Why now

The deadlines arrived before the quantum computer did.

Encrypted traffic is being collected today

Adversaries record encrypted traffic now and decrypt it once the hardware catches up. Anything that must stay secret for years is already at risk: patient records, contracts, keys, board papers. CISA, the NSA and NIST call it harvest now, decrypt later.

The standards are here, and the deadlines followed

NIST published the first three post-quantum standards in August 2024. The EU expects high-risk systems migrated by 2030, Germany’s BSI accepts classical key agreement on its own only until 2031, and a US executive order sets 2030 and 2031. NIST’s own estimate for a migration like this: 10 to 20 years.

In Switzerland, the regulator has started asking

FINMA’s guidance of 9 July 2026 recommends a post-quantum roadmap by mid-2027 and announces closer supervisory attention to the topic. There is no binding Swiss deadline; FINMA treats quantum risk as part of the governance duties institutions already have.

When each deadline falls

2027 FINMA: PQC roadmap recommended by mid-2027
2030 EU: high-risk use cases migrated
2031 BSI: end of classic key agreement alone
2035 EU: medium-risk use cases migrated

FINMA surveyed 60 supervised Swiss institutions, November 2025 to January 2026:

72% had not yet planned or taken any measures
8% had a specific roadmap
76% saw high or very high value in a cryptographic inventory

Every one of these roadmaps starts with the same step: knowing what cryptography you actually have.

Almost nobody has that step behind them. That is why we built Post Quantum Leap.

Sources

Every dated or numeric claim above, with the document it comes from.

The full picture, authority by authority, with sources →