Ten questions. Five minutes. One honest answer about where your institution stands.
On 9 July 2026, FINMA published Guidance 05/2026 on quantum computing. It surveyed 60 Swiss financial institutions and found that 72% had not yet planned or implemented any measures for quantum-safe encryption, and only 8% had a specific roadmap.
FINMA did not create a new rule. It said something more uncomfortable: the technology-neutral, principles-based requirements your institution is already subject to cover this risk — and that it will give the topic greater prominence in its ongoing supervisory activities. It recommends a PQC roadmap by mid-2027 at the latest.
This self-assessment mirrors FINMA's own five recommendation areas. It is deliberately short, and deliberately hard to answer generously. Answer as you would if your supervisor were asking.
Scoring: for each question — 0 = No / not started · 1 = Partially, or in progress · 2 = Yes, and we could evidence it. Maximum score: 20.
Section A — Strategy and roadmap
FINMA 05/2026, §3.1
1. Has your board of directors adopted a strategy that explicitly covers migration to quantum-safe cryptography?
(It may sit inside an existing cyber-risk strategy — but it must be board-adopted, not an IT initiative.)
2. Do you have an implementation plan derived from that strategy, with milestones, priorities and named responsibilities — including target dates for migrating critical business processes?
3. Will you have a documented PQC roadmap in place by mid-2027?
(FINMA's recommended date. "We intend to" scores 1; "it is scheduled and resourced" scores 2.)
Section B — Risk analysis and cryptographic inventory
FINMA 05/2026, §3.2
4. Have you analysed your business processes to identify which encryption, signature and authentication technologies they actually depend on?
5. Does your cryptographic inventory cover systems that are operated in-house, outsourced *and* consumed as a service — including data in transit (VPN, TLS, HTTPS), data at rest, digital signatures, key management and authentication?
6. Is that inventory continuously updated to reflect the current situation — rather than a point-in-time snapshot that ages the moment it is signed off?
(FINMA explicitly links continuous updating to the effectiveness of the measure.)
Section C — Critical data and "harvest now, decrypt later"
FINMA 05/2026, §3.3
7. Have you identified which of your data requires long-term confidentiality, integrity or non-repudiation — and stated, in years, how long that protection must hold?
8. Have you assessed your exposure to "harvest now, decrypt later" attacks and prioritised the longest-lived data for early protection, including consideration of hybrid (classical + PQC) approaches?
Section D — Crypto-agility
FINMA 05/2026, §3.4
9. Is crypto-agility a stated requirement for systems you procure or develop — that is, can you replace a cryptographic algorithm without major changes to the software architecture?
Section E — External service providers
FINMA 05/2026, §3.5
10. Do your new outsourcing and software agreements require crypto-agility or PQC readiness — and have you begun incorporating those requirements into existing arrangements?
(Responsibility for an outsourced function remains with your institution — FINMA Circular 2018/3.)
Your result
0–5 · **In the 72%**
You are where most of the Swiss market currently sits — FINMA found that 72% of surveyed institutions had not yet planned or implemented any measures. That is context, not comfort: the same guidance says existing operational-risk and resilience requirements already cover this.
The next two moves: get a board mandate (even a one-page decision), and start the cryptographic inventory. Everything else in the guidance depends on knowing what you actually run.
6–11 · **Decided, but not yet executing**
You are in the 28% who have taken a strategic decision — ahead of the majority, but the gap between decision and roadmap is where mid-2027 will be won or lost.
The next two moves: complete the risk analysis and inventory (§3.2), and convert intent into a dated, resourced roadmap. Note FINMA's own finding: institutions that have roadmaps expect four to five years until critical data and processes are quantum-safe.
12–16 · **On track**
You are meaningfully ahead of roughly nine in ten of your peers. The risk at this stage is not absence of effort but decay: a static inventory, or a roadmap that never reaches the supplier chain.
The next two moves: make the inventory continuous rather than periodic, and push crypto-agility into procurement and outsourcing templates (§3.4, §3.5).
17–20 · **In the 8%**
You are in the small minority FINMA identified as having a specific roadmap. The useful question is no longer "have we started" but "would this survive scrutiny" — by an auditor, by your board, or by a supervisor now giving the topic greater prominence.
The next two moves: independently validate the inventory's completeness (the gaps are usually in as-a-service and legacy interfaces), and stress-test the roadmap's dates against realistic migration durations.
The what is now clear — FINMA has set it out in five areas. The how, the when and the with what are the hard part. That is precisely the work we do at SeQure AG: a live cryptographic inventory, an institution-specific risk analysis, a prioritized migration roadmap, a governance framework, and the board-level evidence to go with it.
Source throughout: FINMA Guidance 05/2026, "Quantum computing", 9 July 2026. All figures are FINMA's own survey results (60 institutions, November 2025 – January 2026).