FINMA Guidance 05/2026: What It Says, What It Doesn’t, and What to Do Before Mid-2027

September 3, 2026
originally published in:
Kes Magazine
overview
FINMA recommends a PQC roadmap by mid-2027, but sets no migration deadline. We break down what the guidance says and what institutions can do now.

On 9 July 2026, FINMA published Guidance 05/2026 on quantum computing, setting out recommendations for supervised institutions preparing for the risks posed by cryptographically relevant quantum computers.

One date stands out:

Mid-2027.

FINMA recommends that supervised institutions draw up a Post-Quantum Cryptography (PQC) roadmap by mid-2027 at the latest.

But there is an important distinction.

Mid-2027 is not a deadline for completing the PQC migration. It is the latest recommended point for having the roadmap in place.

FINMA does not prescribe an end date for completing the migration.

That distinction matters because the migration itself may take years.

What FINMA Guidance 05/2026 actually is

Guidance 05/2026 is supervisory guidance containing recommendations.

It is not a new FINMA circular and does not itself create new law.

Instead, FINMA points to existing technology-neutral and principles-based requirements concerning governance and risk management, which it considers applicable to the risks associated with cryptographically relevant quantum computers.

The guidance is informed by a survey of 60 supervised institutions, conducted between November 2025 and January 2026.

It covers institutions including:

  • banks
  • insurance companies
  • managers of collective assets
  • financial market infrastructures

Quantum key distribution and risks arising from the use of quantum computing itself are outside the scope of the guidance.

So what does FINMA actually recommend?

The five areas FINMA addresses

1. Strategy and roadmap

FINMA recommends establishing a strategy that is adopted by the institution's most senior governing body.

That strategy should be supported by an implementation plan containing milestones and priorities, including target dates for both:

  • migration of critical processes
  • completion of the overall migration

The roadmap should be drawn up by mid-2027 at the latest.

The message is therefore not simply “start thinking about PQC.”

Institutions need to turn that awareness into an organised programme with ownership, priorities and dates.

2. Risk analysis and cryptographic inventory

Before an institution can establish credible migration dates, it needs to understand what cryptography it actually uses.

FINMA recommends analysing business processes for encryption, signature and authentication technologies and building an inventory across ICT systems, applications and infrastructure.

The scope includes:

  • data in transit
  • data at rest
  • digital signatures
  • key management
  • authentication mechanisms

And it applies whether those technologies are operated internally, outsourced or consumed as a service.

This goes significantly further than creating a certificate inventory.

It requires visibility into the broader cryptographic landscape.

Related insight: Cryptographic Discovery: Why No Single Tool Can Build Your PQC Inventory →

3. Protect critical data

Not every cryptographic asset carries the same risk.

FINMA recommends considering how long critical data needs to remain protected and accounting for the possibility that encrypted information could be collected today and decrypted later when sufficiently capable quantum computers become available.

This is commonly referred to as “harvest now, decrypt later.”

For critical data, FINMA recommends considering hybrid approaches combining classical and quantum-safe algorithms, while recognising the additional complexity such approaches can introduce.

The practical implication is important:

Migration priority depends not only on when quantum computers arrive, but also on how long today's information needs to remain confidential.

4. Build crypto-agility

PQC is unlikely to be the last cryptographic transition organisations will need to manage.

FINMA therefore also focuses on crypto-agility.

Crypto-agility is the ability to replace cryptographic algorithms without requiring far-reaching changes to the underlying software architecture.

FINMA recommends requiring this capability particularly for newly procured and newly developed ICT systems and applications.

This shifts the objective from simply: “Replace today's vulnerable algorithms.”

to: “Build an environment where cryptography can be changed again when necessary.”

That makes automation, visibility and repeatable cryptographic lifecycle processes strategically important.

5. Include external service providers

PQC migration does not stop at the organisational boundary.

Cloud providers, software vendors, managed services and other external providers may control cryptographic components that institutions depend on.

FINMA makes the responsibility clear:

Responsibility remains with the outsourcing institution.

Crypto-agility should therefore be considered in new outsourcing relationships and addressed in existing ones.

That means supplier questions need to become part of the migration programme:

  • What cryptography does the service depend on?
  • What is the provider's PQC migration plan?
  • What is its expected timeline?
  • Which changes require customer action?
  • How is crypto-agility addressed?
  • Are relevant requirements reflected contractually?

Supplier readiness can become a critical dependency in an institution's own roadmap.

What FINMA's survey tells us

This is where I would use the actual FINMA data as the main visual element of the article.

Source: FINMA Guidance 05/2026. Survey of 60 supervised institutions, November 2025–January 2026.

The real issue is the migration timeline

One survey result deserves particular attention.

Only 8% of institutions surveyed already had a specific roadmap.

Those institutions expected it to take approximately four to five years before their critical assets would be protected.

Now put that next to FINMA's recommendation to have the roadmap in place by mid-2027.

An institution that completes its roadmap around mid-2027 and subsequently requires four to five years to protect its critical assets could be looking at approximately:

2027 → 2031/2032

At the same time, 52% of respondents consider quantum-related risks relevant within four to seven years.

This doesn't mean every institution will follow the same timeline.

But it illustrates why the distinction between roadmap completion and migration completion matters.

The challenge isn't simply reaching mid-2027 with a document.

It's ensuring the organisation has started early enough to execute what that document requires.

Illustrative timeline based on FINMA survey responses; not a FINMA migration deadline.

What institutions can do now

The recommendation is to have the roadmap in place by mid-2027.

That doesn't mean institutions need to wait until then to start.

Several activities can begin now.

Establish ownership.
Identify the executive sponsor, operational programme owner and relevant technical owners.

Start cryptographic discovery.
Identify where cryptography is used across systems, applications, infrastructure and third-party services.

Build the inventory.
Move from disconnected asset lists towards a structured, maintainable cryptographic inventory.

Identify critical assets.
Understand which data and systems require the earliest attention.

Assess crypto-agility.
Determine how easily algorithms, certificates and other cryptographic components can be changed today.

Engage suppliers.
Understand external migration timelines and dependencies before they become blockers.

Turn evidence into the roadmap.
Use the resulting visibility to establish priorities, milestones, accountabilities and defensible target dates.

Related insight: Building a PQC Roadmap Your Board Can Actually Approve →

Ultimately:

A roadmap without an inventory contains intentions. A roadmap built on discovery and inventory can contain defensible dates.