EY refers to the global organization, and may refer to one or more, of the member firms of Ernst & Young Limited, each of which is a separate legal entity. Ernst & Young Limited is a Swiss company with registered seats in Switzerland providing services to clients in Switzerland.
How EY can help
-
Discover how EY's cybersecurity, strategy, risk, compliance & resilience teams can help your organization with its current cyber risk posture and capabilities.
Read more
FINMA concludes that further developing risk management and change management is advisable for many institutions in order to remain compliant with existing operational risk and resilience requirements.
Understanding your institution’s quantum exposure
While FINMA Guidance 05/2026 applies to all FINMA-supervised institutions, the urgency is greatest for organizations that:
- Hold long-lived sensitive data such as client identifiers, contracts, health data or long-duration insurance records.
- Rely heavily on public-key cryptography (RSA, ECDSA, EdDSA, Diffie-Hellman and EC-Diffie-Hellman) for encryption, digital signatures, authentication, and secure communications.
- Depend on external service providers, cloud environments or software suppliers whose cryptographic capabilities and migration timelines are only partially under their control.
For these institutions, quantum computing represents a tangible business risk today, especially with the threat of "harvest now, decrypt later", whereby information encrypted today may be collected and retained by adversaries with the expectation that future quantum computers will be able to decrypt it. As a result, PQC readiness should not be viewed solely as a future technology initiative, but as a current risk management priority for protecting critical information assets and business processes.