FINMA's quantum-computing guidance, read against ANSSI's 2027 PQC timeline
FINMA's Guidance 05/2026 gives Swiss institutions five PQC recommendations and exactly one date (a roadmap by mid-2027), while ANSSI's FAQ supplies the dated European anchors, 2027 for product qualification and 2030 for purchasing, that a migration plan can be sanity-checked against.
FINMA's Guidance 05/2026 gives Swiss institutions five PQC recommendations and exactly one date (a roadmap by mid-2027), while ANSSI's FAQ supplies the dated European anchors, 2027 for product qualification and 2030 for purchasing, that a migration plan can be sanity-checked against.
Between November 2025 and January 2026, FINMA surveyed 60 authorised banks, insurers, managers of collective assets and financial market infrastructures on quantum computing. 72% said they had not yet planned or implemented any measures relating to quantum-safe encryption. Only 8% have a specific roadmap. On 9 July 2026, FINMA answered with Guidance 05/2026 "Quantum computing": an eight-page supervisory note whose one concrete date, in section 3.1 of the PDF, never appears on the news page that announced it.
What FINMA Guidance 05/2026 actually asks for
Section 3 of the guidance carries the substance: five recommendation subsections, addressed to supervised institutions. FINMA frames them as recommendations, in so many words:
"The following recommendations are based on FINMA's supervisory activities. FINMA brings these to the attention of the supervised institutions concerned and recommends that they be taken into account in their internal risk management."
The news page compresses this into a six-item list (strategy and roadmap, risk analysis, cryptographic inventory, "harvest now, decrypt later" protection, external service providers, crypto-agility). The PDF organizes the same content as five subsections: risk analysis and inventory are merged into 3.2, and "harvest now, decrypt later" lives inside 3.3 Critical data. Where the two texts differ, I quote the PDF.
The five, briefly:
3.1 Strategy and roadmap. A strategy "adopted by the board of directors," an implementation plan with milestones and priorities, and this: "it is advisable to set target dates for the complete migration, as well as for the migration of critical business processes, to quantum-safe cryptography."
3.2 Risk analysis and inventory. Analyse all business processes to identify "the encryption, signature and authentication technologies used," producing "a comprehensive inventory listing all the cryptographic methods used": data in transit ("e.g. VPN, TLS, HTTPS"), stored data, signatures, key management, authentication, "regardless of whether these are operated in-house, outsourced or procured as a service." A footnote names the quantum-vulnerable families: "For example, RSA, ECDSA, EdDSA, DH, EC-DH." The replacements referenced are the NIST PQC standards FIPS 203, 204 and 205.
3.3 Critical data. "FINMA recommends taking into account the risk of 'harvest now, decrypt later' attacks": data encrypted today, stolen now, decrypted later on a capable quantum computer. "Data that needs to remain protected in the long term should be given priority and protected accordingly using PQC algorithms."
3.4 Crypto-agility. The ability to swap out cryptographic algorithms is "recommended as a requirement for ICT systems and applications to be procured or developed."
3.5 External service providers. Migration "generally entails dependencies on external service providers." Responsibility stays with the outsourcing institution (FINMA Circular 2018/3), and "it is recommended that crypto-agility be made a prerequisite for all new outsourcing arrangements in the software and data sectors."
How binding is any of this? The PDF's own assessment: "Based on its supervisory activities, FINMA concludes that further developing risk management would be advisable for many institutions in order to ensure ongoing compliance with the requirements relating to operational risks and resilience." (The news page paraphrases the same point harder: "action is needed in the risk management process of numerous institutions.") The strongest sentence in the guidance itself, "FINMA expects supervised institutions to address these risks in a timely manner and to align their governance and risk management accordingly," carries no date.
The only date in the guidance
One date exists in the document, and it is in section 3.1:
"FINMA recommends that a PQC roadmap be drawn up by mid-2027 at the latest."
Two things about it are easy to misread. First, it is a recommendation, embedded in the internal-risk-management framing quoted above. Second, it dates a document: what should exist by mid-2027 is the roadmap. Target dates for the migration itself are left to each institution to set, and across all eight pages no compliance deadline of any kind appears.
The news page omits the mid-2027 date entirely. If you only read the press page, you miss the single dated expectation FINMA put on paper.
On what comes next, the guidance says FINMA "will continue to actively monitor developments in the field of QC and will give greater prominence to this topic in its ongoing supervisory activities." Whether a dated follow-up comes, I don't know, and the guidance doesn't say.
ANSSI's 2027 is a different instrument
The nearest European agency with more dates on paper is France's ANSSI, in its PQC FAQ. The sentence that traveled furthest:
« L'ANSSI vise la mise en place d'obligations PQC pour l'entrée en qualification de produits à partir de 2027. »("ANSSI aims to put in place PQC obligations for products entering qualification from 2027.")
Read the scoping before borrowing the date. The sentence sits in the FAQ branch that begins "Pour les développeurs de produits de sécurité" — for developers of security products. "Vise" is an aim, and "entrée en qualification" means entry into ANSSI's qualification process, part of the Visa de sécurité system. The obligation, once in place, would bind vendors bringing security products into French qualification. For a Swiss financial institution, it sets nothing.
ANSSI is explicit about the limits of its own instrument. The FAQ lists the currently regulated perimeter: defence-classified and Diffusion Restreinte data, vital information systems (SAIV), and product certifications/qualifications (Visas de sécurité). It then states: « Les préconisations de l'ANSSI sur la PQC (y compris sur l'hybridation) n'ont pas à ce jour de caractère d'obligation réglementaire. » ("ANSSI's recommendations on PQC, including on hybridization, do not to date have the character of a regulatory obligation.")
The English-language press compressed this. Bruce Schneier's July 6 post ran under the headline "France to Stop Certifying Non-Quantum-Safe Encryption", quoting a Reuters report that ANSSI "would stop certifying security products that lack quantum-resistant encryption" from 2027. An aim ("vise") became a settled halt, and qualification, a specific ANSSI process distinct from certification, became "certifying" in general. Qualification and certification are different processes, and the FAQ's 2027 sentence names qualification.
Which leaves a coincidence worth noticing: FINMA's roadmap recommendation and ANSSI's qualification aim both land in 2027, and they are different instruments: a supervisory recommendation to have a plan, and a qualification-entry rule for product vendors. Neither is a migration deadline.
The ANSSI anchors that do transfer
Three FAQ positions travel well across the border, because they reason from procurement cycles and data lifetimes rather than from French regulatory scope.
The 2030 purchasing line.
« L'ANSSI indique qu'il ne sera pas raisonnable d'acheter des produits qui n'intègrent pas de la PQC après 2030. »("ANSSI states that it will not be reasonable to buy products that do not incorporate PQC after 2030.")
The FAQ places this sentence right after establishing that for organisations outside the regulated perimeter "il n'existe pas d'obligation réglementaire": it is advice aimed precisely at readers under no French obligation, which is what makes it borrowable. The good-practice list restates it flatly: "Ne plus acheter des produits n'intégrant pas de PQC à partir de 2030" ("stop buying products that do not incorporate PQC from 2030").
Start the inventory now.
« L'ANSSI conseille aux organisations publiques et privées de démarrer dès à présent un premier travail d'inventaire, afin d'obtenir une bonne visibilité de ses usages de la cryptographie. »("ANSSI advises public and private organisations to start a first inventory effort now, to gain good visibility of their uses of cryptography.")
The FAQ adds a concrete inventory criterion: record "les données dont la confidentialité et/ou l'authenticité doivent être garanties après 2030" — the data whose confidentiality or authenticity must still hold after 2030. That is the operational version of FINMA's "harvest now, decrypt later" concern: a date to test each dataset against instead of a vague "long term."
As a purely illustrative starting point, a text sweep over your own repositories is the cheapest first visibility you can get:
shell
# Why these tokens: FINMA's guidance names the quantum-vulnerable# families ("For example, RSA, ECDSA, EdDSA, DH, EC-DH").grep -rEn 'RSA|ECDSA|EdDSA|ECDH|EC-DH' src/ config/
A sweep like this only scratches code and config; the inventory FINMA describes also covers TLS endpoints, VPNs, stored data, key management and authentication, in-house and outsourced.
Hybridization.
« L'ANSSI insiste sur la nécessité de l'hybridation partout où une protection contre la menace quantique est nécessaire, à la fois à court et à moyen terme. »("ANSSI insists on the necessity of hybridization wherever protection against the quantum threat is needed, in both the short and medium term.")
Within the French regulated perimeter, ANSSI goes further: "l'hybridation est obligatoire" — hybridization is mandatory there. FINMA is noticeably softer on the same point: it reports that "various organisations recommend a hybrid solution over pure PQC algorithms in the short to medium term" and leaves the decision to the institution's internal risk analysis. The gap between "obligatoire" and "various organisations recommend" is real; a plan shouldn't cite FINMA as mandating hybrid schemes, because it doesn't.
Testing a FINMA-shaped plan against ANSSI's dates
Here is the pairing I'd use: each FINMA recommendation next to the dated ANSSI anchor a plan can be tested against.
FINMA Guidance 05/2026
ANSSI anchor (FAQ PQC)
What the pairing checks
3.1 Strategy and roadmap
None needed; FINMA supplies its own date: roadmap "by mid-2027 at the latest"
Does a board-adopted strategy exist, and will the roadmap be on paper before mid-2027, with institution-set migration target dates?
3.2 Risk analysis and inventory
"démarrer dès à présent" — start the inventory now
Has the inventory started, is it continuously updated, and does it record algorithms plus data-protection durations?
3.3 Critical data ("harvest now, decrypt later")
Data whose confidentiality/authenticity must hold "après 2030"
Is every dataset tagged with how long it must stay protected, and is everything past 2030 prioritised for PQC?
3.4 Crypto-agility
Hybridization stance (mandatory only in the French regulated perimeter) plus renewal-cycle advice
Do procurement and development requirements demand swappable algorithms, and is the hybrid decision documented in the risk analysis?
3.5 External service providers
"Ne plus acheter des produits n'intégrant pas de PQC à partir de 2030"
Do new outsourcing contracts require crypto-agility now, and does procurement treat non-PQC products as unreasonable after 2030?
The renewal-cycle pairing in row 4 is closer than it looks: ANSSI says PQC "doivent être pris en compte dans le cycle de renouvellement des systèmes d'information" (must be taken into account in the information-system renewal cycle), and FINMA's section 3.5 independently notes that "it usually makes sense to integrate it into regular release cycles."
And here is where the mapping honestly breaks. A supervisory recommendation folded into internal risk management and a product-qualification regime are different instruments; rows in this table pair reasoning, never obligations. The hybridization stances differ in strength, as covered above. And on the most important number of all, the date by which your systems are actually migrated, both sources are silent by design: FINMA tells each institution to set its own target dates, and ANSSI's dated positions are, in its own words, without regulatory obligation to date. The table checks a plan's assumptions; it cannot supply the deadline.
FINMA's guidance gives Swiss institutions the what and exactly one dated when: a roadmap on paper by mid-2027. ANSSI's FAQ supplies the only other dated European anchors worth testing that roadmap against, provided the 2027 qualification aim and a compliance deadline never blur into each other.
devguard helps teams keep risk analyses and control inventories (including a cryptographic inventory) current as systems change: devguard.ch.
// authored by
VS
Vadim Sikora
Co-founder · devguard
Vadim leads engineering, the architecture, automation, and integrations that let compliance live. He's set on making a serious, audit-grade system genuinely easy to run.