Thought Leadership - SeQure AG

FINMA 05/2026 Readiness Self-Assessment

Written by Amit Agarwal | Aug 24, 2026, 2:22:46 PM

Ten questions. Five minutes. One honest answer about where your institution stands.

On 9 July 2026, FINMA published Guidance 05/2026 on quantum computing. It surveyed 60 Swiss financial institutions and found that 72% had not yet planned or implemented any measures for quantum-safe encryption, and only 8% had a specific roadmap.

FINMA did not create a new rule. It said something more uncomfortable: the technology-neutral, principles-based requirements your institution is already subject to cover this risk — and that it will give the topic greater prominence in its ongoing supervisory activities. It recommends a PQC roadmap by mid-2027 at the latest.

This self-assessment mirrors FINMA's own five recommendation areas. It is deliberately short, and deliberately hard to answer generously. Answer as you would if your supervisor were asking.

Scoring: for each question — 0 = No / not started · 1 = Partially, or in progress · 2 = Yes, and we could evidence it. Maximum score: 20.

Section A — Strategy and roadmap

FINMA 05/2026, §3.1

1. Has your board of directors adopted a strategy that explicitly covers migration to quantum-safe cryptography?

(It may sit inside an existing cyber-risk strategy — but it must be board-adopted, not an IT initiative.)

2. Do you have an implementation plan derived from that strategy, with milestones, priorities and named responsibilities — including target dates for migrating critical business processes?

3. Will you have a documented PQC roadmap in place by mid-2027?

(FINMA's recommended date. "We intend to" scores 1; "it is scheduled and resourced" scores 2.)

Section B — Risk analysis and cryptographic inventory

FINMA 05/2026, §3.2

4. Have you analysed your business processes to identify which encryption, signature and authentication technologies they actually depend on?

5. Does your cryptographic inventory cover systems that are operated in-house, outsourced *and* consumed as a service — including data in transit (VPN, TLS, HTTPS), data at rest, digital signatures, key management and authentication?

6. Is that inventory continuously updated to reflect the current situation — rather than a point-in-time snapshot that ages the moment it is signed off?

(FINMA explicitly links continuous updating to the effectiveness of the measure.)

Section C — Critical data and "harvest now, decrypt later"

FINMA 05/2026, §3.3

7. Have you identified which of your data requires long-term confidentiality, integrity or non-repudiation — and stated, in years, how long that protection must hold?

8. Have you assessed your exposure to "harvest now, decrypt later" attacks and prioritised the longest-lived data for early protection, including consideration of hybrid (classical + PQC) approaches?

Section D — Crypto-agility

FINMA 05/2026, §3.4

9. Is crypto-agility a stated requirement for systems you procure or develop — that is, can you replace a cryptographic algorithm without major changes to the software architecture?

Section E — External service providers

FINMA 05/2026, §3.5

10. Do your new outsourcing and software agreements require crypto-agility or PQC readiness — and have you begun incorporating those requirements into existing arrangements?

(Responsibility for an outsourced function remains with your institution — FINMA Circular 2018/3.)

Your result

0–5 · **In the 72%**

You are where most of the Swiss market currently sits — FINMA found that 72% of surveyed institutions had not yet planned or implemented any measures. That is context, not comfort: the same guidance says existing operational-risk and resilience requirements already cover this.

The next two moves: get a board mandate (even a one-page decision), and start the cryptographic inventory. Everything else in the guidance depends on knowing what you actually run.

6–11 · **Decided, but not yet executing**

You are in the 28% who have taken a strategic decision — ahead of the majority, but the gap between decision and roadmap is where mid-2027 will be won or lost.

The next two moves: complete the risk analysis and inventory (§3.2), and convert intent into a dated, resourced roadmap. Note FINMA's own finding: institutions that have roadmaps expect four to five years until critical data and processes are quantum-safe.

12–16 · **On track**

You are meaningfully ahead of roughly nine in ten of your peers. The risk at this stage is not absence of effort but decay: a static inventory, or a roadmap that never reaches the supplier chain.

The next two moves: make the inventory continuous rather than periodic, and push crypto-agility into procurement and outsourcing templates (§3.4, §3.5).

17–20 · **In the 8%**

You are in the small minority FINMA identified as having a specific roadmap. The useful question is no longer "have we started" but "would this survive scrutiny" — by an auditor, by your board, or by a supervisor now giving the topic greater prominence.

The next two moves: independently validate the inventory's completeness (the gaps are usually in as-a-service and legacy interfaces), and stress-test the roadmap's dates against realistic migration durations.

The what is now clear — FINMA has set it out in five areas. The how, the when and the with what are the hard part. That is precisely the work we do at SeQure AG: a live cryptographic inventory, an institution-specific risk analysis, a prioritized migration roadmap, a governance framework, and the board-level evidence to go with it.

Source throughout: FINMA Guidance 05/2026, "Quantum computing", 9 July 2026. All figures are FINMA's own survey results (60 institutions, November 2025 – January 2026).