FINMA Guidance 05/2026
A post-quantum roadmap by mid-2027.
FINMA recommends that supervised institutions have one by mid-2027. It also says it will look at this topic more closely in future supervision.
The document
- What
- Guidance 05/2026, Quantum computing · 9 July 2026
- Type
- Guidance (Aufsichtsmitteilung), not a circular. It creates no new duty.
- Applies to
- Banks, insurers, managers of collective assets, financial market infrastructures
- Asks for
- A roadmap by mid-2027, built on an inventory of the cryptography you use (ch. 3)
- Algorithms
- None of its own. Points to NIST FIPS 203, 204 and 205.
- Also states
- The rules on governance and risk that already bind you cover quantum risk too. FINMA expects action in good time.
Read it PDF, German ↗ PDF, English ↗ PDF, French ↗ Press release ↗
How to get on it
-
01 ch. 3.2
Find it
List every system: your own, outsourced, and bought as a service. Find the encryption, signatures, authentication and keys they use, for data in transit and data at rest. Then mark what a quantum computer will break.
Post Quantum Leap A network scan finds what answers. A host scanner reaches inside machines a scan cannot see. You import the rest. Each endpoint then gets a post-quantum status, based on rules you set.
-
02 ch. 3.2 · 3.3
Rank it
Find the data that must stay secret for years. Attackers can record traffic today and decrypt it later. Then write a migration plan for each system, sized to its risk.
Both A view of how critical each system is against how hard it is to move. How long data must stay secret is a business decision, so we do that part with you.
-
03 ch. 3.1 · 3.4 · 3.5
Plan it
A strategy your board approves, with milestones and target dates: one for the full migration, one for critical processes. New systems and new outsourcing contracts must allow algorithms to be changed later.
With us A workshop, based on the finished inventory. This step is decisions and contracts. No scanner can produce those, which is why the first two steps matter.
About twelve weeks for a first project. It ends with the roadmap and a FINMA report that shows the evidence behind every number. Your systems decide the real time, and we tell you after the first scan, not before.
The six-phase method behind this → What a supplier review will ask →Request a live demo
See it live, then try it yourself.
Around 30 to 45 minutes, online. We drive: nothing to install, no environment to prepare, no data needed from you. We walk through discovery, the inventory, the crypto graph and compliance reporting on a full demo installation, then spend most of the time on whatever is closest to your situation.
If you want to keep going after that, we can give you a login to a demo tenant, or set you up with a local install so you can try it against your own infrastructure.
- What you get
- A straight answer on whether Post Quantum Leap fits your infrastructure, including when it does not.
- Prefer email
- info@postquantumleap.com
Request received.
We have emailed you a confirmation and will reply within one working day with a few suggested times. If nothing arrives, write to info@postquantumleap.com.