The headline number from FINMA’s recent quantum computing survey is difficult to ignore: only 8% of the Swiss financial institutions surveyed have a specific roadmap for transitioning to quantum-safe encryption.
But another pair of numbers may be even more important.
76% of respondents see significant value in compiling an inventory of the cryptographic methods they use. And 73% consider crypto-agility, the ability to replace cryptographic algorithms quickly and flexibly, important or very important.
Those figures point to a larger conclusion hiding inside FINMA Guidance 05/2026.
The post-quantum transition is not simply an algorithm migration. It is forcing financial institutions to confront a more fundamental problem: most organizations do not have a sufficiently current, operational view of the cryptography on which their businesses depend.
That makes FINMA’s guidance as much about cryptographic risk management as it is about quantum computing.
FINMA surveyed 60 banks, insurance companies, managers of collective assets, and financial market infrastructures between November 2025 and January 2026. Around two-thirds expect quantum-related cyber risks to affect their institutions within seven years, and roughly the same proportion expect a quantum computer capable of breaking RSA-2048 within 24 hours to emerge within ten years.
So the industry understands the issue. Execution is another matter.
FINMA found that 72% of respondents had not yet planned or implemented specific measures related to quantum-safe encryption. Only 8% had a defined roadmap, while 43% had not yet decided when to create one.
That gap between awareness and execution explains FINMA’s recommendation that supervised institutions develop a PQC roadmap by mid-2027 at the latest, based on a board-approved strategy with milestones, priorities, and target dates for both critical business processes and the broader migration.
But creating the roadmap is only the visible part of the challenge. The harder question is: What evidence will the roadmap be based on?
FINMA describes risk analysis and inventory as the first step toward quantum-safe encryption.
Its guidance goes well beyond identifying a few applications that use RSA or elliptic-curve cryptography. FINMA recommends analyzing business processes across ICT systems, applications, infrastructure, distributed-ledger technologies, and services, whether they are operated internally, outsourced, or consumed as a service. The resulting inventory should encompass encryption in transit and at rest, digital signatures, key management, and authentication mechanisms.
There is an especially important phrase in the guidance: FINMA says a cryptographic inventory should be continuously updated to reflect the current situation. That distinction matters.
A spreadsheet created during a six-month assessment can answer, “What cryptography did we find?”
A continuously maintained cryptographic inventory must answer much harder questions:
That is the difference between cryptographic discovery and cryptographic posture management.
Simply finding cryptography will not solve the problem.
Large financial institutions may uncover cryptographic dependencies across application code, open-source components, frameworks, operating systems, certificates, network connections, cloud infrastructure, and third-party services. Our Cryptographic Posture Management platform, for example, is designed to discover and correlate cryptography across those environments using agentless scanning, APIs and integrations, repository and pipeline analysis, existing enterprise telemetry, and optional targeted runtime visibility.
The resulting inventory becomes significantly more useful when cryptographic findings are connected to business and operational context.
A quantum-vulnerable public-key algorithm inside an unused test dependency does not present the same risk as the same algorithm protecting a customer-facing payment application or long-lived confidential records.
SafeLogic CPM therefore correlates cryptographic evidence with factors including quantum vulnerability, application criticality, external exposure, data sensitivity, runtime activity, compliance status, remediation readiness, and estimated remediation effort. The goal is not simply to produce more findings; it is to produce a ranked action queue that helps teams determine what should be addressed first.
That risk-based approach aligns closely with FINMA’s emphasis on prioritizing critical data and business processes rather than treating the transition as a uniform technology replacement exercise.
Quantum computers capable of breaking today’s widely deployed public-key cryptography do not yet exist. FINMA explicitly acknowledges that.
But some quantum risk already exists.
In a “harvest now, decrypt later” scenario, an attacker captures encrypted information today and retains it until a sufficiently powerful quantum computer can decrypt it. FINMA therefore recommends identifying information that requires long-term confidentiality, integrity, authenticity, or non-repudiation and prioritizing that data for protection.
This changes how organizations should think about migration priority. The critical variable is not simply when will a cryptographically relevant quantum computer arrive?
It is also, How long must this data remain secure?
A record that loses its sensitivity after six months has a very different risk profile from information that must remain confidential for 10, 20, or 30 years.
A useful cryptographic inventory therefore needs to connect technical findings to data sensitivity, business criticality, exposure, and expected lifespan. Without that context, organizations risk spending migration resources on what is easiest to find rather than what is most important to protect.
Post-quantum migration will eventually involve deploying new cryptographic algorithms. But FINMA makes another point that may prove even more enduring—organizations should design systems so cryptographic algorithms can be replaced without major architectural changes.
FINMA recommends crypto-agility as a requirement for new ICT systems and applications. It also recommends making crypto-agility a prerequisite for new software and data outsourcing arrangements, while incorporating it into existing outsourcing requirements at the earliest opportunity.
That is important because PQC will not be the last cryptographic migration. Algorithms change. Implementations develop vulnerabilities. Policies evolve. Standards are revised. Libraries become obsolete. New threats emerge.
The goal, therefore, should not be to execute one successful migration from “old crypto” to “quantum-safe crypto.” It should be to create an operating model in which cryptography can be discovered, assessed, changed, verified, and governed continuously.
SafeLogic CPM is built around that lifecycle: Discover → Understand → Act → Govern. It can maintain a continuously updated cryptographic inventory and CycloneDX Cryptographic Bill of Materials (CBOM), connect cryptographic findings with application and business context, support prioritized remediation, verify changes through subsequent scanning or targeted telemetry, and enforce cryptographic policies throughout development and production.
That makes PQC migration one use case for a capability that institutions will continue to need long after their initial quantum transition is complete.
There is a risk that organizations will interpret FINMA’s mid-2027 recommendation primarily as a documentation deadline:
Those steps matter. But they will have limited value if the underlying information becomes stale as applications, cloud environments, suppliers, certificates, dependencies, and cryptographic implementations change.
FINMA’s guidance points toward something more durable. Financial institutions need to know what cryptography they have, understand where it creates business risk, establish priorities for replacing it, manage dependencies on external providers, and retain the ability to adapt when cryptographic requirements change again. FINMA has also said it intends to continue monitoring quantum-computing developments and give the topic greater prominence in its ongoing supervisory activities.
In that sense, the mid-2027 roadmap should not be the finish line. It should be the beginning of a cryptographic risk management discipline.
The most striking statistic in FINMA’s survey may be that only 8% of institutions have a quantum-safe roadmap. But the larger lesson is not that organizations need another roadmap. They need the capability to keep that roadmap connected to reality.
A continuously maintained cryptographic inventory gives security, engineering, architecture, risk, and compliance teams a common view of their cryptographic estate. Business-aware prioritization turns thousands of technical observations into a manageable migration sequence. Integrated remediation moves the program from assessment to action. Continuous governance helps prevent weak or noncompliant cryptography from simply returning after the initial migration.
That is ultimately what crypto-agility looks like in practice.
And it is why FINMA’s quantum guidance should be viewed not simply as a warning about a future computer, but as a prompt to modernize how cryptography is managed today.
Learn how SafeLogic Cryptographic Posture Management can help your organization discover, prioritize, remediate, and continuously govern cryptographic risk while preparing for the post-quantum transition.