On 9 July 2026, Switzerland’s financial regulator, FINMA, published Guidance 05/2026 on quantum computing – a clear signal that a national financial regulator is prepared to translate post-quantum cryptography from a research topic into a supervisory expectation.
The guidance is grounded in a real survey, not a hypothetical. Between November 2025 and January 2026, FINMA surveyed 60 authorised banks, insurance companies, managers of collective assets and financial market infrastructures on how they see the risks and opportunities of quantum computing. The results are worth sitting with.
What the survey found
Swiss financial institutions are not in denial about the threat. Around two-thirds of respondents expect to be directly affected by quantum-related cyber risk within seven years, and a similar proportion expect that, within ten years at the latest, a quantum computer will be able to break RSA 2048-bit encryption in under 24 hours. Asked where the risk lies, institutions pointed to data security first, followed by incomplete migration to quantum-safe encryption, a lack of in-house expertise, “harvest now, decrypt later” attacks, and interoperability with legacy systems.
Awareness, though, has not translated into readiness.
72% of institutions surveyed have not yet planned or implemented any measures relating to quantum-safe encryption.
Only 28% have made a strategic decision at board or executive level, and just 8% have an actual roadmap – those that do typically expect four to five years to get critical data and processes quantum-safe. Nearly half plan to build a roadmap within the next one to three years; 43% haven’t decided when they’ll start.
There was clearer consensus on two specific practices: 73% of institutions rate crypto-agility as important or very important, and 76% see high or very high value in building a cryptographic inventory. 60% are already in contact with software suppliers about PQC migration, or plan to be.
What FINMA is asking institutions to do
FINMA’s recommendations sit within its existing, technology-neutral principles for governance and operational risk management – this is guidance on how those principles apply to quantum risk, not a new law. Five areas stand out:
- Strategy and roadmap. Work should be grounded in a board-adopted strategy, with an implementation plan setting milestones and target dates for both full migration and the migration of critical business processes. FINMA recommends a PQC roadmap be in place by mid-2027 at the latest.
- Risk analysis and inventory. Institutions should analyse all business processes – across ICT systems, applications, infrastructure and newer technologies such as distributed ledger technology – to build a comprehensive inventory of cryptographic methods in use: encryption in transit and at rest, digital signatures, key management and authentication. That inventory should flag which algorithms are quantum-vulnerable (FINMA names RSA, ECDSA, EdDSA, DH and EC-DH) and needs to be kept continuously current.
- Critical data. Institutions should identify data requiring long-term confidentiality, integrity or non-repudiation guarantees, and prioritise it against “harvest now, decrypt later” risk. In the short to medium term, FINMA notes that a hybrid approach, combining a classical algorithm with a post-quantum one, is widely recommended as the safer path while real-world experience with PQC algorithms is still limited.
- Crypto-agility. Systems should be built or procured with the ability to swap cryptographic algorithms without major architectural change – a requirement that outlasts any single migration, since today’s post-quantum algorithms may themselves need replacing in time.
- External service providers. Responsibility for outsourced functions stays with the institution that outsourced them. FINMA recommends making crypto-agility a contractual requirement for new outsourcing arrangements in software and data, and building it into existing arrangements at the earliest opportunity.
The pattern is bigger than Switzerland
FINMA is not acting in isolation. The guidance leans on the same finalised NIST standards – ML-KEM (FIPS 203), ML-DSA (FIPS 204) and SLH-DSA (FIPS 205) – that underpin post-quantum migration guidance from national bodies across Europe, and it cites a 2025 joint statement on the PQC transition backed by partners from 21 European states. What’s notable here is the shift in form: a financial supervisor turning survey data on its own regulated sector into a recommended roadmap, with a date attached.
Why this maps directly onto ECEM
Read closely, FINMA’s five recommendations describe a single continuous discipline, not five separate projects. A risk analysis producing a comprehensive, continuously updated cryptographic inventory. Critical data identified and prioritised. Migration plans sized to actual risk. Crypto-agility built in rather than bolted on. Outsourced dependencies brought into scope, not left outside it.
That is what Enterprise Cryptographic Exposure Management (ECEM) is designed to do – discover cryptography across the estate, inventory it as a living Cryptography Bill of Materials (CBOM), assess and prioritise by real business risk, and manage the transition and ongoing monitoring as one continuous process rather than a one-off project.
For any FINMA-supervised institution, the mid-2027 roadmap recommendation is close enough that the inventory step – the part 76% of respondents already say they value most – needs to start now, not once the roadmap itself is due.