanging encryption keys and ML-DSA and SLH-DSA for digital signatures. Institutions should assess where and when to use them based on the importance of the data, the readiness of their systems and the support available from technology providers. |
FINMA expects a roadmap by mid-2027 at the latest
Given the urgency of the topic, FINMA recommends that institutions base their migration to quantum-safe cryptography on a strategy approved by their highest governing body. This strategy should define an implementation plan with clear milestones, priorities and target dates for the migration of critical business processes. FINMA specifically suggests developing such a PQC roadmap by mid-2027. This makes PQC a management topic, not only a cybersecurity task. In our view, institutions need board-level sponsorship and clear accountability before technical planning can become executable. Decision rights, ownership and escalation paths must be defined across business, risk, legal, compliance, IT, cyber security, architecture and vendor management. The roadmap itself should be built on two foundations: a view of critical information assets and flows, and a cryptographic inventory showing which cryptographic methods are used where. Only by combining both perspectives can institutions identify which processes require priority treatment, where quantum-vulnerable dependencies exist, and which external providers need to be involved early. |
A PQC roadmap starts with transparency
Together with qubit-lab.ch and Adnovum, Horn & Company support institutions in this transition. Our approach translates FINMA’s expectations into a structured management and implementation agenda. The starting point is mobilization. Creating a shared understanding of quantum-related risks is a prerequisite for aligning the relevant functions, assigning ownership and establishing the governance required to steer the migration. This ensures that PQC is not treated as an isolated inventory exercise, but as a cross-functional resilience program. The next step is transparency. In a joint approach with our partners, we assess the cryptographic methods used across systems, applications, infrastructure, signatures, authentication and key management. In parallel, we analyze business processes and information assets according to confidentiality, integrity and long-term protection requirements. The decisive step is to connect both views. A combined business and cryptographic inventory creates the basis for a prioritization matrix that clarifies which assets are most critical, which cryptographic dependencies are most exposed, and where migration should start. The result is a pragmatic PQC roadmap with clear priorities, governance requirements and implementation steps. |

From roadmap to crypto-agile resilience
The FINMA survey shows that many Swiss institutions understand the topic, but few have turned it into a controlled management agenda. This is where the real gap lies. A credible PQC roadmap must connect business ownership, cyber expertise, IT architecture, vendor management, legal, risk and compliance. It must identify which assets need to become quantum-safe first, where vulnerable cryptography is used, which third parties are involved, and which migration steps need to be sequenced before Q-Day is reached, the point at which quantum computers can break today’s widely used encryption. But the roadmap is only the first step. The long-term objective is crypto-agility: the ability to replace cryptographic algorithms flexibly when standards evolve, vulnerabilities emerge, or today’s secure algorithms need to be exchanged again. For Swiss financial institutions, post-quantum security is therefore not a one-off migration project. It is a new capability for resilient, future-proof digital trust. |
Sources
- (1) https://www.finma.ch/en/news/2026/07/20260709-mm-am-05-26/
- (2) https://csrc.nist.gov/pubs/fips/203/final
- (3) https://csrc.nist.gov/pubs/fips/204/final
- (4) https://csrc.nist.gov/pubs/fips/205/final




