Only 8% of Swiss financial institutions have a post-quantum roadmap, yet FINMA expects all to close this gap by mid-2027.
FINMA has raised the bar, Swiss based financial institutions should now turn awareness into action.
Quantum computing poses an imminent cryptographic threat to financial institutions. Sufficiently powerful quantum computers will undermine today’s commonly used Public-Key Cryptography (PKC) that secures a wide range of essential practices, such as digital communications, electronic document signing, software integrity checking, and protecting sensitive data at rest.
Cryptographically relevant quantum computers are not yet on the market, but several risks already exist today. FINMA Guidance 05/2026 specifically highlights “Harvest Now, Decrypt Later” (HNDL) attacks, where encrypted data is collected now and decrypted in the future, once quantum capabilities mature. However, HNDL is not the only concern for financial institutions. Quantum-enabled attacks compromise not only the confidentiality security property, but also the properties of integrity, authenticity and non-repudiation.
The transition to quantum-safe cryptography will be a complex and multi-year effort. The FINMA Guidance 05/2026 makes this point clear by introducing the concept of crypto-agility that extends beyond Post-Quantum Cryptography (PQC). Crypto-agility is the ability to replace cryptographic algorithms, parameters and implementations efficiently when risks, standards or business requirements change. However, achieving a sufficient level of crypto-agility will require time, due to its complexity found in heterogeneous technology landscapes.
As outlined in the FINMA Guidance 05/2026, Swiss financial institutions demonstrate awareness of quantum-related cybersecurity risks, yet many remain at an early stage in translating awareness into concrete action. The transition to quantum-safe cryptography is complex and time-intensive, which is precisely why financial institutions should start now to prioritise impactful actions by risk and build the capabilities required for sustained cryptographic resilience.
Why crypto-agility already matters today: Independent of the post-quantum threat, the ability to adapt cryptography quickly becomes increasingly important, as Artificial Intelligence (AI) accelerates vulnerability discovery and exploitation of software, including vulnerable implementations of cryptographic algorithms. Only crypto-agile organisations can rapidly detect, assess, and remediate cryptographic risks. Non-crypto-agile organisations might take up to several years to remediate such risks, as it has been observed in the case of the SHA-1 remediation.
FINMA's survey of 60 Swiss financial institutions reveals a critical gap: while most financial institutions recognise quantum-related cyber risks, few have translated awareness into concrete planning. Below, five critical actions are proposed based on FINMA's recommendations, each outlining what financial institutions should consider for building cryptographic resilience reaching beyond post-quantum computing threats.
The first step of a post-quantum programme is to understand where the financial institution stands today by answering to “diagnostic” questions that help to determine which pathway is the most appropriate.
Examples of questions include:
Based on the answers, one of the two pathways below will be most relevant for a given organisation.
Post-Quantum Cryptography (PQC) is a technical topic that requires a robust understanding of the risks it introduces. The FINMA survey revealed that while most financial institutions recognise the quantum threat, few have translated awareness into concrete action to strive for cryptographic resilience. FINMA Guidance addresses this gap by outlining five recommendation areas, reflecting regulators' commitment to supporting a safe and structured transition to the post-quantum era.
For a safer transition, the priorities are to build better visibility on where cryptography is used and to enable crypto-agility. The ability to replace cryptographic algorithms, parameters and implementations efficiently is valuable already now, as AI-enabled vulnerability discovery requires financial institutions to be faster in finding and patching vulnerabilities.
Financial institutions that start the post-quantum journey early will be better positioned to integrate post-quantum requirements into normal change cycles rather than force a disruptive and costly quantum-migration later.