What Financial Supervisors Are Signalling On Quantum Risk
Central banks and financial supervisors are moving from awareness to specific asks on quantum risk. Here is what the G7, SAMA, MAS, FINMA, OSFI, the HKMA and Europol's forum have said, and how binding each is.
Checked against primary sources and independently reviewed on . Sources are listed at the end.
Banks and other financial institutions depend on cryptography for payments, trading, customer authentication and links with each other. That makes the sector a natural focus for quantum risk, and financial supervisors have been publishing on it since early 2024. Their documents range from statements that set no expectations to circulars with dates.
This article compares the main supervisory signals as of October 2026. It focuses on what each issuer asks for, how binding it is, and what that tells a financial institution about the direction of travel. DORA’s binding cryptography rules for EU firms are covered in a separate article in this section.
The Shared Message
Read together, these documents send a consistent message. Quantum risk needs attention from senior management and the board, an inventory of cryptographic assets and a risk assessment come early, and firms should plan for crypto-agility, meaning the ability to change algorithms without rebuilding systems. Where they differ is in how firmly they say it and whether they attach dates.
| Issuer | Date | Status | Inventory Expectation | Dates | Board Role |
|---|---|---|---|---|---|
| G7 Cyber Expert Group | Statement September 2024; roadmap January 2026 | Non-binding; says it sets no guidance or regulatory expectations | Discovery and inventory is phase 2 of 6, covering cryptographic assets, protocols and third-party dependencies | Critical systems 2030 to 2032; overall 2035 as a reference | Executive-level awareness and strategy in phase 1 |
| Monetary Authority of Singapore | Advisory 20 February 2024; announcement 28 July 2026 | Supervisory advisory; expectations with milestones announced for later in 2026 | Inventory of cryptographic solutions with algorithm, key length, owner and system | None in the 2024 advisory; MAS aims for quantum resilience before the end of this decade | Senior management should understand the threat |
| OSFI (Canada) | March 2026 | Technology risk bulletin; OSFI says its bulletins are not regulatory expectations | Inventorying cryptographic assets is phase 2 of 5 | Cites 2035 from other authorities; sets no deadline of its own | Not specified |
| Saudi Central Bank (SAMA) | 27 August 2026 | Binding circular | Procedures that accurately and comprehensively identify and classify all cryptographic assets | Inventory procedures by end Q4 2026; risk assessment by end Q1 2027 | Standing item for board committees, with reporting to the board |
| FINMA (Switzerland) | 9 July 2026 | Supervisory recommendation (Guidance 05/2026) | Comprehensive, continuously updated inventory, including outsourced and as-a-service systems | Post-quantum roadmap by mid-2027 | Strategy adopted by the board of directors |
| Hong Kong Monetary Authority | 27 July 2026 | Announcement of a sector objective | No inventory requirement; a toolkit is being developed to help banks set transition priorities | Full sector readiness by 2030 as an HKMA aim | Not specified in the announcement |
| Europol Quantum Safe Financial Forum | 7 February 2025 | Non-binding call to action | Urges prioritising the transition | None | Not specified |
International Reference Points: The G7 And Europol
The G7 Cyber Expert Group advises G7 finance ministers and central bank governors on cybersecurity. Its September 2024 statement described the benefits and risks of quantum computing. Its January 2026 roadmap goes further and sets out six phases: awareness and preparation, discovery and inventory, risk assessment and planning, migration execution, migration testing, and validation and monitoring.1
The roadmap is careful about its status. It states that it does not set guidance or regulatory expectations and that its timelines are not prescriptive. It notes that guidance in several jurisdictions often points to 2035, and suggests that addressing the most critical systems in 2030 to 2032 would limit the risk of the threat arriving early.1 Its value is as a common reference that national supervisors can build on.
In Europe, Europol’s Quantum Safe Financial Forum issued a call to action on 7 February 2025 urging financial institutions and policymakers to prioritise the move to quantum-safe cryptography.2 It carries no legal force, and the G7 group lists the forum among the sources it drew on.1
Asia Pacific And Canada: MAS, The HKMA And OSFI
The Monetary Authority of Singapore issued its advisory, MAS/TCRS/2024/01, on 20 February 2024, addressed to the chief executives of all financial institutions.3 It asks institutions to consider a set of measures under three headings: keeping up with quantum developments, maintaining an inventory of cryptographic assets, and building strategies and skills.
The inventory guidance is unusually specific. MAS suggests recording the algorithm and key length, who owns and maintains each cryptographic asset, and the system or application where it is used. It also suggests classifying dependent IT and data assets by sensitivity, criticality, risk exposure and how long they stay sensitive, so that migration can be prioritised. The advisory is supplementary to MAS’s technology risk management notices and guidelines.3
MAS has since signalled firmer expectations. On 28 July 2026 its managing director said MAS would issue supervisory expectations later in 2026, with milestones and timelines covering cryptographic asset inventories, migration priorities, technical capabilities and governance, and that MAS aims for financial institutions to reach quantum resilience before the end of this decade.4 Readers should check the MAS website to see whether those expectations have since been issued; the 2024 advisory is the MAS text that this article describes in detail.
On 27 July 2026 the Hong Kong Monetary Authority launched a whitepaper on the quantum preparedness of Hong Kong’s banking sector, together with its first Quantum Preparedness Index. The initial score was 2.3 out of 10, which the HKMA describes as an early stage of preparedness. It aims for full sector readiness by 2030 and is co-developing a toolkit to help banks identify transition priorities and improve crypto-agility.5 That 2030 date is the HKMA’s own objective, not a deadline imposed on banks.
In March 2026 Canada’s Office of the Superintendent of Financial Institutions (OSFI) published a technology risk bulletin on quantum readiness phases and timelines. It describes five phases: building competency and awareness, inventorying cryptographic assets, assessing risk and planning the migration, carrying out the transition, and testing and validating the result.6 It notes that guidance from other authorities generally points to quantum readiness across all systems by 2035, rather than setting that date itself. OSFI states that its technology risk bulletins are not regulatory expectations; they describe sound practices that institutions can apply at their discretion.7
SAMA In Saudi Arabia
SAMA’s circular 482021280, dated 27 August 2026, is the most specific supervisory instrument in this group. It requires SAMA-supervised financial institutions to do four things.8
- Carry out an enterprise-level assessment of quantum computing risks, with action plans, by the end of Q1 2027.
- Make sure their procedures for identifying and classifying all cryptographic assets are accurate and comprehensive, by the end of Q4 2026.
- Build plans to reach the required cryptographic resilience for priority assets, based on that classification. No date is given.
- Make quantum risk a standing monitoring item for the Information Security Supervisory Committee and the Risk Committee, with challenges and recommendations reported to the board.
- Upcoming
Saudi Arabia · Saudi Central Bank (SAMA) Binding
Ensure procedures identify and classify all cryptographic assets accurately and comprehensively.
- Upcoming
Saudi Arabia · Saudi Central Bank (SAMA) Binding
Complete a quantum risk assessment with action plans.
- Upcoming
Switzerland · FINMA Supervisory
Draw up a post-quantum cryptography roadmap.
FINMA In Switzerland
FINMA Guidance 05/2026, published on 9 July 2026, combines survey findings with recommendations.9 Only 8 percent of the institutions surveyed had a specific roadmap for quantum-safe cryptography. FINMA recommends that the work rest on a strategy adopted by the board of directors, that target dates be set for both critical processes and complete migration, and that a roadmap for post-quantum cryptography (PQC) be drawn up by mid-2027 at the latest.
FINMA sees a risk analysis as the first step, covering both the cryptographic methods in use and the critical data that needs long-term protection. To support it, FINMA asks institutions to analyse their business processes to identify the encryption, signature and authentication technologies in use. It expects that analysis to cover every information and communication technology (ICT) system, whether run in-house, outsourced or bought as a service, and to produce a comprehensive inventory that is kept current.9
What Firms Can Take From This
Three practical points follow for a financial institution anywhere.
First, start the inventory early. Every issuer above that gives operational guidance puts it among the first tasks, alongside a risk assessment, and SAMA attaches dates to both. Second, give the board a role. SAMA requires board committee oversight and FINMA recommends a board-adopted strategy. Third, cover third parties. The G7 roadmap and FINMA both stress dependencies on vendors and outsourced services, which are often where cryptography is hardest to see.
Footnotes
-
G7 Cyber Expert Group, “Advancing a Coordinated Roadmap for the Transition to Post-Quantum Cryptography in the Financial Sector”, January 2026. home.treasury.gov ↩ ↩2 ↩3
-
Europol, “Call for action: urgent plan needed to transition to post-quantum cryptography together”, 7 February 2025. europol.europa.eu ↩
-
Monetary Authority of Singapore, “MAS/TCRS/2024/01: Advisory on Addressing the Cybersecurity Risks Associated with Quantum”, 20 February 2024. mas.gov.sg ↩ ↩2
-
Monetary Authority of Singapore, “Remarks by Mr Chia Der Jiun, Managing Director, MAS, at the MAS Annual Report 2025/2026 Media Conference”, paragraphs 57 and 58, 28 July 2026. mas.gov.sg ↩
-
Hong Kong Monetary Authority, press release on the banking sector Quantum Preparedness Index, 27 July 2026. info.gov.hk ↩
-
Office of the Superintendent of Financial Institutions, “Quantum Readiness Phases and Timelines”, technology risk bulletin, March 2026. osfi-bsif.gc.ca ↩
-
Office of the Superintendent of Financial Institutions, “Technology risk bulletins”, consulted 7 October 2026. osfi-bsif.gc.ca ↩
-
Saudi Central Bank, “Circular 482021280: Enhancement of Operational Resilience to Address Quantum Computing Risks”, 27 August 2026. rulebook.sama.gov.sa ↩
-
FINMA, “FINMA Guidance 05/2026: Quantum computing”, 9 July 2026. finma.ch ↩ ↩2
Knowledge Hub content is general information. It is not legal advice, a compliance certification, a guarantee of security or a substitute for an assessment of your own systems. Standards and rules change; check the sources for the latest position.