CRYPTOGRAPHY COMPLIANCE / ADVANCED

What Financial Supervisors Are Signalling On Quantum Risk

Central banks and financial supervisors are moving from awareness to specific asks on quantum risk. Here is what the G7, SAMA, MAS, FINMA, OSFI, the HKMA and Europol's forum have said, and how binding each is.

Checked against primary sources and independently reviewed on . Sources are listed at the end.

Banks and other financial institutions depend on cryptography for payments, trading, customer authentication and links with each other. That makes the sector a natural focus for quantum risk, and financial supervisors have been publishing on it since early 2024. Their documents range from statements that set no expectations to circulars with dates.

This article compares the main supervisory signals as of October 2026. It focuses on what each issuer asks for, how binding it is, and what that tells a financial institution about the direction of travel. DORA’s binding cryptography rules for EU firms are covered in a separate article in this section.

The Shared Message

Read together, these documents send a consistent message. Quantum risk needs attention from senior management and the board, an inventory of cryptographic assets and a risk assessment come early, and firms should plan for crypto-agility, meaning the ability to change algorithms without rebuilding systems. Where they differ is in how firmly they say it and whether they attach dates.

IssuerDateStatusInventory ExpectationDatesBoard Role
G7 Cyber Expert GroupStatement September 2024; roadmap January 2026Non-binding; says it sets no guidance or regulatory expectationsDiscovery and inventory is phase 2 of 6, covering cryptographic assets, protocols and third-party dependenciesCritical systems 2030 to 2032; overall 2035 as a referenceExecutive-level awareness and strategy in phase 1
Monetary Authority of SingaporeAdvisory 20 February 2024; announcement 28 July 2026Supervisory advisory; expectations with milestones announced for later in 2026Inventory of cryptographic solutions with algorithm, key length, owner and systemNone in the 2024 advisory; MAS aims for quantum resilience before the end of this decadeSenior management should understand the threat
OSFI (Canada)March 2026Technology risk bulletin; OSFI says its bulletins are not regulatory expectationsInventorying cryptographic assets is phase 2 of 5Cites 2035 from other authorities; sets no deadline of its ownNot specified
Saudi Central Bank (SAMA)27 August 2026Binding circularProcedures that accurately and comprehensively identify and classify all cryptographic assetsInventory procedures by end Q4 2026; risk assessment by end Q1 2027Standing item for board committees, with reporting to the board
FINMA (Switzerland)9 July 2026Supervisory recommendation (Guidance 05/2026)Comprehensive, continuously updated inventory, including outsourced and as-a-service systemsPost-quantum roadmap by mid-2027Strategy adopted by the board of directors
Hong Kong Monetary Authority27 July 2026Announcement of a sector objectiveNo inventory requirement; a toolkit is being developed to help banks set transition prioritiesFull sector readiness by 2030 as an HKMA aimNot specified in the announcement
Europol Quantum Safe Financial Forum7 February 2025Non-binding call to actionUrges prioritising the transitionNoneNot specified
Supervisory and international signals on quantum risk for the financial sector, as of October 2026. Status reflects the issuer's own description where one is given.

International Reference Points: The G7 And Europol

The G7 Cyber Expert Group advises G7 finance ministers and central bank governors on cybersecurity. Its September 2024 statement described the benefits and risks of quantum computing. Its January 2026 roadmap goes further and sets out six phases: awareness and preparation, discovery and inventory, risk assessment and planning, migration execution, migration testing, and validation and monitoring.1

The roadmap is careful about its status. It states that it does not set guidance or regulatory expectations and that its timelines are not prescriptive. It notes that guidance in several jurisdictions often points to 2035, and suggests that addressing the most critical systems in 2030 to 2032 would limit the risk of the threat arriving early.1 Its value is as a common reference that national supervisors can build on.

In Europe, Europol’s Quantum Safe Financial Forum issued a call to action on 7 February 2025 urging financial institutions and policymakers to prioritise the move to quantum-safe cryptography.2 It carries no legal force, and the G7 group lists the forum among the sources it drew on.1

Asia Pacific And Canada: MAS, The HKMA And OSFI

The Monetary Authority of Singapore issued its advisory, MAS/TCRS/2024/01, on 20 February 2024, addressed to the chief executives of all financial institutions.3 It asks institutions to consider a set of measures under three headings: keeping up with quantum developments, maintaining an inventory of cryptographic assets, and building strategies and skills.

The inventory guidance is unusually specific. MAS suggests recording the algorithm and key length, who owns and maintains each cryptographic asset, and the system or application where it is used. It also suggests classifying dependent IT and data assets by sensitivity, criticality, risk exposure and how long they stay sensitive, so that migration can be prioritised. The advisory is supplementary to MAS’s technology risk management notices and guidelines.3

MAS has since signalled firmer expectations. On 28 July 2026 its managing director said MAS would issue supervisory expectations later in 2026, with milestones and timelines covering cryptographic asset inventories, migration priorities, technical capabilities and governance, and that MAS aims for financial institutions to reach quantum resilience before the end of this decade.4 Readers should check the MAS website to see whether those expectations have since been issued; the 2024 advisory is the MAS text that this article describes in detail.

On 27 July 2026 the Hong Kong Monetary Authority launched a whitepaper on the quantum preparedness of Hong Kong’s banking sector, together with its first Quantum Preparedness Index. The initial score was 2.3 out of 10, which the HKMA describes as an early stage of preparedness. It aims for full sector readiness by 2030 and is co-developing a toolkit to help banks identify transition priorities and improve crypto-agility.5 That 2030 date is the HKMA’s own objective, not a deadline imposed on banks.

In March 2026 Canada’s Office of the Superintendent of Financial Institutions (OSFI) published a technology risk bulletin on quantum readiness phases and timelines. It describes five phases: building competency and awareness, inventorying cryptographic assets, assessing risk and planning the migration, carrying out the transition, and testing and validating the result.6 It notes that guidance from other authorities generally points to quantum readiness across all systems by 2035, rather than setting that date itself. OSFI states that its technology risk bulletins are not regulatory expectations; they describe sound practices that institutions can apply at their discretion.7

SAMA In Saudi Arabia

SAMA’s circular 482021280, dated 27 August 2026, is the most specific supervisory instrument in this group. It requires SAMA-supervised financial institutions to do four things.8

  1. Carry out an enterprise-level assessment of quantum computing risks, with action plans, by the end of Q1 2027.
  2. Make sure their procedures for identifying and classifying all cryptographic assets are accurate and comprehensive, by the end of Q4 2026.
  3. Build plans to reach the required cryptographic resilience for priority assets, based on that classification. No date is given.
  4. Make quantum risk a standing monitoring item for the Information Security Supervisory Committee and the Risk Committee, with challenges and recommendations reported to the board.
  1. Upcoming

    Saudi Arabia · Saudi Central Bank (SAMA) Binding

    Ensure procedures identify and classify all cryptographic assets accurately and comprehensively.

    Circular 482021280 on quantum computing risks. Applies to SAMA-regulated financial institutions. Source · Verified 7 Oct 2026

  2. Upcoming

    Saudi Arabia · Saudi Central Bank (SAMA) Binding

    Complete a quantum risk assessment with action plans.

    Circular 482021280 on quantum computing risks. Applies to SAMA-regulated financial institutions. Source · Verified 7 Oct 2026

  3. Upcoming

    Switzerland · FINMA Supervisory

    Draw up a post-quantum cryptography roadmap.

    FINMA Guidance 05/2026. Applies to FINMA-supervised institutions (recommendation). Source · Verified 7 Oct 2026

Countdowns run to the end of each deadline date (UTC) and are calculated in your browser. "Binding" means legally or contractually required; other labels describe supervisory expectations, guidance, drafts or announcements. Always check the source for the current text.

FINMA In Switzerland

FINMA Guidance 05/2026, published on 9 July 2026, combines survey findings with recommendations.9 Only 8 percent of the institutions surveyed had a specific roadmap for quantum-safe cryptography. FINMA recommends that the work rest on a strategy adopted by the board of directors, that target dates be set for both critical processes and complete migration, and that a roadmap for post-quantum cryptography (PQC) be drawn up by mid-2027 at the latest.

FINMA sees a risk analysis as the first step, covering both the cryptographic methods in use and the critical data that needs long-term protection. To support it, FINMA asks institutions to analyse their business processes to identify the encryption, signature and authentication technologies in use. It expects that analysis to cover every information and communication technology (ICT) system, whether run in-house, outsourced or bought as a service, and to produce a comprehensive inventory that is kept current.9

What Firms Can Take From This

Three practical points follow for a financial institution anywhere.

First, start the inventory early. Every issuer above that gives operational guidance puts it among the first tasks, alongside a risk assessment, and SAMA attaches dates to both. Second, give the board a role. SAMA requires board committee oversight and FINMA recommends a board-adopted strategy. Third, cover third parties. The G7 roadmap and FINMA both stress dependencies on vendors and outsourced services, which are often where cryptography is hardest to see.

Footnotes

  1. G7 Cyber Expert Group, “Advancing a Coordinated Roadmap for the Transition to Post-Quantum Cryptography in the Financial Sector”, January 2026. home.treasury.gov ↩ ↩2 ↩3

  2. Europol, “Call for action: urgent plan needed to transition to post-quantum cryptography together”, 7 February 2025. europol.europa.eu ↩

  3. Monetary Authority of Singapore, “MAS/TCRS/2024/01: Advisory on Addressing the Cybersecurity Risks Associated with Quantum”, 20 February 2024. mas.gov.sg ↩ ↩2

  4. Monetary Authority of Singapore, “Remarks by Mr Chia Der Jiun, Managing Director, MAS, at the MAS Annual Report 2025/2026 Media Conference”, paragraphs 57 and 58, 28 July 2026. mas.gov.sg ↩

  5. Hong Kong Monetary Authority, press release on the banking sector Quantum Preparedness Index, 27 July 2026. info.gov.hk ↩

  6. Office of the Superintendent of Financial Institutions, “Quantum Readiness Phases and Timelines”, technology risk bulletin, March 2026. osfi-bsif.gc.ca ↩

  7. Office of the Superintendent of Financial Institutions, “Technology risk bulletins”, consulted 7 October 2026. osfi-bsif.gc.ca ↩

  8. Saudi Central Bank, “Circular 482021280: Enhancement of Operational Resilience to Address Quantum Computing Risks”, 27 August 2026. rulebook.sama.gov.sa ↩

  9. FINMA, “FINMA Guidance 05/2026: Quantum computing”, 9 July 2026. finma.ch ↩ ↩2

Knowledge Hub content is general information. It is not legal advice, a compliance certification, a guarantee of security or a substitute for an assessment of your own systems. Standards and rules change; check the sources for the latest position.