FINMA Quantum Computing PQC Guidance
- Brian Couzens
- Jul 12
- 1 min read
FINMA's new guidance on Quantum Computing is welcome.
It sends an important signal. Quantum risk is no longer a theoretical technology discussion. It is a governance and operational resilience issue that financial institutions are expected to address now.
I agree with the direction of travel.
Board-approved strategies, risk analysis, cryptographic inventories, crypto-agility and supplier management all deserve attention.
However, I was struck by how extraordinarily light the guidance is.
At just eight pages, it identifies what institutions should do, but offers very little on how to do it.
There is almost no discussion of programme governance, operating models, transformation methodology, decision-making, prioritisation, funding, assurance or independent validation. These are precisely the areas where large-scale PQC programmes succeed or fail.
The recommendation to build a cryptographic inventory is sound. But inventories do not migrate organisations. They provide visibility. The real challenge is converting that visibility into risk-based decisions, governance, investment and execution.
Perhaps that is intentional. Regulators should avoid prescribing implementation models.
Even so, many organisations looking for practical direction will finish the document with more questions than answers.
The guidance is an important milestone.
It is not a blueprint.
That work still sits with the industry.
#PQC #PostQuantumCryptography #FINMA #CryptographicGovernance #OperationalResilience #CyberRisk #QuantumRisk #EnterpriseTransformation



Comments