Switzerland Post-Quantum Cryptography Regulation: NCSC Guidance and FINMA 05/2026
Switzerland has no single PQC statute. NCSC's technology briefs say start now; FINMA Guidance 05/2026 expects a board-backed roadmap by mid-2027, with inventory, crypto-agility and harvest-now-decrypt-later prioritisation.
NA
Nagib Aouini··10 min read
Switzerland Post-Quantum Cryptography Regulation: NCSC Guidance and FINMA 05/2026
Switzerland has not passed a post-quantum cryptography statute and has not published a national 2028/2031/2035 calendar in the style of the UK NCSC or Germany's BSI TR-02102. That absence is not the same as a free pass. The National Cyber Security Centre (NCSC) has told organisations that action on PQC is required, and for FINMA-supervised financial institutions the expectation is now specific: a board-approved migration roadmap by mid-2027, built on a cryptographic inventory, risk analysis of long-lived data, and crypto-agility in outsourcing.
This guide covers what the NCSC and FINMA have actually said, who sits in scope, which dates matter, and the first steps that turn guidance into a programme: inventory, HSM/KMS readiness, and hybrid PQC deployment. For the FINMA landing path specifically, see also our FINMA 05/2026 use case.
In November 2024 the NCSC published an assessment stating that action is required on post-quantum cryptography. In December 2025 it followed with a technology brief on quantum computers and PQC. The brief's practical message is consistent across both documents:
Assess where current asymmetric cryptography is used
Inventory encryption, signatures and authentication dependencies
Prioritise data with long confidentiality requirements threatened by harvest-now-decrypt-later collection
Require providers and outsourcing partners to plan migration rather than waiting for a Swiss statute to name algorithms
The NCSC points to the NIST-standardised algorithms (ML-KEM / FIPS 203, ML-DSA / FIPS 204, SLH-DSA / FIPS 205) as the technical destination Switzerland's federal monitoring work already tracks. It does not invent a parallel Swiss algorithm suite.
FINMA Guidance 05/2026: roadmap by mid-2027
On 9 July 2026 FINMA published Supervisory Communication 05/2026 on quantum computing. The communication reports a survey of 60 supervised institutions (November 2025 to January 2026) and then sets supervisory expectations.
Survey findings FINMA chose to publish:
Institutions are aware of the cryptographically relevant quantum risk
Only about 8% held a concrete migration roadmap
Roughly 72% had taken no post-quantum measures at the time of the survey
Respondents themselves ranked crypto-agility and a cryptographic inventory as high-value foundations for migration
FINMA's recommended measures are concrete enough to plan against:
A strategy adopted by the board of directors (Oberleitungsorgan), from which an implementation plan with milestones and priorities is derived
Target dates for complete migration and for migration of critical business processes
Institution-specific risk analysis that treats harvest-now-decrypt-later as a real confidentiality risk for long-lived data
A comprehensive, continuously updated cryptographic inventory covering data in transit (VPN, TLS, HTTPS and similar), data at rest, digital signatures, key management and authentication mechanisms
Migration plans for systems still using quantum-vulnerable algorithms, sized to the associated risk
Crypto-agility as a prerequisite for new software and data outsourcing, and incorporation into existing outsourcing as early as practicable
A PQC roadmap drawn up by mid-2027 at the latest
FINMA frames this inside existing operational risk and resilience obligations. It is not inventing a new licence condition from nothing; it is telling institutions that those existing duties already require forward-looking cryptography risk management.
Federal PKI and procurement
Separately, the Federal Office of Information Technology, Systems and Telecommunication (FOITT / BIT) has been adjusting Swiss Government PKI parameters and signalling preparation for post-quantum cryptography on government certificate classes. If you issue into or rely on Swiss Government PKI, treat BIT's migration work as a dependency on your own certificate and signing roadmap, even if FINMA does not supervise you.
Who Is in Scope
Regime
Who it binds
What it demands on PQC
FINMA Guidance 05/2026
FINMA-supervised financial institutions (banks, insurers and other supervised entities in the survey population and broader supervised perimeter)
Board-backed strategy, inventory, risk analysis, mid-2027 roadmap, crypto-agility in outsourcing
NCSC technology briefs
Broad audience: enterprises and operators handling information requiring protection
Start inventory and migration planning; prioritise long-lived confidential data; push providers for PQC plans
Revised FADP (nDSG)
Controllers and processors of personal data under Swiss data protection law
Appropriate technical and organisational measures; encryption remains a risk-proportionate control, not a named PQC mandate
Federal administration / BIT PKI
Federal systems and parties using Swiss Government PKI
Follow FOITT/BIT certificate and algorithm migration work for government trust services
Critical infrastructure / NCS monitoring
Operators tracked under the National Strategy for the Protection of Switzerland against Cyber-Risks
NCSC and Cyber-Defence Campus monitoring; no separate published national PQC completion statute as of this writing
Most Swiss banks and insurers sit in the FINMA row and the FADP row at once. Technology providers to those institutions inherit crypto-agility expectations through outsourcing clauses even when FINMA does not supervise the provider directly.
Board-approved PQC roadmap with milestones and priorities
FINMA Guidance 05/2026
Institution-defined
Target dates for critical-process migration and full migration
FINMA expects you to set these in the roadmap; it does not publish a single national 2030/2035 cutover for all Swiss systems
Aligned to NIST / peers
Hybrid then PQC-only deployment following FIPS 203/204/205
NCSC technical direction; no Swiss-only algorithm list
Switzerland is stricter than many jurisdictions on the near-term governance artefact (roadmap by mid-2027) and looser on a single national technical sunset date. Do not read the missing 2031 key-agreement sunset as permission to delay discovery. FINMA's survey already treated missing roadmaps as an operational-risk gap.
For comparison: Germany's BSI names 2030/2031/2035 technical dates; the UK NCSC names 2028/2031/2035 programme milestones; the US federal path names HVA key-establishment by 2030. A Swiss FINMA roadmap that ignores those peer calendars for cross-border systems will age poorly.
Practical First Steps
1. Cryptographic inventory
FINMA is explicit: risk analysis of business processes should produce a comprehensive inventory of cryptographic methods in use, kept current. Cover at least:
Outsourced systems where cryptography is performed by a third party
Mark which algorithms are quantum-vulnerable and which data sets need multi-year confidentiality. That marking is what turns the inventory into a prioritised migration plan rather than a spreadsheet. A CBOM is the durable format; see our CBOM guide.
2. HSM and KMS readiness
FINMA lists key management inside the inventory scope for a reason. A roadmap that changes TLS ciphersuites but cannot re-issue or protect new key types in your HSMs will stall at the first critical process.
Inventory every key store that holds material for in-scope business processes
Confirm support (or a dated upgrade path) for NIST PQC key types and larger hybrid artefacts
Decide which keys must remain under Swiss or institution control for secrecy and outsourcing reasons, separate from algorithm choice
Put crypto-agility language into new outsourcing contracts now; FINMA recommends it as a prerequisite for new software and data arrangements
3. Hybrid PQC deployment
Neither the NCSC nor FINMA requires a Swiss-specific hybrid construction. Both point at the same NIST standards the rest of the regulated world is adopting. Hybrid classical-plus-ML-KEM on high-exposure transit paths is the practical first deployment pattern:
Customer- and partner-facing TLS termination
Inter-bank and market-infrastructure links
Remote access and site-to-site IPsec
Use the same implementation paths covered in our F5 and FortiGate guides. Document the hybrid step as transitional, with a path to drop the classical half once your risk committee accepts PQC-only for that channel. FINMA's own survey already treated crypto-agility as a core success factor; a hybrid deployment you cannot reverse or advance is incomplete.
The Technical Checklist
Board (or equivalent governing body) has adopted a PQC / quantum-risk strategy, or a dated paper is on the agenda before mid-2027
A written roadmap exists with milestones, owners, and target dates for critical processes and full migration
Cryptographic inventory covers transit, at-rest, signatures, authentication and key management, including outsourced systems
Inventory flags quantum-vulnerable algorithms and data with long confidentiality requirements
Harvest-now-decrypt-later is explicitly addressed in the risk analysis, not only "quantum computer exists" scenarios
HSM/KMS platforms can support planned PQC/hybrid key types, or replacement is scheduled
New outsourcing contracts in software and data include crypto-agility requirements; existing contracts have a remediation path
Hybrid PQC is piloted on at least one high-exposure transit path with a documented path to PQC-only
If you rely on Swiss Government PKI, BIT/FOITT migration plans are tracked as an external dependency
How This Maps to DuoKey Cockpit
FINMA's mid-2027 roadmap starts with an inventory you can maintain, not a one-off workshop slide. DuoKey's CBOM generation and Quantum Risk Score produce the continuously updated cryptographic posture FINMA describes, including outsourced and multi-cloud estates. Details are in the CBOM guide and the FINMA 05/2026 use case.
Hybrid deployment on edge TLS and IPsec maps to the same F5 and FortiGate MCP-assisted workflows used in other jurisdictions. Key control that has to remain with the institution, a recurring Swiss secrecy and outsourcing concern, maps to DuoKey's customer-held key and MPC vault model rather than leaving migration solely in a cloud provider's shared-responsibility matrix.
FAQ
Q: Is FINMA Guidance 05/2026 binding law?
It is a supervisory communication, not a Federal Act. FINMA published it as the articulation of what existing operational-risk and resilience expectations already require for quantum-related cyber risk. Supervised institutions that arrive at mid-2027 without a roadmap should expect that gap to surface in supervisory dialogue.
Q: Does Switzerland mandate specific PQC algorithms?
Not in a Swiss-named suite. NCSC material points to NIST FIPS 203/204/205. Plan against those standards unless and until a Swiss federal standard says otherwise.
Q: We are not a bank. Does any of this apply?
NCSC guidance still applies as national cyber advice. FADP still requires appropriate security for personal data. If you are a critical technology provider to FINMA-supervised institutions, expect crypto-agility and migration evidence to appear in contracts even without direct FINMA supervision.
Q: How does this compare to the UK or German timelines?
Switzerland is earlier on the governance artefact (roadmap by mid-2027) and less prescriptive on a single national technical sunset. Use peer timelines (UK, Germany, US) to set technical milestones inside your FINMA roadmap so cross-border systems are not planned twice.
Conclusion
Swiss PQC regulation is guidance-led, not statute-led, and that is enough to create a real deadline for financial institutions: a board-backed roadmap by mid-2027, sitting on a living cryptographic inventory, harvest-now-decrypt-later risk analysis, and crypto-agile outsourcing. The NCSC has already told the wider economy to start the same inventory work. Build the inventory, prove your key stores can change algorithms, and deploy hybrid PQC on the transit paths that already carry long-lived confidential data.