17.07.2026

|

André Clerc

|

Commentary

FINMA statement on quantum computing: An important step – but is the clock ticking faster than expected?

Teaser Image

In its latest Supervisory Notice 05/2026, FINMA has sent a clear signal to the Swiss financial sector: Post-Quantum Cryptography (PQC) must now be placed on the risk management agenda with immediate effect. The fact that the regulator is tackling this issue proactively is most welcome.

However, anyone wishing to ensure that the migration is carried out pragmatically and in a future-proof manner should supplement the recommendations with a number of critical points that are somewhat overlooked in the document:

  1. The timeline is extremely ambitious (even if it doesn’t seem so): FINMA recommends a PQC roadmap to be in place by mid-2027. However, Google recently announced that it would make its entire infrastructure quantum-secure by 2029 – partly because recent research shows that ECC-256 encryption could be broken by optimised quantum computers in under 9 minutes. Waiting until 2027 just to start the roadmap is playing a risky game against the clock
  2. The underestimated danger: Trust Now – Forge Later: The communication rightly warns against ‘Harvest Now, Decrypt Later’ (the theft of encrypted data for later decryption). However, an equally significant risk concerns digital signatures and timestamps. If attackers compromise signatures or timestamps, they can retroactively forge transactions and contracts. This threatens the integrity of our entire system.
  3. Regulatory pressure is coming from outside: Swiss institutions do not operate in a vacuum. France, for example, will stop certifying products without quantum-secure encryption from mid-2027 onwards. International compliance pressure will massively accelerate the transition – long before domestic roadmaps are finalised or Cryptographically Relevant Quantum Computers (CRQCs) become widely available.
  4. Crypto-agility is not a one-way street: FINMA is correct in stating that, in future, PQC methods will also need to be replaced. However, we must realise that every algorithm (whether classical or new) can have vulnerabilities. True crypto-agility means building systems that allow us to replace algorithms on a weekly basis should a mathematical breakthrough render them obsolete overnight.

My conclusion: FINMA’s supervisory notice provides an excellent and necessary foundation. However, to put this into practice, we need to step up the pace and take a holistic view of the issue, looking beyond mere data confidentiality.

About the author

André Clerc
André Clerc
Managing Security Consultant
Dipl. Ing. FH Computer Science
CISSP, CAS Project Management

I support my customers with creativity and passion in areas such as Public Key Infrastructure (PKI), Crypto Agility, Internet of Things (IoT), authorization solutions, security architectures and system hardening. As a security architect and security engineer, I have extensive experience in the development of customized security solutions in complex IT environments. I am also involved in teaching practice-oriented PKI expertise at universities of applied sciences and at SGO in the area of Business Process Model and Notation (BPMN).

vCard Linkedin

Further publications

To all contributions