Insights

FINMA Guidance 05/2026: start your quantum-safe migration now

Written by Peter Philp | Jul 23, 2026 2:42:21 AM

Most of the encryption in use today – securing online banking sessions, client records, digital signatures – rests on mathematical problems that ordinary computers cannot solve in any useful timeframe. A sufficiently powerful quantum computer is expected to solve them quickly. No such machine exists yet, and FINMA notes that technological progress has gained momentum. One risk applies already: data stolen today can be stored and decrypted once the hardware arrives, an attack FINMA describes as an already very real risk.

On 9 July 2026, the Swiss Financial Market Supervisory Authority FINMA published Guidance 05/2026, “Quantum computing”. It asks supervised institutions to prepare in an orderly way for the move to quantum-safe encryption – replacing today’s vulnerable algorithms with ones designed to withstand quantum attack – and it names a date: a post-quantum cryptography (PQC) roadmap drawn up by mid-2027 at the latest, derived from a strategy adopted by the board of directors.

FINMA frames this within rules that already apply. The financial market law requirements for effective governance and risk management are technology-neutral and principles-based, and in FINMA’s reading they already cover the risks arising from powerful quantum computers. The guidance makes the supervisory expectation explicit and gives institutions a planning horizon.

What the 60 institutions told FINMA

43 of the 60 institutions surveyed have neither planned nor implemented any quantum-safe measure.

FINMA surveyed 60 authorised institutions – banks, insurers, managers of collective assets and financial market infrastructures – between November 2025 and January 2026. The institutions recognise the risk and have largely yet to act on it. Around two-thirds expect to be directly affected by quantum-related cyber risk within seven years, and around two-thirds expect that within 10 years at the latest a quantum computer will crack RSA 2048-bit encryption inside 24 hours.

Of the 60, some 43 have neither planned nor implemented any measure on quantum-safe encryption. Around five hold a specific roadmap, and they typically foresee four to five years before critical data and processes are quantum-safe. Around half intend to draw one up within the next one to three years.

Respondents agree on what matters. Around three in four rate a cryptographic inventory as offering high or very high added value, and a similar share regard crypto-agility – the ability of a system to swap cryptographic algorithms without major architectural change – as important or very important. The gap sits between recognising the work and starting it.

What FINMA recommends

FINMA sets out recommendations in five areas, all limited to the move to quantum-safe algorithms under the United States National Institute of Standards and Technology standards FIPS 203, 204 and 205. Quantum key distribution falls outside the guidance.

The five FINMA recommendation areas

  1. 1

    Strategy and roadmap.

  2. 2

    Risk analysis and inventory.

  3. 3

    Critical data.

  4. 4

    Crypto-agility.

  5. 5

    External service providers.

A board-adopted PQC strategy, with an implementation plan setting milestones, priorities and target dates. A risk analysis covering both the cryptographic methods in use and the critical data needing long-term protection. A cryptographic inventory spanning all information and communication technology systems, applications and infrastructure, whether run in-house, outsourced or bought as a service, and covering data in transit, data at rest, digital signatures, key management and authentication. Priority protection for critical data against “harvest now, decrypt later” attacks, where data encrypted today is taken now and decrypted later once the hardware exists. Crypto-agility built in as a requirement for systems procured or developed from here. The fifth area, external service providers, is where many institutions will find much of the work sits.

On critical data, FINMA notes that long-term experience of PQC algorithms does not yet exist, and that various organisations recommend a hybrid approach in the short to medium term, pairing a classical algorithm with a PQC one. FINMA also notes the added complexity and implementation risk this carries.

The two moves that come first

The inventory is the starting point. Encryption sits in places nobody has documented in years: virtual private network tunnels, transport layer security certificates, signing keys, service accounts, appliances shipped with vendor defaults. A useful inventory names the algorithm, the system, the owner and whether the algorithm is quantum-vulnerable, and it stays current as the estate changes.

Outsourcing is the second. FINMA recommends making crypto-agility a prerequisite in all new outsourcing arrangements in software and data, and folding it into existing arrangements at the earliest opportunity. Responsibility for an outsourced function stays with the outsourcing institution under FINMA Circular 2018/3 “Outsourcing”. Where a third party runs the platform, the institution still answers for the cryptography inside it. Of the 60 surveyed, 36 are in contact with their software suppliers or plan to be.

Putting this on the agenda

Our colleague Hossein Fezzazi made the case in June for putting a cryptographic inventory on the 2026 board agenda. FINMA has now formalised it and attached a date. The strategy is a board decision; the inventory and the supplier conversations are execution, and they take longer than the calendar suggests.

Penta works with Geneva institutions on exactly this: building the cryptographic inventory across owned and outsourced estates, and writing crypto-agility into supplier arrangements so the requirement survives the next contract renewal. Put it on the agenda this quarter, and talk to us about getting from the agenda item to the roadmap.

 

References

  1. FINMA, Guidance 05/2026 “Quantum computing”, 9 July 2026 (PDF).
  2. FINMA, press release on Guidance 05/2026, 9 July 2026.
  3. FINMA Circular 2018/3 “Outsourcing”.
  4. NIST, FIPS 203, 204 and 205 (post-quantum cryptography standards).