Becoming quantum-safe before it becomes necessary: FINMA reorders the quantum agenda for banks
On 9 July 2026, the Swiss Financial Market Supervisory Authority FINMA published its Guidance 05/2026 on quantum computing (cf. FINMA, 2026a, 2026b). The underlying survey of 60 Swiss financial institutions reveals an asymmetry that matters for any plan. Institutions expect to need the protective side of the technology earlier than they expect to draw on its business benefits. At the same time, 72 per cent of them have neither planned nor taken any measures towards quantum-safe encryption. Benjamin Schaefer sets out what the supervisor expects in concrete terms, why a research result from 2025 has shifted the timeline and why a cryptographic inventory and crypto-agility are the decisions that count over the next twelve months.
Some technologies create a need for action long before they become available. Quantum computing is one of them, and this is precisely where the planning task for decision-makers lies. A topic whose timing nobody knows, yet whose preparation takes years, does not fit into a conventional investment framework. In June 2025, this blog described the technology primarily as an opportunity, with considerable potential for portfolio optimisation, risk analysis and credit risk management, accompanied by technological, security-related and personnel-related challenges (Schaefer, 2025). A good year later, the emphasis has shifted. What stands in the foreground is no longer the potential, but the expectation of the supervisor.
Between November 2025 and January 2026, FINMA surveyed 60 Swiss financial institutions on the opportunities and risks of quantum computing, among them banks, insurers, managers of collective assets and financial market infrastructures (FINMA, 2026a; finews.ch, 2026). The authority summarises the result soberly in its media release. Institutions are aware of the cyber risks posed by cryptographically relevant quantum computers, yet in most cases a clear roadmap and sufficiently forward-looking planning for the migration to quantum-safe encryption are missing (FINMA, 2026a).
The decisive sentence follows immediately afterwards. In order to continue meeting the requirements on operational risks and resilience, FINMA identifies a «need for action in the risk management of numerous institutions» (FINMA, 2026a). Anyone familiar with the language of supervision reads this not as a suggestion but as a finding. The figures behind it are unambiguous. 72 per cent of the institutions surveyed have neither planned nor taken any measures towards quantum-safe encryption. 28 per cent have taken a strategic decision at executive board or board of directors level, and only 20 per cent additionally have a project under way (FINMA, 2026b).
The asymmetry between protection needs and benefits
The survey becomes instructive where it places two time horizons side by side. 69 per cent of institutions expect the cyber risks of quantum computing to become relevant for them within seven years, and around two thirds assume that a quantum computer will be able to break RSA-2048-bit encryption within 24 hours in ten years at the latest (FINMA, 2026b; cf. finews.ch, 2026). When it comes to their own benefit, the assessment is markedly more reserved. Just under two thirds do not expect to use quantum applications productively for another eight years or more (Fintechnews Switzerland, 2026). Figure 1 places both findings alongside each other.

This asymmetry is the most instructive finding of the survey. Institutions need the protective side of the technology earlier than they can put its benefits to work. In this constellation a classic business case that weighs return against expenditure does not carry far, because the return consists in assured confidentiality over a period whose end is open today. This is precisely why the supervisor moves the question out of the investment decision and into risk management, where uncertainty is the basic condition of the work in any case. The justification for the undertaking therefore draws not on the expected benefit but on the protection needs of the data and on the expectation of the supervisor.
A brief recap: why quantum computers change cryptography
Classical computers work deterministically, quantum computers probabilistically (Dietz et al., 2020). The difference begins with the smallest unit. A classical bit takes exactly one of two states at any given moment, either zero or one. A qubit, the computing unit of a quantum computer, can represent both states at the same time. This condition is referred to as «superposition» (Dietz et al., 2020; Shipilov, 2019). Added to this is «entanglement», in which two or more qubits are connected in such a way that the state of one immediately determines the state of the other, irrespective of the spatial distance between them (Dietz et al., 2020). Computing operations therefore act not on one qubit after another, but on many at once.
The actual leverage follows from these two properties. A system of N qubits can theoretically represent two to the power of N states in parallel, which for certain classes of problems produces an exponential advantage over N classical bits (Dietz et al., 2020; Schaefer, 2025). In practice this advantage is barely usable so far, because current systems remain error-prone and operate in the intermediate phase without full error correction described by Preskill (2018). A detailed introduction to how the technology works, where it can be applied and which challenges it raises is provided in the article from June 2025 (Schaefer, 2025).
The development becomes relevant to security through Shor’s algorithm, which showed as early as 1994 that very large numbers can be factorised efficiently using quantum methods (Shor, 1994). Widely used asymmetric schemes such as RSA and elliptic curve cryptography rest precisely on the practical infeasibility of this task. Affected are therefore key exchange and digital signatures, that is, the building blocks on which e-banking sessions, payment messages, certificate chains and secured communication with service providers are built (cf. BSI, 2026). Symmetric schemes are less exposed and can essentially be secured through longer keys (cf. Auer et al., 2024). A quantum computer is accordingly regarded as «cryptographically relevant» only once it is powerful enough to actually break these schemes. Such machines do not exist today, yet in FINMA’s assessment technical progress has gained momentum, so that their development is to be expected in the coming years (FINMA, 2026b).
The point that matters most for planning is a different one. The need for protection does not begin with the first powerful quantum computer, but already today. The attack pattern known as «harvest now, decrypt later», sometimes also called «store now, decrypt later», proceeds in two steps. First, attackers intercept encrypted data, for instance from network traffic, from copied backups or from extracted archives, and store it without being able to read it. Once a sufficiently powerful quantum computer becomes available later on, they decrypt the collected material retrospectively (Auer et al., 2024; Noone, 2023). Confidentiality is therefore decided not at the moment of access, but by the question of how long the data has to remain protected. It is exactly this protection period that forms the planning parameter.
For financial institutions this pattern shifts the relevant time axis. What counts is not the release date of the technology, but the period over which data has to remain confidential. Anyone who has to protect client files, credit records or contractual documents for ten or fifteen years should begin doing so today, following this logic. Mosca (2018) translated this relationship into a simple inequality. Once the protection period of the data and the duration of the migration together extend beyond the time until a cryptographically relevant quantum computer appears, the start belongs in the present. Figure 2 applies this calculation to the time frames currently known.

A research result that changed the calculation
Why the need for action is increasing precisely now can be read from the research. Gidney and Ekerå (2021) estimated that an RSA-2048-bit number could be factorised in around eight hours using some 20 million noisy qubits, an order of magnitude that long relativised the urgency. In May 2025, Gidney presented a new estimate. Under the same hardware assumptions, this analysis finds that fewer than one million noisy qubits are sufficient to solve the same task in less than a week (Gidney, 2025). The estimate of the qubit requirement thus falls by roughly a factor of twenty, paid for with a longer running time and without a single new chip having to be built.
The cause of this shift is remarkable. It stems not from the hardware but from better algorithms and more efficient error correction (cf. Gidney, 2025). Progress in this field has been particularly rapid in recent years, for instance when error correction below the critical threshold of the surface code was demonstrated (Google Quantum AI and Collaborators, 2025). In parallel, the hardware side remains ambitiously scheduled. For 2029, IBM announces Starling as, by its own account, the first large-scale fault-tolerant quantum computer, intended to execute around twenty thousand times more operations than current systems (IBM, 2025). For institutions this yields an insight relevant to planning. Their own assessment can change within a year without anything having changed in the available hardware. Those who rely on crypto-agility make themselves independent of such shifts.
What FINMA expects in concrete terms
The guidance introduces no new set of rules. In the authority’s view, the existing technology-neutral and principle-based requirements on governance and risk management already cover the risks arising from the development of powerful quantum computers (Lexology, 2026). This makes the degree of specification all the more notable. FINMA describes six possible areas of measures, namely a clear strategy and roadmap for the migration to quantum-safe encryption, an institution-specific risk analysis, the creation of a cryptographic inventory, the protection of critical data against attacks following the «harvest now, decrypt later» pattern, the involvement of external service providers and the transition to crypto-agility (FINMA, 2026a, 2026b). The roadmap should be in place by mid-2027 at the latest (FINMA, 2026b; cf. Fintechnews Switzerland, 2026).
Read soberly, this list reveals a shift in responsibility. Five of the six points concern governance, architecture, data management and procurement rather than cryptography itself. Selecting algorithms is the smallest part of the work, because the standards for it have long been available. With ML-KEM for key agreement and ML-DSA and SLH-DSA for signatures, NIST has created the algorithmic foundation (NIST, 2024). The open question is not which schemes will be used, but at which points in the institution they can be used at all.
One observation in the margins deserves attention, because it characterises the nature of the document. In the guidance the term opportunities appears only twice, whereas risks and its compounds are mentioned more than twenty times (finews.ch, 2026). The supervisor has thus clearly chosen its perspective. For institutions this means that they have to occupy the opportunity side themselves if they want it occupied at all.
Regulatory convergence rather than a Swiss special case
FINMA is not acting in isolation. Only two days before its publication, on 7 July 2026, ECB Banking Supervision addressed the management bodies of significant institutions in letter SSM-2026-0301 and required a comprehensive action plan for countering AI-enabled cyberattacks, to be submitted to the responsible Joint Supervisory Teams by 31 October 2026 (European Central Bank, 2026). At the same time, the European Systemic Risk Board warned of systemic cyber risks arising from frontier artificial intelligence models (A&O Shearman, 2026). On post-quantum cryptography, the ECB announces a separate letter and notes that its adoption requires a longer time horizon, has to begin now and needs to be funded strategically over a period of years (European Central Bank, 2026).
This sequence is more significant than it appears at first glance. European supervision treats AI-enabled attacks as the acute problem and the cryptography migration as the structural one. Both agendas compete for the same budgets, the same architectural initiatives and the same scarce specialists. Institutions that plan and budget for both agendas together keep even the slower undertaking on schedule.
In parallel, deadlines are emerging that function as a de facto market standard, even where they do not apply directly to Swiss institutions. In the February 2026 update of its Technical Guideline TR-02102, the German Federal Office for Information Security formulated an expiry date for classical asymmetric encryption schemes for the first time. For key agreement, their exclusive use is to be recommended only until the end of 2031, for highly sensitive applications until the end of 2030, and for classical signature schemes until the end of 2035, in each case followed by a hybrid combination with post-quantum cryptography (BSI, 2026). At European level, the coordinated roadmap of the NIS Cooperation Group recommends that member states implement first steps and national migration strategies by the end of 2026 and move critical infrastructure to quantum-safe schemes by 2030 (NIS Cooperation Group, 2025). For institutions with EU business, international payment connections or European software, these dates help determine their own timetable, because protocols, certificates and product versions will follow them.
The operational core: inventory, hybrid schemes, crypto-agility
The first task sounds unspectacular and is nevertheless the bottleneck. An institution needs to know where which cryptography is in use within it. FINMA expects an inventory across all business processes that records encryption, signature and authentication schemes and includes ICT systems, applications, infrastructure and newer technologies such as distributed ledger applications, irrespective of whether these are operated in-house, outsourced or obtained as a service (FINMA, 2026b; cf. Fintechnews Switzerland, 2026). Only on this basis is it possible to assess which algorithms are vulnerable to quantum attacks and in which order they need to be replaced. The effort involved is regularly underestimated, because cryptographic schemes are embedded not only in core applications but also in certificates, VPN connections, hard-coded keys and in-house developments. The European roadmap therefore explicitly highlights cryptographic inventories and dependency maps as the foundation of any migration planning (cf. NIS Cooperation Group, 2025).
The second step is to prioritise by protection needs and protection period rather than by system criticality alone. Data that has to remain confidential over the long term is to be protected first. For this purpose FINMA recommends a hybrid solution, that is, the combination of a classical with a quantum-safe algorithm, so that confidentiality is preserved even if one of the two schemes becomes insecure (FINMA, 2026b; cf. Fintechnews Switzerland, 2026). The same logic leads to the third and strategically most important point. Because schemes considered secure today may unexpectedly fall in future, the supervisor calls for crypto-agility, that is, the ability to replace cryptographic schemes without fundamentally rebuilding the software architecture (FINMA, 2026b; cf. Fintechnews Switzerland, 2026).
This brings to the fore a principle that has already been described in this blog in other contexts, namely the decoupling of function and implementation (cf. Schaefer, 2026). Crypto-agility requires that cryptographic operations be obtained through clearly defined interfaces and central services instead of being hard-wired into applications, scripts and interface configurations. Institutions that have consistently developed their architecture towards modularity in recent years start with a structural advantage here. For everyone else, the migration is less a security project than an architecture programme with a supervisory need for evidence.
Service providers determine the pace
In a market with a high degree of outsourcing, a large share of the cryptography concerned lies outside the institution’s own house. It sits in core banking platforms, in business process outsourcing, in cloud services, in hardware security modules and in the connections to financial market infrastructures (cf. Schaefer, 2026). Accordingly, FINMA expects institutions to satisfy themselves that their service providers are also carrying out the transition to quantum-safe cryptography. Crypto-agility is to become a prerequisite for all new outsourcing arrangements in the area of software and data, and is to be incorporated into the requirements of existing arrangements at the earliest possible opportunity (FINMA, 2026b; cf. Fintechnews Switzerland, 2026). In addition, the authority recommends long-term planning with third-party providers and the early contractual anchoring of corresponding measures (cf. FINMA, 2026b).
In practice this means that an institution’s migration speed depends not only on its own roadmap but on the roadmap of its providers, and on the negotiating position from which it can call for one. For small and medium-sized institutions on standardised platforms the consequence is obvious. They will need to address the topic collectively, for instance through existing user communities or through sector-level bodies such as the Swiss Financial Sector Cyber Security Centre, whose cooperation with the Federal Office for Cybersecurity is explicitly mentioned in the annual report for 2025 (BACS, 2026). For providers, in turn, demonstrated crypto-agility can become a differentiating feature that can be examined in tender processes.
The benefits remain, they simply arrive later
Throughout all of this the opportunity side easily slips from view, even though it formed the starting point of the discussion. The institutions surveyed by FINMA see the greatest business value of the technology in risk and portfolio analysis, in transaction monitoring, in algorithmic trading and in the generation of better random numbers (FINMA, 2026b; cf. Fintechnews Switzerland, 2026). This assessment matches the fields of application that have been discussed in research for years, from portfolio optimisation to the acceleration of Monte Carlo simulations in risk management (Orús et al., 2019; Schaefer, 2025). Economically the field remains attractive. McKinsey puts the global value potential of quantum computing by 2035 at 1.3 to 2.7 trillion US dollars, of which up to 600 billion US dollars are expected to fall to the financial industry (McKinsey & Company, 2026; cf. Fintechnews Switzerland, 2026).
Such figures are scenarios and not planning parameters. What is instructive above all is their stability. The order of magnitude of the expected benefit has barely changed over several years (cf. Schaefer, 2025), whereas the protective side has developed from an abstract warning into a specified supervisory expectation with a time horizon. For prioritisation within the institution this yields a clear sequence. Use cases can be observed, tested in collaborations and, where necessary, deferred. The migration of the cryptography cannot be deferred, because its lead time is determined by supervisory deadlines and by technological developments rather than by the institution’s own planning calendar.
Conclusion
For financial institutions, quantum computing has moved from a topic of the future to a management task with a deadline. Guidance 05/2026 creates no new obligations but shifts the burden of justification. Anyone unable to present a robust roadmap by mid-2027 has to expect to explain to the supervisor why the requirements on operational risks and resilience continue to be met (cf. FINMA, 2026a, 2026b). The actual work lies not in the selection of algorithms but in three decisions that need to be taken now. First, it has to be settled who owns the cryptographic inventory within the institution, and with what mandate. Second, it has to be determined which data holdings are to be secured in hybrid form first on the basis of their protection period. Third, it has to be established from when crypto-agility applies as a binding requirement in every architecture and sourcing decision.
What is particular about this task is the twofold origin of its time pressure. One part is dated and set by supervision. It ranges from the roadmap by mid-2027 and the European timetable by the end of 2026 through to the expiry dates for classical schemes at the end of the decade (cf. BSI, 2026; FINMA, 2026b; NIS Cooperation Group, 2025). The other part is undated, because nobody knows when a cryptographically relevant quantum computer will become available. The example of the qubit estimate falling by a factor of twenty shows how quickly this second part can shift, and indeed through better thinking alone rather than through better machines (cf. Gidney, 2025). Those who plan towards the dated deadlines meet the requirements. Those who also take the undated part into account gain additional freedom of action. A one-off changeover is therefore the wrong objective. Institutions that instead build the ability to change their cryptography repeatedly and in an orderly manner will master not only this changeover but also the next one.
References
A&O Shearman. (2026). ECB requires significant institutions to address AI-enabled cybersecurity threats. https://www.aoshearman.com/en/insights/ecb-requires-significant-institutions-to-address-ai-enabled-cybersecurity-threats
Auer, R., Dupont, A., Gambacorta, L., Park, J. S., Takahashi, K., & Valko, A. (2024). Quantum computing and the financial system: Opportunities and risks (BIS Papers No. 149). Bank for International Settlements. https://www.bis.org/publ/bppdf/bispap149.pdf
Bundesamt für Cybersicherheit BACS. (2026). Jahresbericht Bundesamt für Cybersicherheit 2025: Konsolidierte Strukturen, gestärkte Wirkung. https://www.ncsc.admin.ch/ncsc/de/home/aktuell/im-fokus/2026/jahresbericht.html
Bundesamt für Sicherheit in der Informationstechnik BSI. (2026). BSI empfiehlt Ende klassischer asymmetrischer Verschlüsselungsverfahren. Press release of 11 February 2026. https://www.bsi.bund.de/DE/Service-Navi/Presse/Pressemitteilungen/Presse2026/260211_Ende_klassischer_Verschluesselungsverfahren.html
Dietz, M., Henke, N., Backes, J., Moon, J., Pautasso, L., & Sadeque, Z. (2020). How quantum computing could change financial services. McKinsey & Company. https://www.mckinsey.com/industries/financial-services/our-insights/how-quantum-computing-could-change-financial-services
Eidgenössische Finanzmarktaufsicht FINMA. (2026a). FINMA-Aufsichtsmitteilung zu Quantum Computing. Media release of 9 July 2026. https://www.finma.ch/de/news/2026/07/20260709-mm-am-05-26/
Eidgenössische Finanzmarktaufsicht FINMA. (2026b). FINMA-Aufsichtsmitteilung 05/2026: Quantum Computing. https://www.finma.ch/de/~/media/finma/dokumente/dokumentencenter/myfinma/4dokumentation/finma-aufsichtsmitteilungen/20260709-finma-aufsichtsmitteilung-05-2026.pdf?sc_lang=de&hash=59B9081AC61161D34364FEA2A69B3574
European Central Bank. (2026). Addressing AI-enabled cybersecurity threats. Letter to significant institutions (SSM-2026-0301) of 7 July 2026. https://www.bankingsupervision.europa.eu/press/letterstobanks/shared/pdf/2026/ssm.2026_letter_on_AI_enabled_cybersecurity_threats.en.pdf
finews.ch. (2026). Finma erteilt Ratschläge zu Quantum Computing. https://www.finews.ch/news/finanzplatz/72895-finma-aufsichtsmitteilung0526-quantencomputer-cyberrisiken-umfrage-empfehlungen-kryptografie
Fintechnews Switzerland. (2026). FINMA releases guidance to help institutions mitigate quantum computing risks. https://fintechnews.ch/fintech/finma-releases-guidance-to-help-institutions-mitigate-quantum-computing-risks/84663/
FIRM Frankfurter Institut für Risikomanagement und Regulierung. (2026). Post-Quantum-Kryptografie und ihre Auswirkungen auf den Finanzsektor. https://firm.fm/paper/post-quantum-kryptografiepqk-und-ihre-auswirkungen-auf-den-finanzsektor/
Gidney, C. (2025). How to factor 2048 bit RSA integers with less than a million noisy qubits (arXiv:2505.15917). Google Quantum AI. https://arxiv.org/abs/2505.15917
Gidney, C., & Ekerå, M. (2021). How to factor 2048 bit RSA integers in 8 hours using 20 million noisy qubits. Quantum, 5, 433. https://doi.org/10.22331/q-2021-04-15-433
Google Quantum AI and Collaborators. (2025). Quantum error correction below the surface code threshold. Nature, 638, 920 to 926. https://doi.org/10.1038/s41586-024-08449-y
IBM. (2025). IBM lays out clear path to fault-tolerant quantum computing. IBM Quantum Computing Blog, 10 June 2025. https://www.ibm.com/quantum/blog/large-scale-ftqc
Lexology. (2026). FINMA guidance warns Swiss financial institutions should prepare for post-quantum cyber risks. https://www.lexology.com/library/detail.aspx?g=4fd1d749-4895-4c39-9629-e5424865eeb5
McKinsey & Company. (2026). Quantum Technology Monitor 2026: A commercial tipping point. https://www.mckinsey.com/capabilities/mckinsey-technology/our-insights/mckinsey-quantum-technology-monitor-2026-a-commercial-tipping-point
Mosca, M. (2018). Cybersecurity in an era with quantum computers: Will we be ready? IEEE Security & Privacy, 16(5), 38 to 41. https://doi.org/10.1109/MSP.2018.3761723
NIS Cooperation Group. (2025). A coordinated implementation roadmap for the transition to post-quantum cryptography. European Commission. https://digital-strategy.ec.europa.eu/en/library/coordinated-implementation-roadmap-transition-post-quantum-cryptography
National Institute of Standards and Technology. (2024). FIPS 203: Module-lattice-based key-encapsulation mechanism standard. Complemented by FIPS 204 on ML-DSA and FIPS 205 on SLH-DSA. https://csrc.nist.gov/pubs/fips/203/final
Noone, G. (2023). Are harvest now, decrypt later cyberattacks actually happening? Tech Monitor. https://www.techmonitor.ai/hardware/quantum/harvest-now-decrypt-later-cyberattack-quantum-computer
Orús, R., Mugel, S., & Lizaso, E. (2019). Quantum computing for finance: Overview and prospects. Reviews in Physics, 4, 100028. https://doi.org/10.1016/j.revip.2019.100028
Preskill, J. (2018). Quantum computing in the NISQ era and beyond. Quantum, 2, 79. https://doi.org/10.22331/q-2018-08-06-79
Schaefer, B. (2025). Quantencomputing in der Finanzwirtschaft: Grundlagen, Potenziale und Herausforderungen. cc-bei.news. https://cc-bei.news/quantencomputing-in-der-finanzwirtschaft-grundlagen-potenziale-und-herausforderungen/
Schaefer, B. (2026). (R)Evolution der Kernbankensysteme: Transformationsstrategien der Anbieter in der Schweiz. cc-bei.news. https://cc-bei.news/revolution-der-kernbankensysteme-transformationsstrategien-der-anbieter-in-der-schweiz/
Shipilov, A. (2019). The real business case for quantum computing. INSEAD Knowledge. https://knowledge.insead.edu/strategy/real-business-case-quantum-computing
Shor, P. W. (1994). Algorithms for quantum computation: Discrete logarithms and factoring. In Proceedings 35th Annual Symposium on Foundations of Computer Science (pp. 124 to 134). IEEE. https://doi.org/10.1109/SFCS.1994.365700
