Quantum computers are often still regarded as a thing of the future. However, FINMA makes it clear that the associated cyber risks must already be incorporated into the risk management of supervised institutions. With its new guidance, the supervisory authority expects banks, insurance companies and other financial market participants to strategically plan the transition to quantum-secure encryption methods. Those who wait until powerful quantum computers are available before taking action may already be too late.
Quantum computers are becoming a focus for financial market supervision
With the publication of Guidance 05/2026 on quantum computing, the Swiss Financial Market Supervisory Authority (FINMA) makes it clear that, from a regulatory perspective, quantum computers are no longer a distant future scenario. Admittedly, quantum computers relevant to cryptography do not yet exist. However, FINMA already expects supervised institutions to integrate the associated risks into their governance, risk management and information security management. The Guidance makes it clear that the existing, technology-neutral requirements for the management of operational risks also cover risks that may arise in future from powerful quantum computers.
No new obligations – but new expectations
It is worth noting that FINMA is not introducing any new regulatory requirements. Rather, it is setting out in more detail its expectations regarding the implementation of existing supervisory requirements. In the regulator’s view, financial institutions must already incorporate the risks posed by powerful quantum computers into their governance today and align their risk management accordingly. The guidance should therefore be understood not so much as new regulation but rather as a supervisory clarification of how existing requirements will be interpreted in future.
The real danger is already present today
Although powerful quantum computers are not yet available, the key risk already exists today. FINMA expressly draws attention to so-called ‘harvest now, decrypt later’ attacks. In such attacks, encrypted data is intercepted and stored today with the aim of decrypting it at a later date using a powerful quantum computer. This is particularly critical for data whose confidentiality must be guaranteed over many years, such as customer information, contractual documents or cryptographic keys. In FINMA’s view, it is precisely this information requiring long-term protection that should be prioritised for migration to quantum-secure methods.
The survey highlights a clear need for action
The guidance is based on a survey of 60 Swiss banks, insurance companies, asset managers and financial market infrastructures. The results reveal a clear discrepancy between risk awareness and actual preparedness. Whilst around two-thirds of the institutions surveyed expect to be affected by the cyber risks posed by quantum computing within the next seven years, An equal number expect RSA-2048 to be cracked by quantum computers within the next ten years. At the same time, however, 72 per cent have neither planned nor implemented any concrete measures to date. Only eight per cent have a specific roadmap for the transition to post-quantum cryptography.
What FINMA now expects from financial institutions
In FINMA’s view, preparations begin with a strategy approved by the board of directors, from which a concrete roadmap setting out priorities and timelines is derived. According to the authority’s recommendations, such a roadmap should be in place by mid-2027 at the latest. In addition, FINMA recommends a comprehensive risk analysis of all business processes, as well as the creation of a complete cryptography inventory. Only once it is known which encryption, signature and authentication methods are actually in use within the organisation can a risk-based migration strategy be developed.
Crypto-agility is becoming the new standard
A key term in the guidance is ‘crypto-agility’. This refers to the ability of IT systems to flexibly swap out cryptographic algorithms without having to make far-reaching changes to the software architecture. FINMA expressly recommends that this principle be taken into account right from the start when developing new applications and procuring new IT systems. This is intended to ensure that future cryptographic developments can be implemented at a reasonable cost.
Outsourcing contracts are also coming under scrutiny
FINMA is paying particular attention to dependencies on external service providers. In many cases, the migration to quantum-secure cryptography will only be possible in collaboration with cloud providers, software manufacturers or other ICT service providers. At the same time, the supervisory authority points out that responsibility for outsourced functions remains with the supervised institution. Institutions should therefore assess at an early stage whether existing contracts contain adequate provisions for the transition to post-quantum cryptography and whether requirements regarding providers’ crypto-agility should be enshrined in future procurement contracts.
Conclusion: Quantum readiness is becoming part of good corporate governance
With Guidance 05/2026, FINMA makes it clear that quantum computers are no longer solely a research topic. From the perspective of the financial market supervisor, the associated cyber risks are already an integral part of sound governance and risk management. Financial institutions should use the time remaining to take stock of their cryptographic procedures, identify data requiring long-term protection and develop a robust migration strategy. Early preparation not only serves the purposes of IT security but is also likely to increasingly become a benchmark for the supervisory assessment of operational resilience.