Blog

FINMA turns quantum risk into a mid-2027 migration roadmap

FINMA’s survey of 60 Swiss financial institutions found broad awareness but little execution. Its new guidance points to board-approved strategy, a living cryptographic inventory and a PQC roadmap by mid-2027.

Switzerland’s financial supervisor has turned post-quantum cryptography from a horizon risk into a concrete governance task. In guidance published on 9 July 2026, FINMA recommends that supervised institutions build a board-backed strategy and complete a post-quantum cryptography (PQC) roadmap by mid-2027 at the latest.

The guidance is valuable because it does not depend on predicting a dramatic “Q-Day”. It focuses on the work financial institutions can verify now: ownership, risk analysis, cryptographic inventory, long-lived data, supplier dependencies and crypto-agilityCrypto-agilityBeing able to swap one encryption algorithm for another without rebuilding your systems. It is what turns the next migration into a configuration change instead of a project..

Awareness is not yet execution

FINMA surveyed 60 authorised banks, insurers, asset managers and financial-market infrastructures between November 2025 and January 2026. The results show a familiar gap between recognising the risk and organising a response.

  • 72% said they had not planned or implemented specific quantum-safe measures.
  • Only 8% had a specific roadmap for quantum-safe cryptography.
  • 73% rated crypto-agilityCrypto-agilityBeing able to swap one encryption algorithm for another without rebuilding your systems. It is what turns the next migration into a configuration change instead of a project. as important or very important, while 76% saw high or very high value in a cryptographic inventory.
  • 60% were already in contact with software suppliers or planned to engage them.

Around two-thirds of respondents expected to be directly affected by quantum cyber risk within seven years. A similar share expected that, within ten years at the latest, a quantum computer could break RSA-2048RSA-2048The encryption behind a large share of today’s web traffic, VPNs, and digital certificates. A sufficiently capable quantum computer would break it outright. within 24 hours. These are the surveyed institutions’ expectations, not proof that such a machine exists or an official technical forecast. FINMA states clearly that a cryptographically relevant quantum computer does not exist today.

A supervisory signal, not a new algorithm mandate

FINMA’s requirements for governance, risk management, operational resilience and outsourcing are technology-neutral. The new document explains how quantum-related cryptographic risk fits inside those existing duties. It recommends early, risk-based preparation rather than a uniform, immediate switch across every system.

That distinction matters. “Quantum-safe” is not a status an institution can obtain by installing one library. Financial services rely on encryption, signatures and authentication across payment systems, mobile applications, identity platforms, hardware security modules, APIs, VPNs, data stores, software updates and distributed-ledger technology. Each use has different owners, data lifetimes and interoperability constraints.

Five controls shape the roadmap

1. Board-approved strategy. FINMA recommends a strategy adopted by the board of directors, with milestones and priorities for critical business processes and the complete migration. The PQC roadmap should be in place by mid-2027.

2. Risk analysis and a living inventory. Institutions should analyse business processes across in-house, outsourced and service-based technology. The resulting inventory should cover cryptography protecting data in transit and at rest, digital signatures, key management and authentication—and it should be kept current.

3. Priority for long-lived critical data. Data that must remain confidential for years can be exposed to “harvest now, decrypt later” collection before a future quantum computer exists. FINMA recommends identifying those protection periods and prioritising them in migration decisions.

4. Crypto-agilityCrypto-agilityBeing able to swap one encryption algorithm for another without rebuilding your systems. It is what turns the next migration into a configuration change instead of a project. by design. New systems should be able to replace algorithms without major architectural change. This is wider than PQC: implementations and standards will continue to evolve, so controlled replacement, observability and rollback are core resilience capabilities.

5. Supplier and outsourcing governance. External providers must be part of the plan. FINMA recommends making crypto-agilityCrypto-agilityBeing able to swap one encryption algorithm for another without rebuilding your systems. It is what turns the next migration into a configuration change instead of a project. a prerequisite for new software and data outsourcing arrangements and adding it to existing requirements at the earliest opportunity.

Hybrid deployment needs its own risk analysis

The guidance notes that several organisations recommend combining established and post-quantum algorithms during the transition. A well-designed hybrid can preserve protection if one component later proves weak. It also adds implementation and operational complexity. Hybrid therefore describes an architecture to test, not a label that replaces assurance.

For security teams, the useful evidence is negotiated algorithms, certificate and key lifecycles, fallback behaviour, performance, failure modes and the ability to retire the classical path when policy requires it.

What financial security leaders should do next

  1. Name an accountable executive sponsor and a cross-functional migration owner.
  2. Define a cryptographic inventory schema that links algorithms to systems, data, owners, suppliers and required protection periods.
  3. Rank long-lived confidential data, signing roots, machine identities and hard-to-upgrade platforms first.
  4. Ask strategic suppliers for dated support, validation, interoperability and rollback evidence—not a generic “quantum-ready” claim.
  5. Select a contained pilot and measure the full operational path before setting production policy.

FINMA’s signal is measured but firm: institutions do not need certainty about the arrival date of a cryptographically relevant quantum computer to improve risk management now. A board-approved roadmap, maintained inventory and supplier-aware migration backlog are defensible outcomes for the coming year.

Primary sources