Silver Brain Quantum
Post-quantum resilience for Swiss financial institutions.
FINMA has put the transition to quantum-safe cryptography on the management agenda. We help financial institutions turn cryptographic risk, dependencies and regulatory expectations into a structured, executable post-quantum transition roadmap.
FINMA Supervisory Guidance 05/2026
The transition is no longer a distant technology question.
On 9 July 2026, FINMA published Supervisory Guidance 05/2026 — a supervisory communication, not a new circular — pairing a survey of 60 authorised banks, insurers, managers of collective assets and financial market infrastructures with recommendations for the migration to quantum-safe cryptography.
The scope is migration to quantum-safe algorithms (NIST FIPS 203/204/205); quantum key distribution and quantum-computing business applications are explicitly out of scope. FINMA states that institutions are expected to address quantum-related risks in a timely manner under existing technology-neutral governance, operational-risk and resilience requirements — and will give the topic more weight in its ongoing supervisory work.
Strategy & roadmap
A board-adopted strategy and implementation plan, with milestones, priorities and target dates — for critical processes and for full migration.
Risk analysis & inventory
Every business process analysed for the encryption, signature and authentication technologies in use — in-house, outsourced or as-a-service — resulting in a comprehensive, continuously updated cryptographic inventory.
Critical data
Data needing long-term confidentiality, integrity or non-repudiation identified and prioritised against harvest-now-decrypt-later exposure. Hybrid classical-plus-PQC schemes recommended for the transition.
Crypto-agility
The ability to swap cryptographic algorithms without major architectural change — recommended as a requirement for systems to be procured or developed.
External providers
Responsibility stays with the outsourcing institution. PQC anchored contractually, planned into release cycles, and crypto-agility made a prerequisite for new outsourcing.
FINMA’s recommendation: a PQC roadmap by mid-2027 at the latest, based on a strategy adopted by the board of directors.
Sector readiness — survey of 60 institutions, Nov 2025 – Jan 2026
of surveyed institutions have neither planned nor implemented any measures on quantum-safe encryption.
have a specific roadmap for quantum-safe encryption — those that do plan 4–5 years for critical data and processes.
expect direct impact from quantum-computing cyber risks within seven years.
intend to draw up a roadmap within the next one to three years; 43% are undecided.
These figures describe the sector, not any single institution’s own maturity. The mid-2027 recommendation moves roadmap preparation onto the management agenda regardless of an institution’s starting point.
Why timing matters: harvest now, decrypt later
Capture
Encrypted traffic in transit, or encrypted archives, is intercepted or exfiltrated. Nothing visible happens.
Retain
The ciphertext is stored. It keeps its value for as long as the underlying data stays sensitive.
Decrypt
A cryptographically relevant quantum computer may defeat the historical public-key protection. Captured data becomes readable.
Migration protects future traffic and systems from that point onward, and data still under an institution’s control can be re-protected. Data already intercepted cannot be retroactively protected by a later migration — the reason long-lived confidentiality is prioritised first. There is no exact Q-day to plan around, only uncertainty to manage; exposure is concentrated in public-key schemes such as RSA, ECDSA, EdDSA, DH and EC-DH.
Read FINMA Supervisory Guidance 05/2026 →
References to FINMA guidance are provided for context and do not imply endorsement or affiliation.
The Roadmap’s Subject
PQC migration is an institution-wide transition.
The first principal PQC standards are final — ML-KEM (FIPS 203), ML-DSA (FIPS 204) and SLH-DSA (FIPS 205), finalised by NIST in August 2024. The roadmap’s subject is not the algorithms. It is the institution-level migration: where, what first, in which order, under whose ownership, and by when.
Where is quantum-vulnerable public-key cryptography used?
Across channels, interfaces, certificates, key management, archives and provider systems — in-house, outsourced and as-a-service.
Which data and processes need protection first?
Ranked by protection horizon, harvest-now-decrypt-later exposure, long-term assurance requirements and service criticality.
Which technology and external dependencies determine sequencing?
Certificate authorities before certificates, the trust layer before what rides on it, provider and counterparty release plans alongside the institution's own.
Which migration waves and target dates are realistic?
Including the two dates FINMA asks for: critical processes, and full migration.
What strategy, resources and residual risks does the board approve?
In a form that satisfies governance today and supervisory scrutiny later.
What We Do
From quantum risk to an executable transition programme.
Silver Brain Quantum helps institutions structure the transition at the level where technology, risk, governance and execution meet.
Executive & institutional readiness
Establish what the quantum transition means for the institution and what management needs to decide.
PQC strategy & roadmap
Develop the institution-specific roadmap from current exposure to controlled migration.
A board-ready strategy and roadmap: priorities, target dates, ownership, dependencies, resource frame and the first migration decisions.
Transformation & implementation
Turn the roadmap into managed execution.
Where specialised cryptographic or engineering capabilities are required, we integrate the appropriate expertise into a single transformation programme.
Who This Is For
Built for institutions where cryptography is embedded in the operating fabric.
We work with leadership teams across Switzerland’s financial sector, including institutions with complex technology estates, long-lived sensitive information, regulated operations and significant third-party dependencies.
Why Silver Brain
Enterprise transformation around consequential technology.
Silver Brain’s work sits between the executive decision and the technology implementation.
We combine strategy, operating-model design and technology fluency to structure transitions that cut across organisational boundaries. Our established work in AI-native transformation is built on the same premise: when a technology changes the capabilities and risks of an enterprise, the response cannot be confined to the technology layer alone.
Senior-led
Direct engagement around management decisions, programme design and executive alignment.
Enterprise-wide
Technology considered together with business processes, governance, data, vendors, ownership and operating implications.
Built for execution
Roadmaps designed to become transformation programmes, not to end as presentation material.