Quantum Risk · the urgent track

Post-Quantum Cryptography

Quantum computers will break today’s public-key encryption. The risk starts earlier than the machine: data harvested now can be decrypted later.

“Harvest now, decrypt later” means an attacker does not need a quantum computer today — recording encrypted traffic and stolen archives is enough, if the data still matters when the machine arrives. Long-lived confidentiality, digital signatures, and trusted communication are exposed years before any cryptographically relevant quantum computer exists.

qubit-lab.ch helps regulated institutions find a lean, efficient path to quantum-safe: awareness, stakeholder alignment, exposure visibility, and the roadmap supervisors now expect — fixed in scope, without a standing program.

The supervisory anchor

FINMA has put a date on it: a PQC roadmap by mid-2027

In its Guidance 05/2026 “Quantum Computing” (July 2026), based on a survey of 60 Swiss financial institutions, FINMA recommends that a PQC roadmap be drawn up by mid-2027 at the latest. It is a recommendation, not a binding rule — but it is the clearest supervisory signal Swiss institutions have, and the survey shows how far most still have to go:

mid-2027

PQC roadmap recommended by then at the latest

Board-adopted strategy with milestones and target dates (§3.1)

72%

have not yet planned or implemented any PQC measures

Of 60 surveyed Swiss financial institutions

~2/3

expect quantum cyber risks to be directly relevant within 7 years

17% within 1–3 years, 52% within 4–7 years

10 yrs

expected horizon for a quantum computer cracking RSA-2048

~2/3 expect a machine able to do it within 24 hours to exist within ten years at the latest

The guidance names five areas of recommended action:

1  Strategy and PQC roadmap2  Risk analysis and cryptographic inventory3  Protection of critical data — harvest-now-decrypt-later, hybrid solutions4  Crypto-agility5  External service providers

Source: FINMA Guidance 05/2026 “Quantum Computing”, published 9 July 2026; survey of 60 Swiss financial institutions (banks, insurers, managers of collective assets, financial market infrastructures), November 2025 – January 2026. FINMA recommends; the guidance is not a binding deadline.

Read the FINMA guidance →
PQC direction is emerging and liability exists today

Management exposure does not depend on a dedicated PQC law.

Sensitive data captured today may still need protection years from now, and digital trust mechanisms created today may need to remain defensible in the future. The immediate question is not how to migrate — it is how to move from general awareness to a structured view of exposure, ownership, and planning readiness, before urgency sets the agenda.

Step 1 · Align

PQC Mobilization

A focused, workshop-based entry step: build awareness and align management, legal, risk, business, and technology stakeholders.

Output: a shared understanding of PQC risk and likely exposure areas — the informed basis a board-level roadmap decision needs. Fixed scope; the natural first move toward the mid-2027 recommendation.

Explore PQC Mobilization

Step 2 · Assess

PQC Navigator

A structured readiness assessment: current status, cryptographic exposure and dependencies, key gaps, and planning maturity.

Includes Mobilization, then delivers a structured management summary, a readiness view across the key assessment dimensions, and prioritized gaps and action areas — the material a PQC roadmap is actually built from.

Where does your institution stand?

A short call is usually enough to see whether Mobilization, the full Navigator assessment, or simply a briefing is the right next step — lean and efficient, like everything else on this site.

Book an Intro Call

Background viewing — short videos explaining PQC concepts in plain terms, for teams that want the fundamentals before or after a conversation.

PQC in plain terms

Filter by tag
Q-Day and Post-Quantum Cryptography (PQC)
STRATEGY#11
Released 18 Sept 2025

Q-Day and Post-Quantum Cryptography (PQC)

Open on YouTube

Have a look and see why the UK and EU issued regulatory guidance on the PQC in summer 2025. This video is not really about quantum computing and quantum algorithms in finance, but about the impact of quantum computing on current and future cryptography. A lot of half-baked information is going around, so I decided to make a video that explains modern cryptography from scratch - as simple as possible, but not simpler, as usual in my videos.

The Quantum Roadmap
STRATEGY#10
Released 04 Sept 2025

The Quantum Roadmap

Open on YouTube

The Business Perspective on Quantum Technology: How to Develop Your Corporate Quantum Roadmap. Quantum is no longer just a research topic - it is becoming a strategic challenge for industries like finance, pharma, and energy. The real question is: how should companies prepare today for a technology that will mature over the next 10-15 years? The key message: it is not about counting qubits. It is about aligning technology evolution with corporate strategy, managing risks early, and building the capability to capture future opportunities.

Start Now or Wait 10 Years?
STQ#1
Released 28 Sept 2025

Start Now or Wait 10 Years?

Open on YouTube

Should we wait until quantum hardware matures - or already start today with hybrid algorithms? A straight talk on opportunities and risks.