On 9 July 2026, FINMA published Supervisory Communication 05/2026 on quantum computing. This is not a research paper or a distant future scenario. It is a clear message to all supervised Swiss financial institutions: the time for simply observing developments is over. Organisations that do not start preparing a strategy for quantum-safe encryption today risk facing a compliance problem tomorrow.
FINMA based its assessment on a survey conducted between November 2025 and January 2026 among 60 banks, insurance companies, asset managers and financial market infrastructures. The results are sobering: the risks are widely recognised, but concrete measures are still missing in most organisations.
This article looks at what FINMA found, what it now expects from supervised institutions and how governance structures and GRC software can support the transition to post-quantum cryptography.
Key Takeaways
FINMA published its Guidance 05/2026 on quantum computing in July 2026 and expects supervised institutions to actively integrate the topic into their risk management.
According to the survey, 72 percent of respondents have not yet planned or implemented measures for quantum-safe encryption, while only 8 percent have a concrete migration plan. Around two thirds expect that a sufficiently powerful quantum computer could become capable of breaking common RSA-2048 encryption within ten years.
One of the most immediate concerns is the so-called “harvest now, decrypt later” scenario, in which encrypted data is intercepted today and stored until future quantum computers are able to decrypt it.
FINMA recommends action in five areas: strategy and roadmap, risk analysis and inventory, protection of critical data, crypto-agility and management of external service providers. A concrete PQC migration plan should be in place by mid-2027.
Why Quantum Computing Is Already a Compliance Topic
Quantum computers do not yet exist at a scale that threatens today’s commonly used encryption methods. That is true, but it is also a dangerous reason to delay action.
Many widely used public-key cryptographic methods, including RSA, ECDSA and EC-DH, rely on mathematical problems that are extremely difficult for classical computers to solve. A sufficiently powerful quantum computer could fundamentally change this.
The real challenge is that a migration to quantum-safe encryption will take years. It affects ICT systems, applications, infrastructure, digital signatures, authentication mechanisms and external interfaces. Organisations that wait until cryptographically relevant quantum computers are available may simply have too little time left to migrate safely.
There is also the “harvest now, decrypt later” risk. Attackers can intercept encrypted data today and store it with the intention of decrypting it in the future. Long-lived sensitive information such as customer data, contracts, transaction histories or identity information may therefore already be exposed to a future risk.
What the FINMA Survey Shows: Awareness Without Action
The survey results reveal a clear gap between risk awareness and operational readiness.
72 percent of the surveyed institutions have not yet planned or implemented any measures for the transition to quantum-safe encryption. 28 percent have at least made a strategic decision at executive management or board level, and 20 percent have an active project underway.
However, only 8 percent currently have a concrete migration plan with target dates. Those organisations generally expect a complete migration to take around four to five years.
At the same time, 43 percent of respondents have not yet made any decision on a future migration plan. FINMA therefore sees a growing need for action, especially given ongoing technological progress, long migration timelines and uncertainty around when cryptographically relevant quantum computers will become available.
The surveyed institutions also see opportunities in quantum computing, particularly in areas such as risk and portfolio analysis, transaction monitoring and algorithmic trading. However, almost two thirds expect that they will only use quantum computing applications themselves in eight years or more.
What FINMA Recommends: Five Priority Areas
FINMA Guidance 05/2026 outlines five areas that supervised institutions should integrate into their internal risk management.
Strategy and Roadmap
FINMA expects institutions to develop a board-supported strategy for the transition to quantum-safe encryption. This should be translated into a concrete implementation plan with milestones and target dates for the overall migration as well as for particularly critical business processes and data.
A PQC migration plan should be available by mid-2027 at the latest. It can form part of an existing cybersecurity strategy, but it should contain clear and specific objectives for the post-quantum transition.
Risk Analysis and Cryptographic Inventory
Before migrating anything, organisations need a clear picture of their current environment.
FINMA recommends analysing business processes and identifying all encryption, signature and authentication methods currently in use. The result should be a comprehensive cryptographic inventory covering ICT systems, applications, infrastructure and external interfaces, regardless of whether they are operated internally, outsourced or consumed as a service.
This inventory should make it possible to identify which algorithms are vulnerable to quantum attacks and where migration is required. It also needs to be kept continuously up to date.
Protection of Critical Data
FINMA recommends paying particular attention to information that requires long-term protection.
The “harvest now, decrypt later” risk should explicitly be included in risk assessments. Data that must remain confidential for ten, twenty or more years should be prioritised when preparing for post-quantum cryptography.
Because there is still limited long-term operational experience with PQC algorithms, many organisations are considering hybrid approaches that combine classical cryptography with post-quantum algorithms during the transition period.
Crypto-Agility
Crypto-agility is the ability of an ICT system to replace cryptographic algorithms quickly and flexibly without requiring major changes to the underlying software architecture.
FINMA recommends including crypto-agility as a requirement in new ICT developments and procurement processes.
The goal is straightforward: if an algorithm becomes insecure or a new standard is introduced, organisations should be able to switch without triggering another multi-year migration project. Crypto-agility is therefore not only a technical capability, but also a governance principle for resilient IT infrastructures.
External Service Providers
Outsourcing does not remove responsibility from the supervised institution. This also applies to the transition to post-quantum cryptography.
If an external provider operates systems, applications or infrastructure for a financial institution, that provider will also need to support the transition to quantum-safe cryptography.
FINMA therefore recommends including crypto-agility and future cryptographic requirements in new outsourcing agreements for software and data services and addressing existing contracts as early as possible.
What This Means for Compliance and Risk Teams
FINMA Guidance 05/2026 is not a new standalone legal obligation in the narrow sense. However, it makes clear that existing technology-neutral requirements for governance and risk management also apply to quantum risks.
For compliance and risk teams, this means quantum risks should become part of the existing cyber and operational risk framework rather than being managed in isolation.
Third parties and software suppliers also need to be included early in the planning process. The survey indicates that many institutions have already started contacting software providers or intend to do so, which reflects the strong dependency on external technology partners.
Another important point is timing. Governance preparation can and should move faster than the technical migration itself. A board decision, a strategy, a risk assessment and a cryptographic inventory can be established relatively quickly, while the technical transition may take several years.
GRC Software as the Structural Foundation for PQC Migration
All five FINMA recommendations have one thing in common: they depend on structured, documented and continuously maintained processes.
A cryptographic inventory covering systems, applications and external interfaces becomes difficult to manage without a central system. The same applies to quantum risk assessments, migration plans, responsibilities, milestones and evidence for supervisory reviews.
GRC software provides a structured foundation for this work. It can help integrate quantum risks into the existing risk management framework, connect relevant assets and third parties, assign responsibilities, document migration measures and provide management visibility into progress.
PQC should also not be treated as an isolated project. It forms part of a broader cyber risk environment that can overlap with other regulatory and governance requirements. Managing these topics in one integrated GRC environment can reduce duplication and prevent the creation of parallel documentation structures.
Zazoon: GRC Software for Tomorrow’s Requirements
At Zazoon, we have developed GRC software to translate complex regulatory requirements into structured and manageable processes.
For financial institutions preparing to implement FINMA’s quantum computing guidance, this means there is no need to create another isolated project silo. PQC requirements can instead be integrated into the existing risk management and governance environment.
Quantum risks, responsibilities, third-party dependencies, measures and supporting evidence can be managed centrally and made transparent for management, audit and supervisory discussions.
Conclusion: It Is Not About If, but When
Cryptographically relevant quantum computers do not yet exist. But the transition to quantum-safe encryption is a multi-year undertaking, and FINMA has made clear that preparation should begin now.
Institutions that do not have a PQC migration plan by mid-2027 may face increasing regulatory and technical pressure as migration windows become narrower.
The first step does not need to be a massive technical programme. It starts with governance: strategy, inventory, risk analysis and third-party requirements.
This is exactly where GRC software can provide the greatest value. Organisations that establish the right structures today will be better prepared for the cryptographic transition of tomorrow.
FAQ
What does FINMA require regarding quantum computing?
FINMA expects supervised financial institutions to actively integrate quantum risks into their existing risk and governance frameworks. This includes a clear strategy, a cryptographic inventory, risk assessments, the protection of particularly sensitive data, crypto-agility and the involvement of external service providers.
By when should a PQC migration plan be in place?
FINMA recommends developing a concrete migration plan for Post-Quantum Cryptography by mid-2027 at the latest. The plan should include target dates, milestones and priorities for critical systems, processes and data.
What does “Harvest now, decrypt later” mean?
This attack scenario involves encrypted data being intercepted and stored today so that it can potentially be decrypted once sufficiently powerful quantum computers become available. Data that needs to remain confidential for many years is therefore particularly at risk.
What is crypto-agility?
Crypto-agility describes the ability of IT systems to replace cryptographic methods flexibly and with minimal effort. This allows organisations to react more quickly when existing algorithms become insecure or new standards need to be introduced.
Why are external service providers important for PQC migration?
Many financial institutions rely on external providers for software, infrastructure and data services. However, responsibility for outsourced functions remains with the supervised institution. Suppliers and outsourcing partners therefore also need to be included in the PQC strategy and in requirements for crypto-agility.
What role does GRC software play in preparing for Post-Quantum Cryptography?
GRC software can help organisations centrally manage quantum risks, cryptographic dependencies, third parties, responsibilities and migration measures. This makes it easier to document progress, risks and evidence in a structured way and provide transparency for management, auditors and regulators.
Table of Contents
- Key Takeaways
- Why Quantum Computing Is Already a Compliance Topic
- What the FINMA Survey Shows: Awareness Without Action
- What FINMA Recommends: Five Priority Areas
- Strategy and Roadmap
- Risk Analysis and Cryptographic Inventory
- Protection of Critical Data
- Crypto-Agility
- External Service Providers
- What This Means for Compliance and Risk Teams
- GRC Software as the Structural Foundation for PQC Migration
- Zazoon: GRC Software for Tomorrow’s Requirements
- Conclusion: It Is Not About If, but When
- FAQ
- What does FINMA require regarding quantum computing?
- By when should a PQC migration plan be in place?
- What does “Harvest now, decrypt later” mean?
- What is crypto-agility?
- Why are external service providers important for PQC migration?
- What role does GRC software play in preparing for Post-Quantum Cryptography?