A specialist practice of Silver Brain AI.silverbrain.ai
FINMA Supervisory Guidance 05/2026
Post-quantum resilience for Swiss financial institutions.
FINMA has put the transition to quantum-safe cryptography on the management agenda. We help institutions turn cryptographic risk, dependencies and regulatory expectations into a structured, executable transition roadmap.
A board-adopted PQC roadmap, by mid-2027 at the latest.
On 9 July 2026, FINMA published Supervisory Guidance 05/2026. It pairs a survey of 60 authorised banks, insurers, managers of collective assets and financial market infrastructures with recommendations for the migration to quantum-safe cryptography.
It is a supervisory communication, not a new circular. Institutions are expected to address quantum-related risks in a timely manner under existing governance, operational-risk and resilience requirements, and FINMA will give the topic more weight in its ongoing supervision.
What FINMA expects
Five areas the roadmap has to cover.
The scope is migration to quantum-safe algorithms (NIST FIPS 203, 204 and 205). Quantum key distribution and business applications of quantum computing are explicitly out of scope.
Guidance 3.1
Strategy and roadmap
A board-adopted strategy and implementation plan with milestones, priorities and target dates, for critical processes and for full migration.
Guidance 3.2
Risk analysis and inventory
Every business process analysed for the encryption, signature and authentication in use, in-house, outsourced or as a service, in a continuously updated cryptographic inventory.
Guidance 3.3
Critical data
Data that needs long-term confidentiality, integrity or non-repudiation identified and prioritised. Hybrid classical-plus-PQC schemes are recommended for the transition.
Guidance 3.4
Crypto-agility
The ability to swap cryptographic algorithms without major architectural change, recommended as a requirement for systems still to be procured or built.
Guidance 3.5
External providers
Responsibility stays with the institution. PQC is anchored in contracts and release plans, and crypto-agility becomes a prerequisite for new outsourcing.
References to FINMA guidance are provided for context and do not imply endorsement or affiliation.
Sector readiness
Most of the sector has yet to start.
These figures describe the sector, not any single institution. The mid-2027 recommendation puts roadmap preparation on the management agenda whatever the starting point.
72%have neither planned nor implemented any measures on quantum-safe encryption.
8%have a specific roadmap. Those that do plan four to five years for critical data and processes.
2/3expect direct impact from quantum-computing cyber risks within seven years.
~50%intend to draw up a roadmap in the next one to three years; 43% are undecided.
Source: FINMA survey of 60 institutions, November 2025 to January 2026.
Why timing matters
Harvest now, decrypt later.
Migration protects future traffic and systems, and data still under an institution’s control can be re-protected. Data already intercepted cannot be protected retroactively. That is why long-lived confidentiality comes first.
There is no exact Q-day to plan around, only uncertainty to manage. Exposure is concentrated in public-key schemes such as RSA, ECDSA, EdDSA, DH and EC-DH.
- Today
Capture
Encrypted traffic or archives are intercepted. Nothing visible happens.
- Interim years
Retain
The ciphertext is stored. It keeps its value as long as the data stays sensitive.
- Quantum capability
Decrypt
A cryptographically relevant quantum computer may break the public-key protection.
The roadmap’s subject
PQC migration is an institution-wide transition.
The first PQC standards are final: ML-KEM, ML-DSA and SLH-DSA, published by NIST in August 2024. The roadmap is not about the algorithms. It is about where, what first, in which order, under whose ownership, and by when.
Where is quantum-vulnerable public-key cryptography used?
Across channels, interfaces, certificates, key management, archives and provider systems, whether in-house, outsourced or as a service.
Which data and processes need protection first?
Ranked by protection horizon, harvest-now-decrypt-later exposure, long-term assurance requirements and service criticality.
Which dependencies determine the sequence?
Certificate authorities before certificates, the trust layer before what rides on it, and provider release plans alongside the institution’s own.
Which migration waves and target dates are realistic?
Including the two dates FINMA asks for: critical processes, and full migration.
What does the board approve?
Strategy, resources and residual risks, in a form that satisfies governance today and supervisory scrutiny later.
What we do
From quantum risk to an executable transition programme.
We structure the transition at the level where technology, risk, governance and execution meet. Engagements build on each other, and each can stand alone.
Orientation
Executive and institutional readiness
Establish what the quantum transition means for the institution and what management needs to decide.
- Management and stakeholder interviews
- Preliminary quantum-risk framing
- Data longevity and business criticality
- Current initiatives and dependencies
- Governance requirements and key decisions
- Management alignment
Core engagement
PQC strategy and roadmap
Develop the institution-specific roadmap from current exposure to controlled migration.
- Governance and FINMA alignment
- Quantum risk and data longevity
- Process-led, evidence-led and tool-assisted inventory
- Critical-process and application priorities
- PKI, identity and signing dependencies
- External-provider readiness
- Crypto-agility principles
- Migration waves and target dates
- Ownership, decision gates and resource frame
Outcome: A board-ready strategy and roadmap: priorities, target dates, ownership, dependencies, resource frame and the first migration decisions.
Execution
Transformation and implementation
Turn the roadmap into managed execution.
- Programme mobilisation and workstream governance
- Vendor and architecture coordination
- Crypto-agility transformation
- Migration-wave management
- Dependency, risk and management reporting
- Validation and transition governance
Where specialised cryptographic or engineering capabilities are needed, we bring the right partners into a single programme.
Who we work with
Institutions where cryptography runs through the operating fabric.
We work with leadership teams across Switzerland’s financial sector: institutions with complex technology estates, long-lived sensitive information, regulated operations and significant third-party dependencies.
Why Silver Brain
Between the executive decision and the technology.
When a technology changes what an enterprise can do and what it is exposed to, the response cannot stay in the technology layer. We combine strategy, operating-model design and technology fluency, the same premise behind our work in AI-native transformation.
About Silver Brain AI →Senior-led
Direct engagement around management decisions, programme design and executive alignment.
Enterprise-wide
Technology considered together with processes, governance, data, vendors, ownership and operating implications.
Built for execution
Roadmaps designed to become transformation programmes, not to end as presentation material.