Businesswoman working on project on digital tablet in office

How Swiss firms should prepare for post-quantum cryptography


FINMA Guidance 05/2026 sets supervisory expectations on quantum-safe cryptography. Learn what Swiss banks and insurers should do now.


In brief

  • Only 8% of Swiss financial institutions have a post-quantum cryptography roadmap; FINMA recommends one by mid-2027 under existing resilience rules.
  • Harvest now, decrypt later attacks make long-term sensitive data an immediate concern that demands quantum-safe encryption today.
  • A cryptographic inventory, crypto-agility and PQC-ready outsourcing form the foundation of a successful transition to quantum-safe algorithms.

FINMA Guidance 05/2026 sets clear supervisory expectations on post-quantum cryptography for Swiss financial institutions. Published on 9 July 2026, it is a supervisory communication under existing, technology-neutral resilience rules. Swiss financial institutions should have a board-approved PQC roadmap in place by mid-2027 and begin adapting their processes, policies and technologies.

What is FINMA Guidance 05/2026?

FINMA Guidance 05/2026 is a supervisory communication (Aufsichtsmitteilung) published by the Swiss Financial Market Supervisory Authority. It sets out how supervised financial institutions should manage the cyber risks arising from cryptographically relevant quantum computers (CRQC). It is not a circular. Instead, it explains how existing, principles-based requirements on governance, operational risk and operational resilience already cover post-quantum cryptography risks.

The guidance follows a FINMA survey of 60 authorized banks, insurance companies, managers of collective assets and financial market infrastructures conducted between November 2025 and January 2026. The results show a wide gap between awareness and action.

The survey shows some key data points for Swiss financial institutions:

FINMA concludes that further developing risk management and change management is advisable for many institutions in order to remain compliant with existing operational risk and resilience requirements.

 

Understanding your institution’s quantum exposure

While FINMA Guidance 05/2026 applies to all FINMA-supervised institutions, the urgency is greatest for organizations that:

  • Hold long-lived sensitive data such as client identifiers, contracts, health data or long-duration insurance records.
  • Rely heavily on public-key cryptography (RSA, ECDSA, EdDSA, Diffie-Hellman and EC-Diffie-Hellman) for encryption, digital signatures, authentication, and secure communications.
  • Depend on external service providers, cloud environments or software suppliers whose cryptographic capabilities and migration timelines are only partially under their control.

For these institutions, quantum computing represents a tangible business risk today, especially with the threat of "harvest now, decrypt later", whereby information encrypted today may be collected and retained by adversaries with the expectation that future quantum computers will be able to decrypt it. As a result, PQC readiness should not be viewed solely as a future technology initiative, but as a current risk management priority for protecting critical information assets and business processes.

ey.com-graphic-template 11

The five building blocks of quantum readiness

FINMA's guidance highlights five key priorities for organizations preparing for the transition to post-quantum cryptography. While full migration will take years, early action can significantly reduce future complexity, costs and risks. Establishing the right foundations today is therefore critical to achieving a successful PQC migration.

The quantum threat does not change the rules of operational resilience. It reinforces the need to apply existing cyber and cryptographic risk management requirements to a new technological challenge.

What should Swiss financial institutions do next?

ey.com-graphic-template 11

Read the latest FINMA Guidance 05/2026 here:


Summary

FINMA Guidance 05/2026 clarifies how existing operational resilience regulations apply to quantum computing risks and sets a clear direction for Swiss financial institutions. A board-approved PQC strategy, a live cryptographic inventory, crypto-agility as a design principle and PQC-ready outsourcing arrangements are the practical building blocks to ensure the protection of data. Depending on where the largest gaps exist, these capabilities can be developed internally or with the support of an external partner that brings specialized expertise and additional capacity. Either way, the message is clear: the time to act is now!

Acknowledgement

Many thanks to Robert Alther and Joseph Abboud for their valuable contribution to this article.


FAQs

Related articles

As technology and risks evolve, how will AI tools elevate your cyber team?

Unlock your cyber team's potential with EY's four AI personas. Enhance effectiveness and prevent threats by integrating AI tools today.

Will you see the next cyber risk coming?

We share highlights from the EY Swiss Cybersecurity Leadership Insights Study and explore how Swiss companies compare at a global level.

If quantum’s the next leap forward, what small steps can you take now?

First-movers are using quantum computing to speed up their calculations. Are you ready for its opportunities and risks?


Explore how EY can help you with Cybersecurity

Secure Creators can innovate and adopt emerging technology without compromising cybersecurity. Explore our service offering.

Teamworking colleagues in high tech data center managing and maintaining databases

About this article

Request for proposal (RFP) - exclusively for Switzerland

|

Submit your request now!