
A financial institution trying to work out what quantum readiness actually requires of it will quickly run into three different bodies saying three different things, in three different registers. NIST sets technical standards but doesn’t supervise anyone. FINMA issues binding guidance to Swiss financial institutions. NCSC publishes national guidance for UK organisations generally. None of them share an enforcement mechanism, and none of them share a deadline. Strip away the differences, though, and the substance underneath converges on the same list.
What NIST requires: the technical foundation
NIST finalised its post-quantum standards – ML-KEM (FIPS 203), ML-DSA (FIPS 204) and SLH-DSA (FIPS 205) – in August 2024, and its draft transition guidance signals deprecating RSA and ECC by 2030, disallowing them by 2035. NIST doesn’t regulate financial institutions directly. What it does is supply the technical foundation that every other body in this piece builds its own guidance on top of – when FINMA or NCSC reference “post-quantum cryptography,” they mean these algorithms.
What FINMA requires: a Swiss regulator’s binding guidance
Switzerland’s financial regulator published Guidance 05/2026 on quantum computing in July 2026, grounded in a survey of 60 authorised institutions. The findings were candid: 72% of respondents had no measures planned or implemented, even though 76% rated a cryptographic inventory as high or very high value. FINMA’s recommendations condense to five requirements – a board-adopted strategy and roadmap (due by mid-2027 at the latest), a comprehensive and continuously current cryptographic inventory flagging quantum-vulnerable algorithms by name (RSA, ECDSA, EdDSA, DH, EC-DH), identification of long-lived critical data prioritised against harvest-now-decrypt-later risk, crypto-agility built into new systems, and outsourced dependencies brought into scope contractually rather than left outside it.
What NCSC requires: a UK national timeline
The UK’s National Cyber Security Centre sets out three milestones rather than a single deadline: a completed discovery exercise and initial migration plan by 2028, early migration activity and a thorough roadmap by 2031, and full migration by 2035. Large organisations running their own infrastructure – which describes most sizeable financial institutions – fall into the group NCSC expects to need two to three years of preparatory work alone. Worked backwards from 2028, that puts the realistic start line in 2025 or 2026 for anyone who hasn’t already begun.
Where the three actually converge
Despite the different levers – a standards body, a supervisory regulator, a national cyber agency – all three land on the same underlying checklist:
- A comprehensive, continuously current cryptographic inventory – not a point-in-time audit that goes stale the day it’s finished.
- Long-lived or critical data identified and prioritised specifically against harvest-now-decrypt-later exposure.
- A board-level roadmap with actual dates attached, not an open-ended intention to “get to it.”
- Crypto-agility treated as a design and procurement requirement, including for outsourced and third-party dependencies.
Notably, none of the three require picking a final algorithm today. All three require knowing what you’re actually running, today.
What this means in practice
For a financial institution operating across jurisdictions, “what’s actually required” isn’t three competing checklists – it’s the same one, described three times by bodies with different reach. DORA and PCI DSS 4.0 add sector-specific teeth in the EU and payments contexts respectively, without changing this underlying list: neither mandates a specific replacement algorithm either, and both expect the same inventory-and-governance evidence FINMA and NCSC describe directly.
The practical starting point is identical across every framework in this piece: Enterprise PQC Discovery producing a living Enterprise CBOM. It’s the prerequisite every other item on this checklist quietly depends on, and the one FINMA’s own survey shows most institutions value and haven’t yet built.
Further reading: FINMA’s full guidance, in detail, NCSC’s migration timeline, in detail, and Quantum Sentinel for financial services.