FINMA Guidance 05/2026

A post-quantum roadmap by mid-2027.

FINMA recommends that supervised institutions have one by mid-2027. It also says it will look at this topic more closely in future supervision.

The document

What
Guidance 05/2026, Quantum computing · 9 July 2026
Type
Guidance (Aufsichtsmitteilung), not a circular. It creates no new duty.
Applies to
Banks, insurers, managers of collective assets, financial market infrastructures
Asks for
A roadmap by mid-2027, built on an inventory of the cryptography you use (ch. 3)
Algorithms
None of its own. Points to NIST FIPS 203, 204 and 205.
Also states
The rules on governance and risk that already bind you cover quantum risk too. FINMA expects action in good time.

Read it PDF, German ↗ PDF, English ↗ PDF, French ↗ Press release ↗

How to get on it

  1. 01 ch. 3.2

    Find it

    List every system: your own, outsourced, and bought as a service. Find the encryption, signatures, authentication and keys they use, for data in transit and data at rest. Then mark what a quantum computer will break.

    Post Quantum Leap A network scan finds what answers. A host scanner reaches inside machines a scan cannot see. You import the rest. Each endpoint then gets a post-quantum status, based on rules you set.

  2. 02 ch. 3.2 · 3.3

    Rank it

    Find the data that must stay secret for years. Attackers can record traffic today and decrypt it later. Then write a migration plan for each system, sized to its risk.

    Both A view of how critical each system is against how hard it is to move. How long data must stay secret is a business decision, so we do that part with you.

  3. 03 ch. 3.1 · 3.4 · 3.5

    Plan it

    A strategy your board approves, with milestones and target dates: one for the full migration, one for critical processes. New systems and new outsourcing contracts must allow algorithms to be changed later.

    With us A workshop, based on the finished inventory. This step is decisions and contracts. No scanner can produce those, which is why the first two steps matter.

About twelve weeks for a first project. It ends with the roadmap and a FINMA report that shows the evidence behind every number. Your systems decide the real time, and we tell you after the first scan, not before.

The six-phase method behind this → What a supplier review will ask →

Request a live demo

See it live, then try it yourself.

Around 30 to 45 minutes, online. We drive: nothing to install, no environment to prepare, no data needed from you. We walk through discovery, the inventory, the crypto graph and compliance reporting on a full demo installation, then spend most of the time on whatever is closest to your situation.

If you want to keep going after that, we can give you a login to a demo tenant, or set you up with a local install so you can try it against your own infrastructure.

What you get
A straight answer on whether Post Quantum Leap fits your infrastructure, including when it does not.

We reply within one working day. No newsletter, no tracking, and your details are not shared with anyone.