FINMA’s Quantum Computing Guidance: What It Means for Financial Institutions — and How ID Quantique Can Help
The Swiss Financial Market Supervisory Authority (FINMA) has released its Guidance 05/2026 – Quantum Computing, a document that sends a clear signal to the financial sector: quantum‑enabled cyber risks are no longer theoretical, and preparation must begin now.
Across 60 surveyed banks, insurers, asset managers and financial market infrastructures, FINMA found strong awareness of the risks—but limited action. While two‑thirds of institutions expect quantum‑related cyber threats to affect them within seven years, only 8% have a roadmap for quantum‑safe encryption, and 72% have not yet started any migration work.
For a sector built on trust, confidentiality and resilience, this gap is significant. And it is precisely where we can help.
Quantum Risk Is Accelerating
FINMA’s report highlights several concerns shared across the industry:
- Breakthrough timelines are shortening. Many institutions expect RSA‑2048 to be breakable within a decade.
- “Harvest now, decrypt later” attacks are already a real threat. Data stolen today may be decrypted once quantum computers mature.
- Critical data requires long‑term protection. Customer information, transaction records, digital signatures and regulatory data must remain secure for decades.
- Migration will take years. Cryptographic inventories, system upgrades, vendor dependencies and governance processes cannot be completed overnight.
FINMA’s conclusion is unambiguous: institutions must begin transitioning to quantum‑safe encryption now, not when quantum computers arrive.
FINMA’s Recommendations: A Clear Roadmap
FINMA outlines five priority actions for financial institutions:
1. A Board‑Approved PQC Strategy and Roadmap
Institutions should define milestones and target dates, with a PQC roadmap in place by mid‑2027.
2. A Dynamic Cryptographic Inventory
All encryption, signatures, authentication and key‑management systems must be mapped—across applications, infrastructure and outsourced services.
3. Prioritization of Critical, Long‑Lived Data
Data vulnerable to harvest now, decrypt later attacks must be protected first, potentially using hybrid cryptographic approaches.
4. Crypto‑Agility
Systems must be designed to switch algorithms flexibly as standards evolve.
5. Engagement with External Providers
Quantum‑safe requirements must be integrated into vendor contracts and release cycles.
These recommendations align closely with global regulatory trends (NIST, ENISA, NCSC) and with the broader shift toward quantum‑safe architectures.
How ID Quantique Supports Financial Institutions
ID Quantique, now part of IonQ has been helping governments, critical infrastructure operators and financial institutions prepare for quantum risk for more than two decades. Our solutions directly address the gaps identified in FINMA’s report.
Quantum‑Safe Cryptography (PQC) Integration
We support institutions in:
- Building cryptographic inventories
- Designing PQC migration roadmaps
- Implementing hybrid cryptographic schemes
- Ensuring crypto‑agility across systems and applications
Our teams work closely with CISOs, architecture leads and compliance teams to ensure alignment with FINMA, NIST and ENISA requirements.
Quantum Key Distribution (QKD) for High‑Value Links
While FINMA’s guidance focuses on PQC, many institutions are also exploring the implementation of QKD to secure their most sensitive backbone links, in addition to PQC. ID Quantique is the global leader in QKD, with deployments across:
- Financial market infrastructures
- Government networks
- Telecom operators
- Cross‑border secure communication corridors
QKD provides information‑theoretic security, ensuring that critical data in transit remains protected even against future quantum computers.
Quantum Random Number Generation (QRNG)
Strong cryptography depends on strong randomness. Our QRNG technology is already used by banks and payment providers to strengthen key generation and authentication systems.
Whether an institution is just beginning its quantum‑safe journey or already running pilots, we provide end‑to‑end support. We can help you:
- Assess quantum risk exposure
- Prioritize critical data
- Engage vendors and align outsourcing contracts
- Build crypto‑agile architectures
- Train teams and strengthen internal expertise
The Time to Act Is Now
FINMA’s message is clear: even though quantum computers are not yet at full scale, the associated risks are already impacting today’s security. Transitioning to quantum‑safe encryption will take years, and institutions that delay will face increasing operational, regulatory and reputational exposure.
At ID Quantique, we believe that preparing early is the only responsible path forward. We are ready to help Swiss financial institutions—and global ones—build the quantum‑safe foundations required for long‑term resilience. If your organization is beginning to plan its PQC roadmap, evaluating hybrid cryptography, or exploring QKD for critical links, our team is here to support you.
Quantum risk is coming. Quantum‑safe security is available today.