FINMA Guidance 05/2026: The Post-Quantum Roadmap Swiss Banks Need by Mid-2027
A close reading of FINMA Guidance 05/2026: the survey of 60 institutions, the five recommendations, and a three-phase work plan with board deliverables for mid-2027.
NA
Nagib Aouini··18 min read
FINMA Guidance 05/2026: The Post-Quantum Roadmap Swiss Banks Need by Mid-2027
On 9 July 2026, the Swiss Financial Market Supervisory Authority FINMA published Guidance 05/2026 "Quantum computing". The document is eight pages long. It reports a survey of 60 supervised institutions and sets out five recommendations. It contains one date: FINMA recommends that "a PQC roadmap be drawn up by mid-2027 at the latest."
This guide covers what the guidance says, what legal weight it has, and how it relates to the FINMA rules banks already apply. It then turns the recommendations into a three-phase work plan, with deliverables you can show your board of directors and your supervisor. For the wider Swiss picture, including the NCSC's guidance, start with our Switzerland post-quantum regulation overview; this article goes deeper on FINMA 05/2026 itself.
The guidance has four chapters: an introduction, the survey results, the recommendations (sections 3.1 to 3.5), and an outlook. It is aimed at more than banks. FINMA surveyed "authorised banks, insurance companies, managers of collective assets and financial market infrastructures." It also addresses its recommendations to "the supervised institutions concerned."
The scope is narrow on purpose. The recommendations "are limited to the transition to quantum-safe algorithms and do not address the use of quantum key distribution (QKD) or issues that may arise from quantum computing applications." A footnote names the quantum-safe algorithms FINMA has in mind: the NIST standards FIPS 203 (ML-KEM), FIPS 204 (ML-DSA) and FIPS 205 (SLH-DSA). A second footnote gives examples of quantum-vulnerable algorithms: "RSA, ECDSA, EdDSA, DH, EC-DH."
FINMA's reasoning is set out in the introduction: "the technology-neutral, principles-based regulatory requirements for effective governance and risk management also cover the risks arising from the emergence of powerful quantum computers." In the outlook, FINMA says it "will give greater prominence to this topic in its ongoing supervisory activities."
Legal Nature: An Expectation, Not a Circular
FINMA Guidance 05/2026 is not a FINMA circular, and it does not create new binding rules. FINMA's own description of its guidance documents is explicit: "Unlike its ordinances and circulars, FINMA guidance is not a supervisory tool, aiming rather to ensure proper application of the rules in practice. It sets out to promote a successful outcome and does not have legal impact."
That does not make it optional in practice. The guidance is best read as a prudential expectation that sits on top of existing operational-risk rules, and three passages point that way:
"FINMA expects supervised institutions to address these risks in a timely manner and to align their governance and risk management accordingly." (section 1)
Further developing risk management "would be advisable for many institutions in order to ensure ongoing compliance with the requirements relating to operational risks and resilience." (section 1)
FINMA "recommends that they be taken into account in their internal risk management." (section 3)
So the obligation comes from the rules you already follow. The guidance tells you how FINMA reads those rules when the risk is a cryptographically relevant quantum computer. Treating the mid-2027 roadmap as a date that does not matter because the document "has no legal impact" would be a misreading of how FINMA uses guidance.
What the Survey Found
FINMA ran the survey between November 2025 and January 2026. Its summary: institutions "are generally aware of the cyber risks posed by quantum computers" but "most are still in the early stages of the transition to quantum-safe encryption."
Finding (FINMA Guidance 05/2026, section 2)
Figure
Institutions surveyed
60
Expect to be directly affected by quantum cyber risk within seven years
Around two-thirds
Expect a quantum computer to crack RSA 2048-bit encryption within 24 hours, within ten years at the latest
Around two-thirds
Have not yet planned or implemented any quantum-safe encryption measures
72%
Have taken a strategic decision
28%
Also have an ongoing project
20%
Have a specific roadmap for quantum-safe encryption
8%
Have not yet decided on drawing up a roadmap
43%
Rate crypto-agility as important or very important
73%
See high or very high added value in a cryptographic inventory
76%
Already in contact with software suppliers, or plan to be
60%
According to FINMA, the few institutions that have a roadmap "usually foresee a timeline of four to five years until critical data and processes are expected to be quantum-safe." FINMA's conclusion is that concrete measures "are only being taken in isolated cases." It points to "the lengthy duration of migration projects" and "the considerable uncertainties regarding the time remaining until the development of cryptographically relevant quantum computers."
The Five Recommendations
3.1 Strategy and roadmap
FINMA recommends that the work "be based on a strategy adopted by the board of directors, from which an implementation plan setting out milestones and priorities is derived." It advises setting "target dates for the complete migration, as well as for the migration of critical business processes, to quantum-safe cryptography." It also recommends that a PQC roadmap be drawn up by mid-2027 at the latest.
Two points here are easy to miss. First, FINMA does not set the migration deadline itself. It expects each institution to set its own target dates, and the roadmap is where those dates go. Second, you do not need a separate strategy document: "The PQC strategy can form part of an existing strategy (e.g. on cyber risks)."
3.2 Risk analysis and inventory
FINMA calls a risk analysis "the first step." It has two parts: the cryptographic methods in use, and "critical data that requires long-term protection." FINMA recommends "analysing all business processes in detail to identify the encryption, signature and authentication technologies used." The scope is wide. It covers all ICT systems, applications, infrastructure and new technologies such as distributed ledger technology, "regardless of whether these are operated in-house, outsourced or procured as a service."
The result should be "a comprehensive inventory listing all the cryptographic methods used." That includes data in transit (for example "VPN, TLS, HTTPS"), stored data, digital signatures, key management and authentication mechanisms. For each quantum-vulnerable system, FINMA considers it appropriate to draw up "a migration plan commensurate with the associated risk." It adds that "a cryptographic inventory that is continuously updated to reflect the current situation contributes to the effectiveness of these measures."
3.3 Critical data
FINMA advises identifying the protection requirements of critical data. In particular, institutions should check whether long-term guarantees of confidentiality, integrity or non-repudiation are needed. It names the "harvest now, decrypt later" risk: data encrypted today may be stolen now and decrypted later with a powerful quantum computer. Data that must stay protected in the long term "should be given priority and protected accordingly using PQC algorithms." Our store now, decrypt later explainer covers the threat model.
On hybrid cryptography, FINMA notes that "various organisations recommend a hybrid solution over pure PQC algorithms in the short to medium term," meaning a classical algorithm combined with a PQC algorithm. It also warns that this "leads to increased complexity, which entails implementation risks."
3.4 Crypto-agility
FINMA writes: "It must be anticipated that even in the future, (PQC) algorithms currently regarded as secure will need to be replaced." Crypto-agility, "the ability of an ICT system or application to flexibly swap out cryptographic algorithms," applies to every algorithm in use, not only the PQC migration. FINMA recommends it "as a requirement for ICT systems and applications to be procured or developed."
3.5 External service providers
PQC migration creates dependencies on providers, both through outsourcing and through external communication interfaces. Providers "must also switch to quantum-safe cryptography." FINMA suggests building this into regular release cycles and planning it jointly with each provider. Responsibility "lies in all cases with the outsourcing institution," and the guidance refers to FINMA Circular 2018/3 "Outsourcing." FINMA recommends making crypto-agility "a prerequisite for all new outsourcing arrangements in the software and data sectors." For existing arrangements, it should be added to the requirements "at the earliest opportunity."
How the Guidance Fits Existing FINMA Rules
The guidance does not name a specific operational-risk circular. It refers generally to "the requirements relating to operational risks and resilience" and, for outsourcing, to Circular 2018/3. For banks, the operational-risk requirements are set out in FINMA Circular 2023/1 "Operational risks and resilience – banks", in force since 1 January 2024. Circular 2023/1 does not mention post-quantum cryptography. Our reading is that several of its existing requirements are where the guidance's recommendations would fit in practice:
FINMA Circular 2023/1 requirement
Where Guidance 05/2026 builds on it
ICT operations: keep inventories of ICT assets, including "the storage locations of critical data" and interfaces to significant external service providers, reviewed regularly for completeness and accuracy
The cryptographic inventory in section 3.2 adds the cryptographic methods each of those assets uses
Change management: functional and non-functional requirements for ICT development and procurement "shall be clearly defined and approved"
Crypto-agility as a requirement for systems "to be procured or developed" (section 3.4)
Critical data: identify critical data "in a systematic and comprehensive way" and categorise it by criticality
Prioritising long-lived critical data against "harvest now, decrypt later" (section 3.3)
Cyber risk: protect inventoried ICT assets and electronic critical data, and respond to identified vulnerabilities
Migration plans for systems running quantum-vulnerable algorithms (section 3.2)
This mapping is our interpretation, not a FINMA statement. It is still useful, because it lets you run the PQC programme through processes that FINMA already supervises instead of building a parallel one.
The Wider Timeline
Mid-2027 is the only date in FINMA's guidance. Other public sources help institutions set their own target dates:
NIST standards. FIPS 203 (ML-KEM), FIPS 204 (ML-DSA) and FIPS 205 (SLH-DSA) were published on 13 August 2024. These are the standards FINMA's footnote cites.
NIST IR 8547 (Initial Public Draft, November 2024). This draft proposes that quantum-vulnerable signature and key-establishment schemes at 112 bits of security strength, which includes RSA-2048, be "deprecated after 2030." It proposes that all of them, including those at 128 bits of security strength, be "disallowed after 2035." It is still a draft, so treat the dates as NIST's stated intent rather than final policy.
European joint statement (June 2025). FINMA cites this statement from partners in 21 European states for its hybrid-cryptography point. It recommends that the most sensitive use cases be protected against "store now, decrypt later" attacks "as soon as possible, latest by the end of 2030," and that detailed PKI transition plans be developed in the same timeframe. Switzerland is not a signatory, but many Swiss institutions operate in those jurisdictions.
Taken together, a roadmap due by mid-2027 that relies on multi-year migrations, which is the four-to-five-year horizon FINMA observed, leaves little room before the dates proposed elsewhere.
A Three-Phase Work Plan
The phases below follow FINMA's own order: risk analysis and inventory first, then prioritisation, then migration. Phases 1 and 2 are what make a credible roadmap possible by mid-2027. Phase 3 runs on the target dates that roadmap sets. For a general roadmap method, see How to Build a PQC Migration Roadmap. This section focuses on what FINMA asks for.
Phase 1: Inventory
Goal: a comprehensive, current inventory of cryptographic methods across the scope FINMA describes: in-house, outsourced and as-a-service.
Anchor the work in a strategy adopted by the board of directors, standalone or as part of your cyber-risk strategy (section 3.1)
Walk the business processes and record the encryption, signature and authentication technologies each one depends on (section 3.2)
Cover data in transit (VPN, TLS, HTTPS), stored data, digital signatures, key management and authentication mechanisms
Flag every quantum-vulnerable algorithm (RSA, ECDSA, EdDSA, DH, EC-DH)
Include distributed ledger technology and outsourced functions, and list the external providers and interfaces involved
Store the inventory in a machine-readable form, such as a CycloneDX CBOM, so it can be kept up to date rather than rebuilt each year. See our CBOM guide
Phase 2: Risk prioritisation
Goal: a ranked list of what to migrate first, with target dates, which becomes the roadmap.
Identify critical data and its protection requirements for confidentiality, integrity and non-repudiation (section 3.3)
Rank by "harvest now, decrypt later" exposure: long-lived confidential data moving over quantum-vulnerable channels comes first
Decide where hybrid schemes are appropriate, and record the implementation risk FINMA warns about
Set target dates for migrating critical business processes and for the complete migration (section 3.1)
For each provider, record current PQC and crypto-agility status and the next contract or release window where it can be addressed (section 3.5)
If the critical data includes personal data, read this alongside your Swiss data protection obligations. See our FADP overview
Phase 3: Migration
Goal: execute the roadmap and leave behind systems that can change algorithms again.
Draw up per-system migration plans "commensurate with the associated risk" (section 3.2)
Add crypto-agility to procurement and development requirements (section 3.4)
Make crypto-agility a prerequisite in new outsourcing contracts, and add it to existing ones at the earliest opportunity (section 3.5)
Align provider changes with their regular release cycles
Keep the inventory continuously updated, so that progress shows up as a measurable reduction in quantum-vulnerable assets
What to Show the Board and FINMA
Phase
Deliverable
Guidance reference
1
Board-adopted PQC strategy, standalone or within the cyber-risk strategy
3.1
1
Cryptographic inventory covering in-house, outsourced and as-a-service systems, with quantum-vulnerable algorithms flagged
3.2
1
List of external service providers and interfaces with PQC dependencies
3.5
2
Critical data register with long-term protection requirements and "harvest now, decrypt later" ranking
3.3
2
PQC roadmap with milestones, priorities and target dates for critical processes and full migration, by mid-2027 at the latest
3.1
2
Documented decisions on hybrid versus pure PQC, with implementation risks noted
3.3
3
Per-system migration plans commensurate with risk
3.2
3
Updated procurement, development and outsourcing requirements that include crypto-agility
3.4, 3.5
3
Continuously updated inventory showing migration progress over time
3.2
How DuoKey Helps
DuoKey offers two separate tools for the first two phases. They do different jobs and should not be confused.
Quantum Risk Score: the free external baseline
The Quantum Risk Score (QRS) is a free, one-shot assessment of your public domain surface. It uses only publicly observable signals, such as TLS, certificates, cipher suites and DNSSEC. It needs no install, agent, VPN or internal access. The output is a 0–100 composite index based on a published formula: Algorithm Resilience 40%, Crypto Agility 30%, Harvest Exposure 20%, Migration Posture 10%. It comes with a board-ready report reviewed with the DuoKey cryptographer who ran the assessment.
For a FINMA roadmap, QRS gives you a documented starting point for your internet-facing cryptography, which you can put in front of a risk committee early. It is not the comprehensive inventory described in section 3.2. That inventory covers internal systems, stored data and outsourced functions, and QRS by design sees none of them. Request your Quantum Risk Score.
Discover: filesystems, source code, GitHub and GitLab repositories, Terraform IaC, TLS-facing domains, SSH fleets, cloud KMS, identity providers and artifact registries feed one CycloneDX CBOM. Discovery is agentless by default, with an optional agent mode for deeper internal coverage.
Score: each asset is scored against the published QRS methodology and checked for drift against your own declared cryptographic policy.
Simulate: model the effect of a policy change before rollout, for example requiring ML-KEM-768 on all IPsec gateways.
Remediate: a scoped pull request against the real target is drafted and reviewed like any other change, then verified once deployed. Findings and migration work can sync into ServiceNow.
This covers the evidence behind Phases 1 to 3: the inventory, the prioritised list of quantum-vulnerable assets, and a record of what has been migrated.
Crypto-agility in practice
Section 3.4 asks for systems that can swap algorithms "without requiring major changes to the software architecture." DuoKey KMS provisions hybrid ML-KEM-768 keys, and certificate and VPN rotation run with rollback. For execution on infrastructure you already run, our F5 BIG-IP and FortiGate guides show what an algorithm change takes. For an overview built around the guidance, see the FINMA 05/2026 PQC migration use case.
FAQ
Q: Is FINMA Guidance 05/2026 binding?
Not by itself. FINMA says its guidance "does not have legal impact" and is "not a supervisory tool," unlike ordinances and circulars. It is a prudential expectation that applies existing operational-risk and resilience requirements to quantum risk, and FINMA has said it will give the topic greater prominence in supervision.
Q: Does it only apply to banks?
No. FINMA surveyed banks, insurance companies, managers of collective assets and financial market infrastructures, and addresses its recommendations to "the supervised institutions concerned."
Q: What exactly is due by mid-2027?
The PQC roadmap. FINMA does not set a date for completing the migration. It recommends that each institution set its own target dates, for critical business processes and for the complete migration, and record them in that roadmap.
Q: Does FINMA prescribe specific algorithms?
No. The guidance cites NIST FIPS 203, 204 and 205 as the quantum-safe algorithms and gives RSA, ECDSA, EdDSA, DH and EC-DH as examples of quantum-vulnerable ones. On hybrid schemes, it reports that various organisations recommend them in the short to medium term and warns about the added complexity.
Q: Does the guidance cover quantum key distribution?
No. The recommendations are explicitly limited to quantum-safe algorithms and do not address QKD.
Q: Is a Quantum Risk Score enough to meet the guidance?
No. QRS assesses only your publicly observable domain surface. FINMA's inventory covers all ICT systems, including internal, outsourced and as-a-service ones. QRS is a baseline for the external part. The full inventory needs continuous discovery across the estate, which is the role of DuoKey CPM.
Q: What if the vulnerable cryptography sits with an outsourcing provider?
Responsibility stays with your institution. FINMA recommends planning the change with the provider, aligning it with release cycles, making crypto-agility a prerequisite in new outsourcing arrangements, and adding it to existing ones at the earliest opportunity.
Conclusion
FINMA Guidance 05/2026 does not introduce a new rule. It tells supervised institutions how FINMA reads the rules they already follow now that cryptographically relevant quantum computers are a planning assumption. The one fixed date is a roadmap by mid-2027. Everything behind that roadmap depends on knowing which cryptography you run, where it runs and what it protects. That work takes longer than the date suggests.
A PQC strategy adopted by the board of directors exists, standalone or within the cyber-risk strategy
Business processes have been analysed for the encryption, signature and authentication technologies they use
A cryptographic inventory covers in-house, outsourced and as-a-service systems, including DLT
Quantum-vulnerable algorithms (RSA, ECDSA, EdDSA, DH, EC-DH) are flagged in the inventory
The inventory is continuously updated rather than rebuilt once a year
Critical data and its long-term confidentiality, integrity and non-repudiation needs are identified
Data exposed to "harvest now, decrypt later" is prioritised for PQC protection
Hybrid versus pure PQC decisions are documented, with implementation risks noted
Target dates are set for critical business processes and for the complete migration
A PQC roadmap with milestones and priorities is drawn up by mid-2027 at the latest
Crypto-agility is a requirement for ICT systems procured or developed
Crypto-agility is a prerequisite in new outsourcing arrangements and is being added to existing ones
PQC changes with external providers are planned into their release cycles