Why now
The deadlines arrived before the quantum computer did.
Encrypted traffic is being collected today
Adversaries record encrypted traffic now and decrypt it once the hardware catches up. Anything that must stay secret for years is already at risk: patient records, contracts, keys, board papers. CISA, the NSA and NIST call it harvest now, decrypt later.
The standards are here, and the deadlines followed
NIST published the first three post-quantum standards in August 2024. The EU expects high-risk systems migrated by 2030, Germany’s BSI accepts classical key agreement on its own only until 2031, and a US executive order sets 2030 and 2031. NIST’s own estimate for a migration like this: 10 to 20 years.
In Switzerland, the regulator has started asking
FINMA’s guidance of 9 July 2026 recommends a post-quantum roadmap by mid-2027 and announces closer supervisory attention to the topic. There is no binding Swiss deadline; FINMA treats quantum risk as part of the governance duties institutions already have.
When each deadline falls
FINMA surveyed 60 supervised Swiss institutions, November 2025 to January 2026:
Every one of these roadmaps starts with the same step: knowing what cryptography you actually have.
Almost nobody has that step behind them. That is why we built Post Quantum Leap.
Sources
Every dated or numeric claim above, with the document it comes from.
- CISA, NSA and NIST, Quantum-Readiness: Migration to Post-Quantum Cryptography , 21 August 2023
- NIST, FIPS 203, 204 and 205 , 13 August 2024
- NIST, FIPS 204, Module-Lattice-Based Digital Signature Standard, Table 2 , 13 August 2024
- NIST IR 8547 (initial public draft), Transition to Post-Quantum Cryptography Standards , November 2024
- NIS Cooperation Group, A Coordinated Implementation Roadmap for the Transition to Post-Quantum Cryptography, v1.1 , 11 June 2025
- BSI Technical Guideline TR-02102-1, version 2026-01 , 23 January 2026
- Executive Order 14412, Securing the Nation Against Advanced Cryptographic Attacks (91 FR 38483); OMB M-26-15 , 22 and 24 June 2026
- FINMA Guidance 05/2026, Quantum computing , 9 July 2026
- FINMA Guidance 05/2026, survey conducted November 2025 to January 2026 , 9 July 2026
- US Office of Management and Budget, Memorandum M-26-15 , 24 June 2026
- Canton Bern ICSGW, Anhang 6 (Kryptographische Verfahren) , in force 1 January 2025
- NCSC, Timelines for migration to post-quantum cryptography , 20 March 2025
- ANSSI, Views on the Post-Quantum Cryptography transition , 4 January 2022
- ASD, Information Security Manual — Guidelines for cryptography , controls ISM-1917 and ISM-2073, revised September 2025
- Canadian Centre for Cyber Security, ITSM.40.001 , 23 June 2025
- AIVD, TNO and CWI, The PQC Migration Handbook, 2nd edition , 3 December 2024
- NIST, NIST Selects HQC as Fifth Algorithm for Post-Quantum Encryption , 11 March 2025
- NSA, NSA Releases Future Quantum-Resistant (QR) Algorithm Requirements for National Security Systems , 7 September 2022