Invest1 publisher3 min readPublished
FINMA gives Swiss banks about a year to put a post-quantum plan before the board
Three regulators have now dated the migration away from today's encryption, and the nearest date belongs to FINMA, which wants supervised institutions to get a post-quantum strategy through the board by mid-2027.
The Investor · Invest desk

What happened
- The G7 Cyber Expert Group's January 2026 roadmap splits the financial sector's cryptographic migration into planning from 2025 to 2027, risk assessments through 2029, and completed execution by 2034.
- The US Treasury set up a Quantum-Readiness Task Force in August 2026 to coordinate the financial sector transition, with particular attention to third-party vendor risk and emerging digital assets.
- A Swiss survey cited by cryptobriefing.com found fewer than 8% of institutions currently hold a formal post-quantum cryptography roadmap.
Compiled by The InvestorSomething wrong?How this is made
Why it matters
- decision The mid-2027 date forces a Swiss bank to name a budget owner and a scope for work whose price appears in none of these documents, so the strategy paper is written before anyone can cost it.
- exposure Data intercepted before migration completes remains decryptable afterwards, so any record whose sensitivity outlasts the 2030 to 2034 execution period is exposed by the timetable.
- cost The expensive federal deadlines bite on vendors selling into agencies first, which means a bank whose suppliers already serve US federal buyers gets much of the work inside its licence and refresh spend.
- contradiction The dated rules skip tokens entirely while elliptic-curve chains carry the exposure, so a crypto custodian holds the risk with no deadline attached to it.
FINMA published its guidance in July 2026 and wants board-approved post-quantum strategies from every supervised institution by mid-2027 [4], which is about twelve months to produce a document [1]. A board paper is the cheapest item in a migration programme. The dated items that cost money sit at the end of 2030 and the end of 2031, and they apply to US federal agencies [2].
Banks meet those federal dates through their vendors. Executive Order 14412 points agencies at the NIST standards finalised in August 2024 as FIPS 203, 204 and 205, built on ML-KEM and ML-DSA [2][6]. Anyone selling key establishment into a federal agency has to ship the new algorithms before 31 December 2030 [2]. The standards were already 22 months old when the order was signed [2], and they will be six years and four months old when that first deadline lands [3]. The Treasury's Quantum-Readiness Task Force, established in August 2026, gives particular attention to third-party vendor risk [5].
cryptobriefing.com, which reported the sequence, wrote that it turns post-quantum cryptography "from a theoretical concern into a compliance deadline with real teeth" [12]. Its readiness number is a Swiss survey finding fewer than 8% of institutions with a formal roadmap [7]. More than 92% therefore need one in front of a board inside a year [4][4]. The survey's sample size and sponsor go unreported.
What none of these documents carries is a price [5]: no franc figure, no headcount, nothing estimated per institution. A bank budgeting for this is budgeting against a calendar: twelve months to a strategy [1], then the G7's five-year window between the end of risk assessments in 2029 and completion in 2034 [6]. The US signature deadline of 31 December 2031 falls three years inside that endpoint [7]. A bank with a US federal-facing business runs to the earlier date.
Two readings compete, and the split is about who absorbs the spend. In the first, the estate turns over anyway on normal refresh cycles between now and 2034, and the incremental cost is a re-procurement the vendors price. In the second, harvest-now-decrypt-later makes 2030 late, because an adversary can store intercepted traffic today and decrypt it once the machines are capable [8]. My read is the first for the compliance line and the second for the risk one, and I would drop it the day a supervised bank discloses post-quantum migration as material capital spending before 2030.
Tokens fall outside every document with a date on it. The G7 roadmap, the executive order and the FINMA guidance are all silent on cryptocurrencies [9]. Bitcoin and Ethereum sign transactions with elliptic curve cryptography, the family quantum machines are expected to break [10], and Shor's algorithm could in theory derive a private key from a public one [11]. The one hook in this material is the Treasury task force's scope, which names emerging digital assets [5].
What to watch
- A FINMA supervisory action or public finding against an institution that misses the mid-2027 strategy requirement.
- Any regulator or listed bank publishing a migration cost estimate, which would replace calendar arithmetic with a budget line.
- Whether the Treasury task force converts its emerging digital assets scope into a dated requirement for token infrastructure.