INSIGHTS
Quantum Computing in 2026: What Belongs on a Swiss Bank Board Agenda – and What Doesn't
Silvan Schriber · August 2026
Quantum computing crossed, in 2026, from a research storyline into a governance one. The hardware progress reported this year is real, and the algorithmic work behind it moved expert timelines materially – without a single working cryptographic attack having been demonstrated. For a Swiss bank board, the operative question is no longer whether the physics will arrive on schedule. FINMA has already put a date on it: it recommends a board-approved PQC roadmap by mid-2027 at the latest – and in supervisory practice, a FINMA recommendation of this kind functions as an expectation, not a suggestion. Separately, the confidentiality of data stolen today is compromised the moment it is copied, not the moment it is decrypted. Both facts argue for treating this as a funded, owned, multi-year technology programme starting now, independent of how the underlying science resolves.
Three storylines from the laboratory, one signal for risk officers
Three announcements dominated the 2026 quantum-hardware narrative. None of them can break RSA-2048 or elliptic-curve cryptography today, or on any credible near-term estimate. What changed the risk conversation was a fourth, quieter piece of work: an algorithmic paper that sharply cut the estimated hardware bar for a cryptographic attack.
-
Google Quantum AI – Willow chip, "Quantum Echoes" (OTOC) algorithm, 22.10.2025: first verifiable quantum advantage on a physics benchmark, ~13,000× faster than the best classical estimate, peer-reviewed in Nature. Caveat: a physics-verification benchmark, not a cryptographic or general-purpose computation.
-
IBM – Nighthawk (120-qubit) and Loon processors, announced November 2025: targets a narrower quantum-advantage claim by end-2026, with a roadmap running Kookaburra (2026) → Cockatoo (2027) → "Starling" fault-tolerant system, 200 logical qubits, targeted for 2029. Caveat: a roadmap, not a delivered result – the intermediate steps are still outstanding.
-
Microsoft – Majorana 2 topological-qubit chip, 02.06.2026: reports ~1,000× coherence improvement (qubit lifetime >20 seconds vs. a microsecond operating requirement). Caveat: pre-peer-review, and follows unresolved scientific scepticism over the 2025 Majorana 1 claims (Nature, 2026: "researchers are still sceptical").
-
Google Research (C. Gidney) – revised RSA-2048 factoring requirement, May 2025 (arXiv:2505.15917): cuts the estimated qubits needed from ~20 million (2019 estimate) to under 1 million, a 20-fold reduction, via improved arithmetic and error-correction. Caveat: runtime rises correspondingly (under a week, vs. 8 hours in 2019), and it still requires a fault-tolerant machine that does not yet exist.
The Gidney paper matters more to a risk committee than any single chip announcement, because it moved the expert consensus, not just the hardware. The Global Risk Institute / evolutionQ Quantum Threat Timeline Report 2025 – an annual survey of roughly two dozen international experts – puts the probability of a cryptographically relevant quantum computer within ten years (by 2036) at 49% under its optimistic reading, up from 34% a year earlier: the largest single-year increase in the survey's seven-year history. The same survey puts the 20-year probability (by 2046) at 92% or higher. These remain expert estimates, not verified facts, and should be labelled as such in any board paper that cites them.
Why the exact arrival date matters less than it appears to
The relevant threat model for a Swiss bank is "harvest now, decrypt later" (HNDL): encrypted traffic and stored data captured today can be decrypted retrospectively once a cryptographically relevant machine exists. This reframes the question from "when does the machine arrive" to "how long must today's data stay confidential." Client relationship data, cross-border structuring records, and historical transaction files routinely carry confidentiality obligations measured in decades under Swiss practice. On that horizon, even the survey's more conservative estimates place the threat inside the exposure window. The practical implication is that the timeline debate, while scientifically live, should not be allowed to delay action – the clock on today's data started when it was first transmitted or stored, not when the physics community reaches consensus.
The regulatory calendar is now the forcing function
FINMA Guidance 05/2026, published in July 2026, is a supervisory communication rather than a new circular: it clarifies that existing, technology-neutral operational-risk and resilience rules already capture quantum risk. That has a practical consequence – there is no new rulemaking process to wait for. The guidance sets five expectations: a board-approved PQC strategy and roadmap; a comprehensive cryptographic inventory; prioritised protection of long-lived, high-value data; crypto-agility designed into systems and procurement; and a documented assessment of service-provider PQC readiness. It applies to banks, insurers, asset managers, and financial-market infrastructures, with the roadmap due by mid-2027.
This sits inside a coordinated international timeline rather than a purely domestic one, which is useful context for a board weighing whether Switzerland is ahead of, or behind, its peers.
-
15.01.2026 – G7 financial-sector quantum roadmap published, non-binding (G7 Cyber Expert Group).
-
March 2026 – Swiss national quantum strategy published (Swiss Confederation).
-
July 2026 – FINMA Guidance 05/2026 published (FINMA).
-
Mid-2027 – Board-approved PQC roadmap "recommended" (FINMA Guidance 05/2026).
-
2030–2032 – Critical financial-system migration priority window (G7 Cyber Expert Group roadmap).
-
2030 – NIST-standardised legacy algorithms scheduled for deprecation (NIST, cited by SIX Group).
-
2035 – Legacy algorithms scheduled for prohibition (NIST, cited by SIX Group).
-
2035 – Sector-wide PQC migration completion horizon (G7 Cyber Expert Group roadmap).
The technical target is settled: NIST's three finalised standards – FIPS 203 (ML-KEM, key exchange) and FIPS 204/205 (ML-DSA and SLH-DSA, digital signatures). SIX Group, Switzerland's own financial-market infrastructure operator, has published its migration posture around these standards, centred on a cryptographic inventory, hybrid deployment during transition, and staged crypto-agility – but has not, at the time of writing, published a firm internal completion date. Boards should ask their own institution's payment and custody counterparties, including SIX, for a dated roadmap rather than a policy statement.
The dependency layer is where the real gap sits
A bank's own migration is necessary but not sufficient. Swiss institutions run on a small number of shared platforms – core-banking providers such as Avaloq, Finnova, and Temenos, financial-market infrastructure via SIX, SWIFT messaging, and cloud hosting among them. FINMA's own 2026 industry survey work, referenced in its guidance, identified a material gap between vendors' stated awareness of quantum risk and the maturity of their actual implementation timelines. A board should treat a management update that stops at "we are quantum-safe" as incomplete without evidence that these third-party dependencies are being tracked contractually – through PQC clauses embedded in outsourcing agreements and renewal cycles – and technically, through cryptographic-discovery tooling on live traffic rather than manual inventories.
There is a domestic capability dimension worth board awareness, though it does not change the near-term compliance mandate. Switzerland's first national quantum strategy, published in March 2026, is candid that current hardware error rates (roughly 10⁻³) remain about seven orders of magnitude above what large-scale computation requires (roughly 10⁻¹⁰), and that a useful machine likely needs upward of 100,000 physical qubits to yield 1,000 reliable logical ones. The strategy also flags that Switzerland has no national quantum key-distribution network – a gap in sovereign quantum-communication infrastructure that may matter over a longer horizon for how Swiss institutions position on quantum-safe channels, distinct from the PQC-migration work required today.
One line on markets
Listed quantum-computing equities – IonQ, Rigetti, and D-Wave among them – were volatile through 2026, with repeated large capital raises drawing scrutiny from financial commentators. That is an investment-thesis question, distinct from the operational and cyber-risk narrative above, and the two should not be allowed to blur in board discussion. The hardware progress cited in this briefing is peer-reviewed where so noted and stands independently of how the related equities trade.
What the board should ask management for now
-
A named executive owner – Chief Risk Officer or Chief Information Security Officer – for the PQC transition, appointed now rather than in 2027.
-
Commissioning of the cryptographic inventory before year-end 2026, sized to complete well ahead of the mid-2027 roadmap deadline given typical 12–18 month inventory timelines.
-
A data-classification exercise flagging the required confidentiality horizon of client and structuring data, with hybrid PQC applied first to data that is both long-lived and currently in transit or storage.
-
PQC and crypto-agility clauses in every outsourcing and core-system contract renewal from now, addressed by name to core-banking, market-infrastructure, and cloud providers.
-
A standing semi-annual board briefing on quantum-threat timeline and vendor-readiness status, so the roadmap remains a governed programme rather than a document filed once and revisited in 2027.
Bottom line, restated
The consequential quantum-computing news of the past year is algorithmic as much as physical, and it moved expert timelines without a demonstrated attack. For a Swiss bank board, that debate does not need to be resolved before acting. FINMA has already turned it into a compliance deadline, the data at risk is compromised at the point of theft rather than the point of decryption, and the vendor ecosystem – not the bank's own systems alone – is the layer most likely to be under-prepared. The prudent position is to fund, own, and govern this now as a multi-year technology-refresh programme, not a 2027 project.