From awareness to accountability

FINMA’s guidance follows a survey of 60 Swiss financial institutions. The findings show a familiar gap. Most institutions recognise the risk, yet 72% said they had neither planned nor implemented measures related to quantum-safe encryption. Only 8% already had a specific quantum-safe roadmap in place.

FINMA is now pushing that conversation forward. Its recommendations include:

  • board-level ownership of the PQC strategy
  • a continuously updated cryptographic inventory
  • prioritisation of long-lived and sensitive data
  • stronger crypto-agility
  • clear migration milestones
  • closer coordination with technology and outsourcing partners

Quantum readiness is becoming a governance issue

One of the strongest signals in the guidance is the role assigned to boards and risk management. FINMA argues that existing governance and operational resilience requirements already cover risks created by quantum computing. Its PQC guidance does not introduce a completely separate risk category. Instead, it places quantum preparedness inside the responsibilities organisations already have.

Quantum readiness is increasingly becoming something leaders may need to explain, prioritise and demonstrate, not simply something technical teams can monitor in the background.

Crypto-agility moves up the agenda

FINMA also puts particular emphasis on crypto-agility: the ability to replace cryptographic algorithms without major architectural change. That is important because PQC migration is unlikely to be a single switch.

Algorithms will evolve. Standards will mature. Vendors will move at different speeds. Organisations that build flexibility into their systems now will be better positioned to respond when requirements change. FINMA even recommends making crypto-agility a requirement in new software and data outsourcing arrangements.

That brings quantum readiness directly into procurement and supplier management.

Why this matters beyond Switzerland

Financial institutions may be among the first organisations facing clear supervisory expectations, but they are unlikely to be the last. Across Europe and beyond, PQC is increasingly appearing in government roadmaps, cybersecurity guidance and sector-specific planning.

For organisations in regulated sectors, waiting for a hard legal deadline may mean waiting too long.

Read the original paper

Want to explore FINMA’s recommendations, the mid-2027 roadmap milestone and what they mean for financial institutions?

Read the full analysis

Related posts