FINMA Guidance 05/2026: What It Says, What It Doesn’t, and What to Do Before Mid-2027

FINMA Guidance 05/2026: What It Says, What It Doesn’t, and What to Do Before Mid-2027
On 9 July 2026, FINMA published Guidance 05/2026 on quantum computing.
The key recommendation is clear: supervised institutions should draw up a Post-Quantum Cryptography (PQC) roadmap by mid-2027 at the latest.
But there is an important distinction.
Mid-2027 is not a deadline for completing the migration. It is the latest recommended point for having the roadmap in place. FINMA sets no end date for the migration itself.
That distinction matters because the migration itself may take years.
What FINMA Guidance 05/2026 actually is
The document is supervisory guidance containing recommendations. It is not a new circular and does not create new law.
FINMA instead refers to existing technology-neutral and principles-based requirements around governance and risk management, which it considers applicable to the risks created by cryptographically relevant quantum computers.
The guidance is based on a survey of 60 supervised institutions conducted between November 2025 and January 2026.
It addresses:
- banks
- insurance companies
- managers of collective assets
- financial market infrastructures
Quantum key distribution and questions arising from quantum-computing applications are explicitly outside its scope.
The five areas FINMA addresses
1. Strategy and roadmap
FINMA recommends a strategy adopted by the institution's most senior governing body, supported by an implementation plan with milestones and priorities.
Target dates should be established for both critical processes and the overall migration. The roadmap should be drawn up by mid-2027 at the latest.
2. Risk analysis and cryptographic inventory
Institutions should analyse where encryption, digital signatures and authentication technologies are used.
That goes significantly further than creating an inventory of certificates.
The scope includes data in transit and at rest, digital signatures, key management and authentication across ICT systems, applications and infrastructure, whether operated internally, outsourced or consumed as a service.
3. Critical data
Institutions should consider how long critical data needs to remain protected and account for the risk commonly described as “harvest now, decrypt later.”
For critical data, FINMA recommends considering hybrid approaches combining classical and quantum-safe algorithms, while acknowledging the additional complexity.
4. Crypto-agility
Crypto-agility means being able to replace cryptographic algorithms without far-reaching changes to the underlying software architecture.
This is particularly important for newly procured and newly developed ICT systems and applications.
5. External service providers
The transition does not stop at the organisational boundary.
External providers will also need to migrate. Responsibility, however, remains with the outsourcing institution. Crypto-agility should therefore become part of new outsourcing relationships and be addressed in existing ones.
What FINMA's survey tells us
The survey provides an interesting picture of current preparedness.
72% of surveyed institutions have neither planned nor implemented measures for quantum-safe encryption.
20% have projects underway and have taken a strategic decision.
Only 8% have a specific roadmap. Those institutions expect it to take approximately four to five years before their critical assets are protected.
At the same time, 52% consider quantum risks relevant within four to seven years.
And 73% consider crypto-agility important or very important, while 76% see high or very high value in a cryptographic inventory.
The real issue is the migration timeline
This is where the dates become important.
If an institution waits until mid-2027 to complete its roadmap and then requires the four to five years estimated by institutions that already have one, critical assets may not be protected until 2031 or 2032.
Meanwhile, 52% of respondents consider the risks relevant within four to seven years, approximately from 2030.
The challenge therefore isn't simply meeting the roadmap recommendation.
It is the gap between planning and completing the migration.
What institutions can do now
Before trying to write the final roadmap, organisations can start building the information needed to make that roadmap credible.
That means naming an executive sponsor and operational owner, beginning cryptographic discovery, creating a machine-readable inventory, prioritising assets according to risk, building crypto-agility into operations and addressing external providers contractually.
Because ultimately:
A roadmap without an inventory contains intentions. A roadmap built on discovery and inventory can contain defensible dates.
FINMA Guidance 05/2026: Customer Briefing
Get the concise briefing covering FINMA's recommendations, survey findings and the practical steps organisations can start taking before mid-2027.