---
title: The board approval paper
description: "The board paper: what a quantum roadmap has to contain to get approved"
image: https://sequre.ch/hubfs/AI-Generated%20Media/Images/Quantum%20Roadmap%20Strategy%20Corporate%20Boardroom%20Meeting.png
---

[Skip to main content](https://sequre.ch/en/blog/boardpaper#main)

[![Sequre Logo\_Hor\_72x212](https://sequre.ch/hs-fs/hubfs/New/Sequre%20Logo_Hor_72x212.png?width=212&height=72&name=Sequre%20Logo_Hor_72x212.png) ![Sequre Logo\_Hor\_72x212](https://sequre.ch/hs-fs/hubfs/New/Sequre%20Logo_Hor_72x212.png?width=212&height=72&name=Sequre%20Logo_Hor_72x212.png) ![Sequre Logo\_Hor\_72x212](https://sequre.ch/hs-fs/hubfs/New/Sequre%20Logo_Hor_72x212.png?width=212&height=72&name=Sequre%20Logo_Hor_72x212.png) ![Sequre Logo\_Hor\_72x212](https://sequre.ch/hs-fs/hubfs/New/Sequre%20Logo_Hor_72x212.png?width=212&height=72&name=Sequre%20Logo_Hor_72x212.png)](https://sequre.ch)

- [Show submenu for Solutions Solutions](https://sequre.ch/solutions) 
    - Show submenu for Quantum Safe Security Quantum Safe Security 
      
          - [QuRisc Atlas](https://sequre.ch/solutions#AIRiskTool)
          - [QuRisc Scout](https://sequre.ch/solutions#Crawler)
          - [QuRisc Vantage](https://sequre.ch/solutions#Vantage)
          - [QuRisc Augur](https://sequre.ch/solutions#Augur)
          - [Quantum Safe encryption](https://sequre.ch/solutions#QSE)
          - [Quantum Security Hardware](https://sequre.ch/solutions#QKD)
          - [Quantum Detection System](https://sequre.ch/solutions#QKD)
    - [Consulting](https://sequre.ch/solutions#Consulting)
    - [Quantum Algorithms](https://sequre.ch/solutions#QuantAlgo)
    - [Industries](https://sequre.ch/solutions#Industries)
- [Show submenu for Resource Resource](https://sequre.ch/resources) 
    - [Blogs](https://sequre.ch/en/blog)
    - [Quantum Computing Knowledge Base](https://sequre.ch/resources#QKB)
- [Show submenu for Company Company](https://sequre.ch/company) 
    - [About Us](https://sequre.ch/company#AboutUs)
    - [Management Team](https://sequre.ch/company#Team)
    - [Advisors](https://sequre.ch/company#Advisors)
    - [Partners](https://sequre.ch/company#Partners)
    - [Careers](https://sequre.ch/company#Careers)
    - [Contact](https://sequre.ch/company#Contact-Us)
- [Whats New](https://sequre.ch/whats-new)

Open main navigation

Close main navigation

- Show submenu for Solutions Solutions 
  
    - Solutions
    - [Solutions](https://sequre.ch/solutions)
    - Show submenu for Quantum Safe Security Quantum Safe Security 
      
          - Quantum Safe Security
          - [QuRisc Atlas](https://sequre.ch/solutions#AIRiskTool)
          - [QuRisc Scout](https://sequre.ch/solutions#Crawler)
          - [QuRisc Vantage](https://sequre.ch/solutions#Vantage)
          - [QuRisc Augur](https://sequre.ch/solutions#Augur)
          - [Quantum Safe encryption](https://sequre.ch/solutions#QSE)
          - [Quantum Security Hardware](https://sequre.ch/solutions#QKD)
          - [Quantum Detection System](https://sequre.ch/solutions#QKD)
    - [Consulting](https://sequre.ch/solutions#Consulting)
    - [Quantum Algorithms](https://sequre.ch/solutions#QuantAlgo)
    - [Industries](https://sequre.ch/solutions#Industries)
- Show submenu for Resource Resource 
  
    - Resource
    - [Resource](https://sequre.ch/resources)
    - [Blogs](https://sequre.ch/en/blog)
    - [Quantum Computing Knowledge Base](https://sequre.ch/resources#QKB)
- Show submenu for Company Company 
  
    - Company
    - [Company](https://sequre.ch/company)
    - [About Us](https://sequre.ch/company#AboutUs)
    - [Management Team](https://sequre.ch/company#Team)
    - [Advisors](https://sequre.ch/company#Advisors)
    - [Partners](https://sequre.ch/company#Partners)
    - [Careers](https://sequre.ch/company#Careers)
    - [Contact](https://sequre.ch/company#Contact-Us)
- [Whats New](https://sequre.ch/whats-new)
- [Contact Us](https://sequre.ch/contact-us)

[Contact Us](https://sequre.ch/contact-us)

# The board approval paper

![Amit Agarwal](https://sequre.ch/hs-fs/hubfs/AmitAgarwal.jpg?width=120&height=120&name=AmitAgarwal.jpg)

 by [Amit Agarwal](https://sequre.ch/en/blog/author/amit-agarwal)

Oct 6, 2026, 11:34:49 AM

FINMA placed its roadmap recommendation in the section on strategy, not the section on technology. Section 3.1 asks for a strategy **adopted by the board of directors**, from which an implementation plan with milestones, priorities and target dates is derived.

That placement is the most useful sentence in the guidance for anyone trying to get this funded, and it is routinely read past.

It means the deliverable is not a migration plan that the board is informed about. It is a board decision from which a migration plan follows. Those are different documents, written for different readers, and only one of them survives a budget round.

This article is about the second one: the paper that goes to committee. Four weeks of writing about inventories, exposure windows and cost structures are of no use whatsoever if the document carrying them is the wrong document.

**Why the strategy section, and not the technology section**

Three consequences follow from FINMA's placement, and each changes what you write.

**It makes the programme durable.** A technology initiative competes for attention every quarter against whatever is loudest. A board-adopted strategy has standing: deferring it requires a decision, and decisions get minuted. Over a four-to-five-year programme — which is what institutions holding roadmaps tell FINMA they expect — that difference decides whether the work survives contact with the next crisis.

**It fixes accountability.** Crypto-agility and cryptographic inventory sit awkwardly between architecture, procurement and operational risk; each function reasonably assumes another owns them. Board adoption resolves that by naming an owner at a level where the ambiguity cannot survive.

**It makes the dates real.** Target dates set inside a technology function are estimates. Target dates in a board-adopted strategy are commitments, and they attract the budget and the sequencing decisions that estimates never do.

**The five components**

**1. It opens with the decision, not the technology**

A board paper that spends its first pages explaining Shor's algorithm has lost before the ask. Not because the committee cannot follow it — many will — but because it signals that the author has misjudged what is being asked of them.

Open with what is being decided, what it costs, what happens if it is deferred. Then the reasoning, for those who want it. An appendix is the correct home for the mathematics, and almost nobody will read it, which is the point: its presence signals rigour without spending the committee's attention.

*The question this pre-empts: "What are we actually being asked to approve?"*

**2. It names an owner whose remit reaches procurement**

Most of a Swiss institution's cryptographic estate is bought, not built — core banking, payments and messaging, custody, and the accumulated SaaS layer. FINMA is explicit that responsibility for an outsourced function remains with the outsourcing institution in all cases, and recommends crypto-agility be made a prerequisite in new outsourcing arrangements.

An owner whose authority stops at architecture cannot deliver a plan whose critical path runs through supplier contracts and renewal cycles. Name someone whose remit reaches both, or the paper is describing a programme nobody can actually execute.

*The question this pre-empts: "Who is accountable, and can they actually do it?"*

**3. It separates the two dates**

FINMA asks for target dates for complete migration **and**, separately, for the migration of critical business processes.

Conflating them is the most common fatal error in these papers, and it fails in two directions at once. A single distant date looks unfundable — an expensive programme whose benefit arrives years away. And it obscures the fact that most of the risk reduction happens early, when the long-lived confidential data gets protected. The critical-process date is the one that reduces exposure; the full-migration date is the one that closes the programme.

Presented separately, the paper offers a board something it recognises: an early, defensible milestone and a longer completion horizon. Presented together, it offers a single number that invites deferral.

*The question this pre-empts: "When do we actually get the benefit?"*

**4. It states what is out of scope**

Every roadmap has a boundary. Some systems will be excluded because they are being decommissioned, some because the data behind them has no meaningful confidentiality horizon, some because a supplier's own timeline makes action impossible before a given date.

Stating those exclusions deliberately is the difference between a scope decision and an oversight. It is also the only way the board can accept a risk — a committee cannot accept what it was never shown, and an unstated exclusion discovered later reads as something withheld rather than something decided.

This is the section that feels like weakness while writing it and reads as authority in the room.

*The question this pre-empts: "What are we not doing, and did you know?"*

**5. It survives the second question**

The first question is always some version of "how much". The second is the one that decides the paper: **"what if you are wrong about the timing?"**

If the roadmap's justification rests on a particular year, that question ends it — because nobody can defend a specific year, and a committee that senses an unfalsifiable premise will defer rather than refuse.

The defensible answer is that the sequencing does not depend on the forecast. It is driven by how long each class of data must remain confidential, which is a property of the business rather than a property of quantum computing. If a cryptographically relevant machine arrives later than expected, the sequencing was still correct and the programme simply completes with margin. If it arrives sooner, the most exposed data was addressed first.

That is a genuinely robust argument, and it is available only to a roadmap that was built on data lifetime in the first place. This is the point at which the analytical choice made months earlier either pays for itself or does not.

*The question this pre-empts: the one that actually kills these papers.*

**Pressure-testing: six questions a risk committee will ask**

Rehearse these before the meeting rather than during it.

**"Is this a regulatory requirement?"** No — and say so plainly. FINMA Guidance 05/2026 contains recommendations, not binding rules. What is binding is the existing, technology-neutral requirement for effective governance and risk management, which FINMA states already covers this risk. The honest answer is stronger than the overstated one, and a committee containing a lawyer will know the difference immediately.

**"Can we wait a year?"** You can, and you should show precisely what it costs. Not in breach probability, but in runway: migration capacity is bounded by release cycles, hardware refresh cycles and contract renewals, none of which accelerate because the budget arrives later.

**"What are our peers doing?"** FINMA answered this for you. Of 60 surveyed institutions, 72% had planned or implemented no measures, and only 8% held a concrete roadmap. Use it as context, never as comfort — the same guidance says action is advisable for many institutions to ensure ongoing compliance with operational-risk and resilience requirements.

**"Is the technology mature enough to commit to?"** The standards are: NIST published FIPS 203, 204 and 205 in August 2024. The engineering is not uniformly mature, which is why FINMA also recommends crypto-agility — it anticipates that today's algorithms, including post-quantum ones, may themselves need replacing.

**"What happens if a post-quantum algorithm is broken?"** It has happened, during standardisation: Rainbow in February 2022 and SIKE that July, both to classical attacks, neither requiring a quantum computer. That is precisely why the roadmap should deliver the ability to change algorithms, not merely a particular algorithm.

**"Why does this need us, rather than the technology committee?"** Because the decision spans budget, procurement standards and third-party contracts, and because FINMA places the strategy at board level. If it goes to a technology committee it becomes a technology project — same slides, materially different outcome.

**What to leave out**

Three things weaken these papers by being in them.

**A specific Q-Day year.** It converts a robust argument into a contestable forecast, and hands the room a way to disagree with the premise instead of the plan.

**Vendor names and product comparisons.** A board is approving a strategy and a budget envelope. Procurement follows the decision; it does not belong inside it.

**Urgency that cannot be verified.** Cryptographically relevant quantum computers do not yet exist — FINMA says so directly. A paper that implies otherwise will be checked, and once one claim is found to be overstated the rest of the document is read differently. The genuine argument is strong enough: long-lived data, long migration times, a supervisor that has said it will give the topic greater prominence.

**A one-page skeleton**

Lift this, fill it in, and let the detail live in appendices.

***Decision requested.*** *Approve the post-quantum migration strategy and mandate the implementation plan, with funding of \[X\] for \[period\].*

***Why now.*** *FINMA Guidance 05/2026 recommends a PQC roadmap by mid-2027. Institutions that hold roadmaps allow four to five years to execute them. Our most sensitive data must remain confidential for \[N\] years.*

***What we know.*** *\[One line on inventory status.\] \[One line on the proportion of the estate carrying quantum-vulnerable algorithms.\] \[One line on the highest-exposure data class.\]*

***What we propose.*** *Critical business processes quantum-safe by \[date\]. Full migration by \[date\]. Crypto-agility required in all new system and outsourcing contracts from \[date\].*

***What it costs.*** *\[Envelope, by year.\] **What deferral costs:** \[runway lost, not risk probability\].*

***Out of scope.*** *\[List, with reasons.\]*

***Owner.*** *\[Name, role — with authority over procurement standards.\]*

***Key risk to the plan.*** *Third-party timelines we do not control. Mitigation: contractual crypto-agility requirements from \[date\], supplier roadmap reviews \[frequency\].*

Nine lines. If the strategy cannot be expressed in nine lines, the thinking underneath is not finished — and a committee will sense that before it can articulate why.

**The point**

FINMA has recommended a roadmap by mid-2027. What most institutions will produce is a technical migration plan with a board endorsement stapled to the front, and it will do roughly what such documents always do.

The guidance asks for something else, and the difference is not presentational. A board-adopted strategy creates an owner, a budget, two dates and a scope boundary — which is to say, it creates a programme. Everything else creates a document.

**References**

1\. FINMA, Guidance 05/2026, *Quantum computing*, 9 July 2026 — in particular §3.1 (strategy and roadmap), §3.3 (critical data), §3.4 (crypto-agility), §3.5 (external service providers), §4 (outlook).

2\. FINMA, Circular 2018/3 *Outsourcing — banks and insurers*.

3\. NIST, FIPS 203 (ML-KEM), FIPS 204 (ML-DSA), FIPS 205 (SLH-DSA), August 2024.

4\. W. Beullens, "Breaking Rainbow takes a weekend on a laptop", 2022.

5\. W. Castryck and T. Decru, "An efficient key recovery attack on SIDH", 2022.

*Survey figures are FINMA's own results (60 institutions, November 2025 – January 2026) as published in Guidance 05/2026.*

**About the author.** Amit Agarwal is CEO and Co-Founder of SeQure AG, a Swiss quantum cybersecurity company helping banks and financial institutions identify, prioritise, and remediate cryptographic vulnerabilities before Q-Day. He brings 25+ years across software, SaaS, payments and FinTech and holds a BTech (Computer Science), an MBA, an MAS, and a Quantum Computing qualification from MIT's executive education.

**Tags:** 

[Blog Post,](https://sequre.ch/en/blog/tag/blog-post) [Quantum Security,](https://sequre.ch/en/blog/tag/quantum-security) [Swiss Banks,](https://sequre.ch/en/blog/tag/swiss-banks) [MigrationComplexity,](https://sequre.ch/en/blog/tag/migrationcomplexity) [Quantum Computing](https://sequre.ch/en/blog/tag/quantum-computing)

![Amit Agarwal](https://sequre.ch/hs-fs/hubfs/AmitAgarwal.jpg?width=120&height=120&name=AmitAgarwal.jpg)

Post by [Amit Agarwal](https://sequre.ch/en/blog/author/amit-agarwal)  
 Oct 6, 2026, 11:34:49 AM

 CEO, SeQure AG · AI-driven crypto inventory & Quantum-Safe Migration for Swiss Banks and FIs · FINMA · DORA · PQC · Q-Day Risk in CHF for Executive Board

[Follow me on my website](https://www.sequre.ch) [Follow me on LinkedIn](https://www.linkedin.com/in/amitagarwal-ch/)

### Related Articles

##### [![Crypto-agility: what it costs to specify, and what it costs to skip](https://sequre.ch/hs-fs/hubfs/AI-Generated%20Media/Images/Crypto%20Agility%20Infographics%20in%20Swiss%20Bank%20Tech%20Office.png?width=520&height=294&name=Crypto%20Agility%20Infographics%20in%20Swiss%20Bank%20Tech%20Office.png) Knowledge Base • Aug 24, 2026, 4:44:23 PM Crypto-agility: what it costs to specify, and what it costs to skip 7 min read](https://sequre.ch/en/blog/crypto-agility-cost)

##### [![FINMA 05/2026 Readiness Self-Assessment](https://sequre.ch/hs-fs/hubfs/AI-Generated%20Media/Images/Quantum%20Computing%20Strategy%20Meeting.png?width=520&height=294&name=Quantum%20Computing%20Strategy%20Meeting.png) Knowledge Base • Aug 24, 2026, 4:22:46 PM FINMA 05/2026 Readiness Self-Assessment 3 min read](https://sequre.ch/en/blog/finma-05/2026-readiness-self-assessment)

## Comments

###### Recent Posts

- [Crypto-agility: what it costs to specify, and what it costs to skip](https://sequre.ch/en/blog/crypto-agility-cost)
- [FINMA 05/2026 Readiness Self-Assessment](https://sequre.ch/en/blog/finma-05/2026-readiness-self-assessment)
- [From Molecules to the Cosmos — The Real Promise of Quantum Computing](https://sequre.ch/en/blog/quantumexplained-4)
- [Is AES Really Safe in the Quantum Era?](https://sequre.ch/en/blog/quantumexplained-3)

[![Sequre Logo\_Hor\_72x212](https://sequre.ch/hs-fs/hubfs/New/Sequre%20Logo_Hor_72x212.png?width=212&height=72&name=Sequre%20Logo_Hor_72x212.png)](https://sequre.ch)

- Stay Connected 
    - [Mail](mailto:info@sequre.ch?subject=Inquiry)
    - [LinkedIN](https://www.linkedin.com/company/sequreag)
- Important Links 
    - [About Us](https://sequre.ch/company#AboutUs)
    - [Contact Us](https://sequre.ch/contact-us)
- Privacy Details 
    - [Data Privacy Statement](https://app.privacybee.io/v/cmirii0su00baqmood8br1jnp?lang=en&type=dsg)
    - [Term of Use](https://sequre.ch/termsofuse)

©2026 SeQure. All rights reserved. [Privacy Policy](https://244153970.hs-sites-na2.com/data-privacy)<https://sequre.ch/privacy-policy>

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Amit Agarwal",
    "url" : "https://sequre.ch/en/blog/author/amit-agarwal"
  },
  "dateModified" : "2026-10-06T09:34:49.303Z",
  "datePublished" : "2026-10-06T09:34:49.000Z",
  "headline" : "The board approval paper",
  "image" : [ "https://sequre.ch/hubfs/AI-Generated%20Media/Images/Quantum%20Roadmap%20Strategy%20Corporate%20Boardroom%20Meeting.png" ],
  "mainEntityOfPage" : {
    "@id" : "https://sequre.ch/en/blog/boardpaper",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://sequre.ch/hubfs/Sequre%20Logo%20Profile%20Image.jpg"
    },
    "name" : "Sequre AG"
  }
}
```