Skip to content
Silver Brain Quantum

A specialist practice of Silver Brain AI.silverbrain.ai

FINMA Supervisory Guidance 05/2026

Post-quantum resilience for Swiss financial institutions.

FINMA has put the transition to quantum-safe cryptography on the management agenda. We help institutions turn cryptographic risk, dependencies and regulatory expectations into a structured, executable transition roadmap.

A board-adopted PQC roadmap, by mid-2027 at the latest.

On 9 July 2026, FINMA published Supervisory Guidance 05/2026. It pairs a survey of 60 authorised banks, insurers, managers of collective assets and financial market infrastructures with recommendations for the migration to quantum-safe cryptography.

It is a supervisory communication, not a new circular. Institutions are expected to address quantum-related risks in a timely manner under existing governance, operational-risk and resilience requirements, and FINMA will give the topic more weight in its ongoing supervision.

What FINMA expects

Five areas the roadmap has to cover.

The scope is migration to quantum-safe algorithms (NIST FIPS 203, 204 and 205). Quantum key distribution and business applications of quantum computing are explicitly out of scope.

Guidance 3.1

Strategy and roadmap

A board-adopted strategy and implementation plan with milestones, priorities and target dates, for critical processes and for full migration.

Guidance 3.2

Risk analysis and inventory

Every business process analysed for the encryption, signature and authentication in use, in-house, outsourced or as a service, in a continuously updated cryptographic inventory.

Guidance 3.3

Critical data

Data that needs long-term confidentiality, integrity or non-repudiation identified and prioritised. Hybrid classical-plus-PQC schemes are recommended for the transition.

Guidance 3.4

Crypto-agility

The ability to swap cryptographic algorithms without major architectural change, recommended as a requirement for systems still to be procured or built.

Guidance 3.5

External providers

Responsibility stays with the institution. PQC is anchored in contracts and release plans, and crypto-agility becomes a prerequisite for new outsourcing.

FINMA’s recommendation

A PQC roadmap by mid-2027, based on a strategy adopted by the board.

Read the guidance on finma.ch →

References to FINMA guidance are provided for context and do not imply endorsement or affiliation.

Sector readiness

Most of the sector has yet to start.

These figures describe the sector, not any single institution. The mid-2027 recommendation puts roadmap preparation on the management agenda whatever the starting point.

72%

have neither planned nor implemented any measures on quantum-safe encryption.

8%

have a specific roadmap. Those that do plan four to five years for critical data and processes.

2/3

expect direct impact from quantum-computing cyber risks within seven years.

~50%

intend to draw up a roadmap in the next one to three years; 43% are undecided.

Source: FINMA survey of 60 institutions, November 2025 to January 2026.

Why timing matters

Harvest now, decrypt later.

Migration protects future traffic and systems, and data still under an institution’s control can be re-protected. Data already intercepted cannot be protected retroactively. That is why long-lived confidentiality comes first.

There is no exact Q-day to plan around, only uncertainty to manage. Exposure is concentrated in public-key schemes such as RSA, ECDSA, EdDSA, DH and EC-DH.

  1. Today

    Capture

    Encrypted traffic or archives are intercepted. Nothing visible happens.

  2. Interim years

    Retain

    The ciphertext is stored. It keeps its value as long as the data stays sensitive.

  3. Quantum capability

    Decrypt

    A cryptographically relevant quantum computer may break the public-key protection.

The roadmap’s subject

PQC migration is an institution-wide transition.

The first PQC standards are final: ML-KEM, ML-DSA and SLH-DSA, published by NIST in August 2024. The roadmap is not about the algorithms. It is about where, what first, in which order, under whose ownership, and by when.

  • Where is quantum-vulnerable public-key cryptography used?

    Across channels, interfaces, certificates, key management, archives and provider systems, whether in-house, outsourced or as a service.

  • Which data and processes need protection first?

    Ranked by protection horizon, harvest-now-decrypt-later exposure, long-term assurance requirements and service criticality.

  • Which dependencies determine the sequence?

    Certificate authorities before certificates, the trust layer before what rides on it, and provider release plans alongside the institution’s own.

  • Which migration waves and target dates are realistic?

    Including the two dates FINMA asks for: critical processes, and full migration.

  • What does the board approve?

    Strategy, resources and residual risks, in a form that satisfies governance today and supervisory scrutiny later.

What we do

From quantum risk to an executable transition programme.

We structure the transition at the level where technology, risk, governance and execution meet. Engagements build on each other, and each can stand alone.

Orientation

Executive and institutional readiness

Establish what the quantum transition means for the institution and what management needs to decide.

  • Management and stakeholder interviews
  • Preliminary quantum-risk framing
  • Data longevity and business criticality
  • Current initiatives and dependencies
  • Governance requirements and key decisions
  • Management alignment

Core engagement

PQC strategy and roadmap

Develop the institution-specific roadmap from current exposure to controlled migration.

  • Governance and FINMA alignment
  • Quantum risk and data longevity
  • Process-led, evidence-led and tool-assisted inventory
  • Critical-process and application priorities
  • PKI, identity and signing dependencies
  • External-provider readiness
  • Crypto-agility principles
  • Migration waves and target dates
  • Ownership, decision gates and resource frame

Outcome: A board-ready strategy and roadmap: priorities, target dates, ownership, dependencies, resource frame and the first migration decisions.

Execution

Transformation and implementation

Turn the roadmap into managed execution.

  • Programme mobilisation and workstream governance
  • Vendor and architecture coordination
  • Crypto-agility transformation
  • Migration-wave management
  • Dependency, risk and management reporting
  • Validation and transition governance

Where specialised cryptographic or engineering capabilities are needed, we bring the right partners into a single programme.

Who we work with

Institutions where cryptography runs through the operating fabric.

We work with leadership teams across Switzerland’s financial sector: institutions with complex technology estates, long-lived sensitive information, regulated operations and significant third-party dependencies.

  • Banks
  • Cantonal banks
  • Private banks
  • Insurers
  • Securities firms
  • Asset and wealth managers
  • Financial market infrastructures
  • Other regulated institutions

Why Silver Brain

Between the executive decision and the technology.

When a technology changes what an enterprise can do and what it is exposed to, the response cannot stay in the technology layer. We combine strategy, operating-model design and technology fluency, the same premise behind our work in AI-native transformation.

About Silver Brain AI

Senior-led

Direct engagement around management decisions, programme design and executive alignment.

Enterprise-wide

Technology considered together with processes, governance, data, vendors, ownership and operating implications.

Built for execution

Roadmaps designed to become transformation programmes, not to end as presentation material.

Contact

Start a conversation.

Tell us where your institution stands. We will come back to you to arrange a first discussion.

This form is protected by reCAPTCHA. The Google Privacy Policy and Terms of Service apply. We use your details only to respond to your inquiry. See our privacy policy.