FINMA Guidance 05/2026 Recommends a Post-Quantum Roadmap by Mid-2027, and Only 8 Percent of the 60 Swiss Institutions It Surveyed Had One

Board-ready intelligence on quantum innovation · Biomedical discovery · Post-quantum transition
On 9 July 2026 Switzerland's financial supervisor published the survey it ran on 60 banks, insurers, asset managers and market infrastructures, and recommended that they draw up a migration roadmap by the middle of next year.

Post-Quantum Transition

On 9 July 2026 Switzerland's financial supervisor published the survey it ran on 60 banks, insurers, asset managers and market infrastructures, and recommended that they draw up a migration roadmap by the middle of next year.

Published by Quentir Systems LLC · September 9, 2026 · 6 min read

A new technology usually reaches a bank as an opportunity first and a hazard some years later. Card networks, electronic trading and cloud infrastructure all arrived in that order. The survey Switzerland's Financial Market Supervisory Authority published on 9 July 2026 records the sequence running the other way. Asked when quantum computing becomes a live cyber risk for their own institution, around two-thirds of respondents answered within seven years. Asked when they expect to run quantum computing applications themselves, almost two-thirds answered eight years or more. The same questionnaire has the Swiss financial sector expecting the risk before the operational benefit.

FINMA Guidance 05/2026, Quantum computing, is eight pages long and does two things. It reports what the supervisor found when it asked its own supervised population how far the post-quantum migration had actually got, and it sets out five recommendations. Quentir has referred to the mid-2027 date before, alongside Germany's end dates, in a read on what those deadlines mean for data already sitting in the archive. The survey underneath the date has more in it than the date does.

Practical takeaway. The section with the longest reach in Guidance 05/2026 is 3.5, not the mid-2027 headline. FINMA recommends crypto-agility as a prerequisite in new outsourcing arrangements in the software and data sectors. For the banks, securities firms and insurers that Circular 2018/3 addresses, responsibility for an outsourced function stays with the institution whatever the supplier does.

What FINMA asked 60 banks, insurers and market infrastructures between November 2025 and January 2026

The population was 60 authorised institutions: banks, insurance companies, managers of collective assets and financial market infrastructures. FINMA ran the survey at the end of 2025 and into January 2026 and published in July. On the threat side the answers are coherent and reasonably alarmed. Around two-thirds expect that within ten years at the latest a quantum computer will break RSA 2048-bit encryption inside 24 hours. On timing for their own exposure, 17 percent said one to three years, 52 percent said four to seven, 25 percent said eight to ten and 7 percent said eleven to fifteen. Beyond the failure of encryption itself, respondents named incomplete migration, a lack of expertise, harvest-now-decrypt-later attacks and interoperability with legacy systems as the significant risks.

They also agree on what the work consists of. Seventy-three percent regard crypto-agility as important or very important. Seventy-six percent see high or very high added value in compiling an inventory of the cryptographic methods in use. Sixty percent are already in contact with their software suppliers about it or plan to be. This is not a sector that misunderstands the problem.

The 72 percent is almost entirely institutions that are watching, not institutions that are unaware

The headline figure travelled further than the chart under it. Seventy-two percent of respondents told FINMA they had not yet planned or implemented any measures relating to quantum-safe encryption. The distribution breaks that number into two very different groups: 70 percent chose "we're monitoring the situation, but we haven't taken any specific measures yet," and 2 percent chose "haven't thought about it yet." The remaining 28 percent had taken a strategic decision at executive board or board of directors level, and 20 percent of the total had a project running as well.

That distinction matters for anyone reading the survey as a supervisory signal. Ignorance and deliberate monitoring call for different interventions, and Guidance 05/2026 is written for the second group. Separately, the text states that only 8 percent of respondents have a specific roadmap for quantum-safe encryption. Around half of the institutions plan to draw one up over the next one to three years, and 43 percent have not yet made any decision about doing so.

The 8 percent with a roadmap expect four to five years to quantum-safe; 52 percent of all respondents put the risk at four to seven

The most useful sentence in the survey section concerns the 8 percent who already have a roadmap. Respondents holding one usually foresee a timeline of four to five years until critical data and processes are expected to be quantum-safe. That figure is their own estimate of how long the work runs; the guidance does not say how far any of them has got with it.

Set that against the risk question. Fifty-two percent of all respondents put the arrival of relevant quantum cyber risk at four to seven years from the survey, which runs to roughly 2030-2033. The four-to-five-year completion estimate comes from the small group already holding a roadmap, and the guidance gives no cross-tabulation between the two groups, so these are not the same institutions answering. Even so, the best-prepared respondents' own estimate of when they finish falls in the same stretch of years that most respondents named for when the risk becomes real. FINMA does not draw the comparison; the two figures are printed pages apart in one publication.

The recommended planning date sits underneath that. FINMA advises a roadmap by mid-2027 at the latest, and the guidance is advisory, not a rule. If an institution treats mid-2027 as the moment to begin rather than the moment to have finished planning, and if its migration then runs at the pace the roadmap holders forecast, it finishes later than they do. That is a conditional scenario built on two assumptions, not something the survey reports: the four-to-five-year figure is measured from where those respondents already stood, not from mid-2027.

Section 3.3 removes the comfort of treating any of this as a future problem. Data requiring long-term confidentiality, integrity or non-repudiation — an insurance underwriting file, a pension record, a signed instruction meant to hold up in a dispute decades from now — can be copied today while still encrypted and read once the hardware exists. Where an institution holds data whose confidentiality obligation runs for decades — a life insurer's underwriting file is the obvious case — that obligation would outlast every date in this guidance, though FINMA sets no retention period and this run did not verify a specific Swiss retention rule. A medical questionnaire completed in 2026 and copied while still under classical encryption could be read once the hardware exists, and the customer who filled it in would have had no part in either the roadmap or the delay.

Sections 3.2 and 3.5: an inventory covering RSA, ECDSA, EdDSA and DH, and FINMA recommends writing crypto-agility into new outsourcing contracts

Section 3.2 asks for a risk analysis followed by a comprehensive inventory of every cryptographic method in use. Its scope is unusually wide: all ICT systems, applications, infrastructure and new technologies including distributed ledger technology, with an explicit cross-reference to Article 973d paragraph 2 of the Swiss Code of Obligations, and covering systems whether operated in-house, outsourced or bought as a service. The inventory has to reach encryption in transit — VPN, TLS, HTTPS — and at rest, plus digital signatures, key management and authentication mechanisms. A footnote names the quantum-vulnerable algorithms it expects to find: RSA, ECDSA, EdDSA, DH and EC-DH. The replacements sit in NIST FIPS 203, 204 and 205, which carry ML-KEM, ML-DSA and SLH-DSA. Defence and critical-infrastructure buyers have been assembling the same artefact under a different name, as Quentir covered when the cryptographic bill of materials turned migration into a map.

Section 3.5 is where the guidance reaches furthest. External providers have to migrate too, or the institution's own migration is decorative. FINMA points to Circular 2018/3 on outsourcing and states that responsibility for the outsourced function lies in all cases with the outsourcing institution. That circular addresses banks, securities firms and insurers; the survey also covered managers of collective assets and financial market infrastructures, which sit under their own regimes, so the responsibility rule quoted here does not reach every institution FINMA asked. It then recommends that crypto-agility be made a prerequisite for all new outsourcing arrangements in the software and data sectors, and incorporated into existing arrangements at the earliest opportunity. Read together with section 3.4, which asks for crypto-agility as a requirement in systems to be procured or developed: if adopted and agreed, this converts a property of cryptographic engineering — the ability to swap an algorithm without rebuilding the software architecture — into a contractual obligation running down the supply chain. The route would be outsourcing supervision, an established Swiss instrument with a decade of practice behind it, and not any new cryptography rule.

Section 3.3 also handles hybrid schemes carefully. FINMA notes that various bodies, citing the 2025 joint statement from partners in 21 European states, recommend combining a classical algorithm with a post-quantum one while long-term experience is thin, and that this raises complexity and therefore implementation risk. The guidance leaves the choice to internal risk analysis instead of mandating either path.

Guidance 05/2026 leaves quantum key distribution out of its recommendations

One sentence at the head of section 3 will matter commercially: the recommendations "are limited to the transition to quantum-safe algorithms and do not address the use of quantum key distribution (QKD) or issues that may arise from quantum computing applications." Swiss financial institutions are an active target market for QKD equipment, and a supervisor declining to treat it as part of the recommended migration path is a useful fact to have in writing when a proposal arrives. The guidance takes the same restrained line on capability: cryptographically relevant quantum computers, it says in the outlook, do not yet exist.

How Quentir Reads It

Three things in Guidance 05/2026 will outlast the mid-2027 date. The first is that a supervisor published a readiness distribution for its own supervised population, with the internal breakdown intact — which is why the 72 percent can be separated into 70 percent watching and 2 percent absent. Measured readiness has been scarce in this field; where it exists, as in the scan finding post-quantum key exchange on more than 19 million of 160 million SSH servers, it consistently reads differently from what organisations report about themselves.

The second is that the sector's two time estimates sit in the same stretch of years. The best-prepared respondents forecast four to five years to quantum-safe critical data; 52 percent of all respondents put the arrival of relevant risk at four to seven. Those are different groups answering different questions, and the guidance does not connect them. What it does show is that nobody in the sample is describing a comfortable margin, and an institution treating mid-2027 as the moment to begin is starting its own clock after the better-prepared ones started theirs.

The third is section 3.5, which is the part most likely to change behaviour outside Switzerland. The recommendation covers new outsourcing arrangements in the software and data sectors, not every vendor an institution buys from, and a crypto-agility clause binds a supplier only once it is written into a contract and agreed. Where that happens at scale, the plausible inference is that suppliers serving Swiss institutions carry the capability into products sold elsewhere, which would reach firms in jurisdictions with no comparable supervisory instrument before their own regulators ask them anything. That is an inference about vendor roadmaps, not something the guidance claims. Our Signature Report on post-quantum migration is built for the institution that has to run the programme: fixed scope, an executive summary, refresh triggers as the standards move, and an internal-use licence. This post gives you the instrument and its numbers; the report is what you hand to the people who have to run the programme.

The Swiss financial sector said in one questionnaire that it expects to be attacked with this technology before it gets to use it. That is a recognisable position — the same one held by anyone whose data is already sitting in someone else's archive, waiting.

Sources. FINMA, Guidance 05/2026 “Quantum computing” (PDF, 8 pages), published 9 July 2026 — survey population, all percentages, and recommendations 3.1–3.5 quoted above. FINMA, “FINMA guidance on quantum computing”, news item of 9 July 2026. FINMA, Circular 2018/3 “Outsourcing” (version of 31 October 2019), cited in section 3.5 of the guidance. Swiss Code of Obligations (SR 220), Article 973d para. 2, cited in section 3.2. NIST, FIPS 203, FIPS 204 and FIPS 205, cited in footnote 1 of the guidance. BSI, “Securing Tomorrow, Today: Transitioning to Post-Quantum Cryptography”, joint statement from partners in 21 European states, 2025, cited in section 3.3. Sources checked 9 September 2026.

Published intelligence, built to inform your own decisions. Published: 9 September 2026.

Sources. FINMA, Guidance 05/2026 “Quantum computing” (PDF, 8 pages), published 9 July 2026 — survey population, all percentages, and recommendations 3.1–3.5 quoted above. FINMA, “FINMA guidance on quantum computing”, news item of 9 July 2026. FINMA, Circular 2018/3 “Outsourcing” (version of 31 October 2019), cited in section 3.5 of the guidance. Swiss Code of Obligations (SR 220), Article 973d para. 2, cited in section 3.2. NIST, FIPS 203, FIPS 204 and FIPS 205, cited in footnote 1 of the guidance. BSI, “Securing Tomorrow, Today: Transitioning to Post-Quantum Cryptography”, joint statement from partners in 21 European states, 2025, cited in section 3.3. Sources checked 9 September 2026.

Published intelligence, built to inform your own decisions. Published: 9 September 2026.

Published intelligence, built to inform your own decisions. Published: September 9, 2026.

© 2026 Quentir Systems LLC
Previous
Previous

FIPS 203 and FIPS 204 Do Not Specify the Silicon: the 9 September 2026 NTT Patent Screening, and the Two Portfolios NIST's Royalty-Free Licenses Cover

Next
Next

Rigetti and D-Wave Disclosed the Equity Terms on Their $100 Million CHIPS Quantum Awards: What the 4-8 September 2026 Agreements Say the Government Gets