Post-quantum migration for financial institutions
With supervisory notice 05/2026, FINMA has set a timeframe: a PQC roadmap approved by executive management by mid-2027 at the latest. Of 60 institutions surveyed, 72 percent had not yet decided on any measures, and only 8 percent had a concrete roadmap. This page describes what belongs in such a roadmap and in which order it is built.
What FINMA expects
- A strategy approved by executive management, with priorities, milestones and target dates.
- A cryptographic inventory across all ICT systems, applications and infrastructure, whether operated in-house, outsourced or purchased as a service. FINMA explicitly includes distributed ledgers.
- A risk analysis focused on data that has to remain confidential for a long time.
- Hybrid methods during the transition period, combining a classical and a post-quantum algorithm. The relevant NIST standards are ML-KEM (FIPS 203) for key establishment, and ML-DSA (FIPS 204) and SLH-DSA (FIPS 205) for signatures.
- Cryptographic agility as a requirement for new systems and procurement.
- PQC requirements in outsourcing contracts, including exit strategies.
Cryptographic inventory: what actually has to be recorded
Every place where RSA, Diffie-Hellman, ECDSA or an elliptic curve is used: TLS and VPN, certificates and PKI, digital signatures, key management and hardware security modules, database encryption, archives and backups. Plus two questions per system: by when does it have to be quantum-safe, and who delivers the update, you or a third party.
Harvest now, decrypt later: which data first
In Switzerland, business records and accounting vouchers must be retained for ten years, and AML documentation likewise. Anyone storing them encrypted today has to keep the data secret longer than an attacker has to wait for a quantum computer. The migration order therefore follows from the protection period of the data, not from the size of the system.
Cryptographic agility: the part that saves money
Cryptographic agility means being able to replace algorithms without rebuilding the architecture. As a requirement for every new purchase and every new contract it is cheap. Retrofitted later it becomes a project of its own. FINMA explicitly recommends it as a precondition for procurement and for new outsourcing agreements.
Suppliers and outsourcing
Institutions have to assess the PQC maturity of their service providers and anchor the requirements contractually. 60 percent of the institutions surveyed by FINMA are already in contact with their software suppliers for this reason. A supplier wanting to answer this needs the same inventory and a migration plan of its own. For institutions and suppliers with an EU nexus, DORA applies, Regulation (EU) 2022/2554, in force since 17 January 2025. DORA does not name post-quantum cryptography and sets no deadline of its own for it. Its technical standard, Commission Delegated Regulation (EU) 2024/1774, does require a documented policy on encryption and cryptographic controls that responds to developments in cryptanalysis and takes the confidentiality lifetime of the data into account. That is precisely where quantum migration begins.
Process and effort
- First conversation, 30 minutes, without obligation.
- Assessment at a fixed price: cryptographic inventory, risk analysis, options. Result in writing.
- Roadmap with milestones and target dates, ready for approval by executive management.
- Delivery in stages, each stage ending with something that runs.
- Handover: documentation, training for your team, an inventory kept current.
Delivery and set-up
Assessment, review and project management are delivered by me from Thalwil. For implementation, the development team of Fidentus Core in Sofia, the technology company of the Fidentus Group, is available. The contractual relationship and your contact person remain in Switzerland. Where data is processed is agreed in writing before the project starts.