DuoKey
Resources
Article

Switzerland Post-Quantum Cryptography Regulation: NCSC Guidance and FINMA 05/2026

Switzerland has no single PQC statute. NCSC's technology briefs say start now; FINMA Guidance 05/2026 expects a board-backed roadmap by mid-2027, with inventory, crypto-agility and harvest-now-decrypt-later prioritisation.

Nagib Aouini··10 min read

Switzerland Post-Quantum Cryptography Regulation: NCSC Guidance and FINMA 05/2026


Switzerland has not passed a post-quantum cryptography statute and has not published a national 2028/2031/2035 calendar in the style of the UK NCSC or Germany's BSI TR-02102. That absence is not the same as a free pass. The National Cyber Security Centre (NCSC) has told organisations that action on PQC is required, and for FINMA-supervised financial institutions the expectation is now specific: a board-approved migration roadmap by mid-2027, built on a cryptographic inventory, risk analysis of long-lived data, and crypto-agility in outsourcing.

This guide covers what the NCSC and FINMA have actually said, who sits in scope, which dates matter, and the first steps that turn guidance into a programme: inventory, HSM/KMS readiness, and hybrid PQC deployment. For the FINMA landing path specifically, see also our FINMA 05/2026 use case.


Table of Contents

  1. What the Regulator Said
  2. Who Is in Scope
  3. The Timeline
  4. Practical First Steps
  5. The Technical Checklist
  6. How This Maps to DuoKey Cockpit
  7. FAQ

What the Regulator Said

NCSC: action required, inventory first

In November 2024 the NCSC published an assessment stating that action is required on post-quantum cryptography. In December 2025 it followed with a technology brief on quantum computers and PQC. The brief's practical message is consistent across both documents:

  • Assess where current asymmetric cryptography is used
  • Inventory encryption, signatures and authentication dependencies
  • Prioritise data with long confidentiality requirements threatened by harvest-now-decrypt-later collection
  • Require providers and outsourcing partners to plan migration rather than waiting for a Swiss statute to name algorithms

The NCSC points to the NIST-standardised algorithms (ML-KEM / FIPS 203, ML-DSA / FIPS 204, SLH-DSA / FIPS 205) as the technical destination Switzerland's federal monitoring work already tracks. It does not invent a parallel Swiss algorithm suite.

FINMA Guidance 05/2026: roadmap by mid-2027

On 9 July 2026 FINMA published Supervisory Communication 05/2026 on quantum computing. The communication reports a survey of 60 supervised institutions (November 2025 to January 2026) and then sets supervisory expectations.

Survey findings FINMA chose to publish:

  • Institutions are aware of the cryptographically relevant quantum risk
  • Only about 8% held a concrete migration roadmap
  • Roughly 72% had taken no post-quantum measures at the time of the survey
  • Respondents themselves ranked crypto-agility and a cryptographic inventory as high-value foundations for migration

FINMA's recommended measures are concrete enough to plan against:

  1. A strategy adopted by the board of directors (Oberleitungsorgan), from which an implementation plan with milestones and priorities is derived
  2. Target dates for complete migration and for migration of critical business processes
  3. Institution-specific risk analysis that treats harvest-now-decrypt-later as a real confidentiality risk for long-lived data
  4. A comprehensive, continuously updated cryptographic inventory covering data in transit (VPN, TLS, HTTPS and similar), data at rest, digital signatures, key management and authentication mechanisms
  5. Migration plans for systems still using quantum-vulnerable algorithms, sized to the associated risk
  6. Crypto-agility as a prerequisite for new software and data outsourcing, and incorporation into existing outsourcing as early as practicable
  7. A PQC roadmap drawn up by mid-2027 at the latest

FINMA frames this inside existing operational risk and resilience obligations. It is not inventing a new licence condition from nothing; it is telling institutions that those existing duties already require forward-looking cryptography risk management.

Federal PKI and procurement

Separately, the Federal Office of Information Technology, Systems and Telecommunication (FOITT / BIT) has been adjusting Swiss Government PKI parameters and signalling preparation for post-quantum cryptography on government certificate classes. If you issue into or rely on Swiss Government PKI, treat BIT's migration work as a dependency on your own certificate and signing roadmap, even if FINMA does not supervise you.


Who Is in Scope

RegimeWho it bindsWhat it demands on PQC
FINMA Guidance 05/2026FINMA-supervised financial institutions (banks, insurers and other supervised entities in the survey population and broader supervised perimeter)Board-backed strategy, inventory, risk analysis, mid-2027 roadmap, crypto-agility in outsourcing
NCSC technology briefsBroad audience: enterprises and operators handling information requiring protectionStart inventory and migration planning; prioritise long-lived confidential data; push providers for PQC plans
Revised FADP (nDSG)Controllers and processors of personal data under Swiss data protection lawAppropriate technical and organisational measures; encryption remains a risk-proportionate control, not a named PQC mandate
Federal administration / BIT PKIFederal systems and parties using Swiss Government PKIFollow FOITT/BIT certificate and algorithm migration work for government trust services
Critical infrastructure / NCS monitoringOperators tracked under the National Strategy for the Protection of Switzerland against Cyber-RisksNCSC and Cyber-Defence Campus monitoring; no separate published national PQC completion statute as of this writing

Most Swiss banks and insurers sit in the FINMA row and the FADP row at once. Technology providers to those institutions inherit crypto-agility expectations through outsourcing clauses even when FINMA does not supervise the provider directly.


The Timeline

ByMilestoneSource
NowCryptographic inventory, harvest-now-decrypt-later prioritisation, provider engagementNCSC briefs (2024/2025)
Mid-2027Board-approved PQC roadmap with milestones and prioritiesFINMA Guidance 05/2026
Institution-definedTarget dates for critical-process migration and full migrationFINMA expects you to set these in the roadmap; it does not publish a single national 2030/2035 cutover for all Swiss systems
Aligned to NIST / peersHybrid then PQC-only deployment following FIPS 203/204/205NCSC technical direction; no Swiss-only algorithm list

Switzerland is stricter than many jurisdictions on the near-term governance artefact (roadmap by mid-2027) and looser on a single national technical sunset date. Do not read the missing 2031 key-agreement sunset as permission to delay discovery. FINMA's survey already treated missing roadmaps as an operational-risk gap.

For comparison: Germany's BSI names 2030/2031/2035 technical dates; the UK NCSC names 2028/2031/2035 programme milestones; the US federal path names HVA key-establishment by 2030. A Swiss FINMA roadmap that ignores those peer calendars for cross-border systems will age poorly.


Practical First Steps

1. Cryptographic inventory

FINMA is explicit: risk analysis of business processes should produce a comprehensive inventory of cryptographic methods in use, kept current. Cover at least:

  • Transit encryption (VPN, TLS, HTTPS, private links)
  • Encryption at rest
  • Digital signatures and authentication mechanisms
  • Key management locations (HSM, KMS, vault, cloud provider)
  • Outsourced systems where cryptography is performed by a third party

Mark which algorithms are quantum-vulnerable and which data sets need multi-year confidentiality. That marking is what turns the inventory into a prioritised migration plan rather than a spreadsheet. A CBOM is the durable format; see our CBOM guide.

2. HSM and KMS readiness

FINMA lists key management inside the inventory scope for a reason. A roadmap that changes TLS ciphersuites but cannot re-issue or protect new key types in your HSMs will stall at the first critical process.

  • Inventory every key store that holds material for in-scope business processes
  • Confirm support (or a dated upgrade path) for NIST PQC key types and larger hybrid artefacts
  • Decide which keys must remain under Swiss or institution control for secrecy and outsourcing reasons, separate from algorithm choice
  • Put crypto-agility language into new outsourcing contracts now; FINMA recommends it as a prerequisite for new software and data arrangements

3. Hybrid PQC deployment

Neither the NCSC nor FINMA requires a Swiss-specific hybrid construction. Both point at the same NIST standards the rest of the regulated world is adopting. Hybrid classical-plus-ML-KEM on high-exposure transit paths is the practical first deployment pattern:

  • Customer- and partner-facing TLS termination
  • Inter-bank and market-infrastructure links
  • Remote access and site-to-site IPsec

Use the same implementation paths covered in our F5 and FortiGate guides. Document the hybrid step as transitional, with a path to drop the classical half once your risk committee accepts PQC-only for that channel. FINMA's own survey already treated crypto-agility as a core success factor; a hybrid deployment you cannot reverse or advance is incomplete.


The Technical Checklist

  • Board (or equivalent governing body) has adopted a PQC / quantum-risk strategy, or a dated paper is on the agenda before mid-2027
  • A written roadmap exists with milestones, owners, and target dates for critical processes and full migration
  • Cryptographic inventory covers transit, at-rest, signatures, authentication and key management, including outsourced systems
  • Inventory flags quantum-vulnerable algorithms and data with long confidentiality requirements
  • Harvest-now-decrypt-later is explicitly addressed in the risk analysis, not only "quantum computer exists" scenarios
  • HSM/KMS platforms can support planned PQC/hybrid key types, or replacement is scheduled
  • New outsourcing contracts in software and data include crypto-agility requirements; existing contracts have a remediation path
  • Hybrid PQC is piloted on at least one high-exposure transit path with a documented path to PQC-only
  • If you rely on Swiss Government PKI, BIT/FOITT migration plans are tracked as an external dependency

How This Maps to DuoKey Cockpit

FINMA's mid-2027 roadmap starts with an inventory you can maintain, not a one-off workshop slide. DuoKey's CBOM generation and Quantum Risk Score produce the continuously updated cryptographic posture FINMA describes, including outsourced and multi-cloud estates. Details are in the CBOM guide and the FINMA 05/2026 use case.

Hybrid deployment on edge TLS and IPsec maps to the same F5 and FortiGate MCP-assisted workflows used in other jurisdictions. Key control that has to remain with the institution, a recurring Swiss secrecy and outsourcing concern, maps to DuoKey's customer-held key and MPC vault model rather than leaving migration solely in a cloud provider's shared-responsibility matrix.


FAQ

Q: Is FINMA Guidance 05/2026 binding law?

It is a supervisory communication, not a Federal Act. FINMA published it as the articulation of what existing operational-risk and resilience expectations already require for quantum-related cyber risk. Supervised institutions that arrive at mid-2027 without a roadmap should expect that gap to surface in supervisory dialogue.

Q: Does Switzerland mandate specific PQC algorithms?

Not in a Swiss-named suite. NCSC material points to NIST FIPS 203/204/205. Plan against those standards unless and until a Swiss federal standard says otherwise.

Q: We are not a bank. Does any of this apply?

NCSC guidance still applies as national cyber advice. FADP still requires appropriate security for personal data. If you are a critical technology provider to FINMA-supervised institutions, expect crypto-agility and migration evidence to appear in contracts even without direct FINMA supervision.

Q: How does this compare to the UK or German timelines?

Switzerland is earlier on the governance artefact (roadmap by mid-2027) and less prescriptive on a single national technical sunset. Use peer timelines (UK, Germany, US) to set technical milestones inside your FINMA roadmap so cross-border systems are not planned twice.


Conclusion

Swiss PQC regulation is guidance-led, not statute-led, and that is enough to create a real deadline for financial institutions: a board-backed roadmap by mid-2027, sitting on a living cryptographic inventory, harvest-now-decrypt-later risk analysis, and crypto-agile outsourcing. The NCSC has already told the wider economy to start the same inventory work. Build the inventory, prove your key stores can change algorithms, and deploy hybrid PQC on the transit paths that already carry long-lived confidential data.


References

Share

Written by

Nagib Aouini

Related Resources

Regulation-driven PQC readiness

FINMA Guidance 05/2026: The Post-Quantum Roadmap Swiss Banks Need by Mid-2027

Sep 19, 2026

Article

A close reading of FINMA Guidance 05/2026: the survey of 60 institutions, the five recommendations, and a three-phase work plan with board deliverables for mid-2027.

Read article

Germany Post-Quantum Cryptography Regulation: What BSI TR-02102 Actually Requires

Sep 02, 2026

Article

BSI TR-02102-1 version 2026-01 names migration dates: classical-only key agreement ends 2031, high-protection systems by 2030, signatures by 2035. Here is who is in scope under BSIG and what to do first.

Read article

UK Post-Quantum Cryptography Regulation: What NCSC's Migration Timeline Actually Requires

Sep 12, 2026

Article

The UK has no single binding PQC law like DORA's RTS. Instead, NCSC's 2028/2031/2035 migration timeline, the NIS Regulations, the Cyber Assessment Framework and sector rules combine into a de facto national deadline. Here is what actually applies.

Read article

US Post-Quantum Cryptography Regulation: NIST, OMB M-26-15 and CNSA 2.0

Sep 06, 2026

Article

US federal PQC is no longer inventory-only. EO 14412 and OMB M-26-15 set HVA key establishment by 2030 and signatures by 2031. CNSA 2.0 covers national security systems. Here is who is in scope and what to do first.

Read article

How to Generate a CBOM with DuoKey Cockpit: Complete Guide 2026

Sep 08, 2026

Article

Generate a CycloneDX 1.7 Cryptography Bill of Materials (CBOM) with DuoKey Cockpit: filesystem, source-code and domain scans, the CBOM Explorer, and the agentic MCP path.

Read article

Discuss the decisions that matter most to your security programme.

Tell us where control is difficult today. We will help you identify a practical next step.