UK And Switzerland: Guidance-Led Quantum Timelines And Operational Resilience
Neither the UK nor Switzerland has a binding post-quantum rule as of October 2026. The UK relies on NCSC dates; FINMA recommends a roadmap by mid-2027. Here is what each expects.
Checked against primary sources and independently reviewed on . Sources are listed at the end.
The United Kingdom and Switzerland both sit outside the EU and both have strong financial centres, so firms often ask whether they face anything like DORA’s cryptography rules. As of October 2026 the short answer is no. Neither country has a binding post-quantum requirement, and both operational resilience regimes are silent on cryptography.
What they do have are clear signals. The UK’s National Cyber Security Centre (NCSC) has published migration dates that serve as the main planning reference for UK organisations, and the Swiss Financial Market Supervisory Authority (FINMA) has set one of the most specific financial supervisor dates in Europe: a post-quantum roadmap by mid-2027. This article explains both, labels each item by its legal force, and is general information rather than legal advice.
Where Each Country Sits
| Item | United Kingdom | Switzerland |
|---|---|---|
| Post-quantum dates | NCSC: discovery and plan by 2028, priority migration by 2031, complete by 2035 (Guidance) | FINMA: roadmap by mid-2027 (Supervisory recommendation) |
| Financial operational resilience | FCA SYSC 15A and PRA SS1/21, no cryptography content (Binding and Supervisory) | FINMA Circular 2023/1, no cryptography content (Supervisory) |
| Where encryption does appear | PRA SS2/21 on outsourcing: encryption and key management (Supervisory) | FINMA Guidance 05/2026: inventory, outsourcing contracts, crypto agility (Supervisory) |
| Cyber law in progress | Cyber Security and Resilience Bill (Draft) | Cyberattack reporting for critical infrastructure since 1 April 2025 (Binding) |
| AI approach | Principles-based, no cross-sector AI law | Sectoral work and plans to ratify the Council of Europe AI Convention |
United Kingdom: NCSC Dates As The Baseline
The NCSC’s timelines for post-quantum migration, published on 20 March 2025, set three milestones. By 2028, organisations should complete discovery and build an initial migration plan. By 2031, they should finish their highest-priority migration activities. By 2035, migration should be complete.1 Status: Guidance. Nothing in UK law requires these dates.
The NCSC is also helping buyers find support. Its Assured Cyber Security Consultancy scheme runs a post-quantum pilot covering discovery, migration planning and advice, scheduled to run until 31 March 2027.2 Status: Announcement.
United Kingdom: Financial Rules Say Little About Cryptography
The FCA’s operational resilience rules in SYSC 15A came into force on 31 March 2022, and the transition period ended on 31 March 2025. They require firms to identify important business services and stay within impact tolerances, but they contain no cryptography requirement.3 Status: Binding. The PRA’s matching supervisory statement, SS1/21, does not mention cryptography, encryption or quantum.4 Status: Supervisory.
Encryption does appear in the PRA’s outsourcing and third-party risk statement, SS2/21. Paragraphs 7.11 and 7.12 list encryption and key management among data security controls, expect keys to be kept secure, and expect encrypted data to remain accessible to the PRA. A further update, published with PS7/26, takes effect on 18 March 2027.5 Status: Supervisory. The critical third parties regime, in force since 1 January 2025, sets resilience duties for designated providers but has no specific cryptography rule.6 Status: Binding once a provider is designated.
The Bank of England has said where it is heading. In October 2025 it said it was testing a supervisory briefing on quantum risks and compared the scale of the migration effort to the LIBOR transition.7 Status: Announcement.
Parliament is working on broader cyber law. The Cyber Security and Resilience (Network and Information Systems) Bill was introduced on 12 November 2025 and carried over into the new session, with Lords Report stage scheduled for 26 October 2026.8 Status: Draft. It is not law as of October 2026.
Switzerland: FINMA Puts A Date On It
FINMA’s operational resilience circular for banks, Circular 2023/1, has applied since 1 January 2024. Its sections on ICT risk, cyber risk and critical data do not use the words cryptography or encryption.9 Status: Supervisory.
The change came with FINMA Guidance 05/2026 on 9 July 2026. FINMA surveyed 60 institutions and found that only 8 percent had a specific post-quantum roadmap, 43 percent had not yet decided whether to draw one up, and 72 percent had not planned or started any quantum-safe measures. It recommends a board-approved strategy with target dates, a roadmap by mid-2027 at the latest, an inventory that puts data exposed to harvest now, decrypt later attacks first, quantum measures that can be set out in outsourcing contracts, and crypto agility as a prerequisite for new software and data outsourcing.10 Status: Supervisory (a recommendation, not a rule).
Outside finance, Switzerland’s Information Security Act and Cybersecurity Ordinance have required critical infrastructure operators to report cyberattacks to the Federal Office for Cyber Security within 24 hours since 1 April 2025.11 Status: Binding. No Swiss national post-quantum guidance from that office was found as of October 2026.
- Upcoming
Switzerland · FINMA Supervisory
Draw up a post-quantum cryptography roadmap.
- Upcoming
United Kingdom · National Cyber Security Centre Guidance
Complete discovery and build an initial migration plan.
- Upcoming
United Kingdom · National Cyber Security Centre Guidance
Complete early, highest-priority migration activities and refine the plan into a roadmap for completing migration by 2035.
- Upcoming
United Kingdom · National Cyber Security Centre Guidance
Complete migration to post-quantum cryptography across systems and products.
A Brief Word On AI
Both countries have chosen not to pass a single horizontal AI law so far. The UK remains principles-based and the government has not introduced an AI bill. On 4 June 2026 a Lords Grand Committee debate, led by Lord Holmes of Richmond, considered the case for a cross-sector AI regulation bill; his own private members’ bill has had only a first reading.12 Switzerland’s Federal Council decided in February 2025 to ratify the Council of Europe AI Convention and make the legal changes ratification requires while continuing sector-by-sector work, and plans a consultation draft by the end of 2026, which had not been published as of October 2026.13 Status for both countries: Guidance and strategy, with no binding cross-sector AI law. For more, see AI Regulation At A Glance and AI Governance And Regulation.
For how these dates compare with the EU, US and Asia, see the global overview and Cryptography Compliance.
Footnotes
-
National Cyber Security Centre, “Timelines for migration to post-quantum cryptography”, 20 March 2025. ncsc.gov.uk ↩
-
National Cyber Security Centre, “Assured Cyber Security Consultancy: PQC pilot”. ncsc.gov.uk ↩
-
Financial Conduct Authority, PS21/3 “Building operational resilience”, March 2021. fca.org.uk ↩
-
Bank of England, Prudential Regulation Authority, SS1/21 “Operational resilience: Impact tolerances for important business services”, March 2021. bankofengland.co.uk ↩
-
Bank of England, Prudential Regulation Authority, SS2/21 “Outsourcing and third party risk management”. bankofengland.co.uk ↩
-
Bank of England, “Operational resilience: Critical third parties to the UK financial sector” policy statement, November 2024. bankofengland.co.uk ↩
-
Bank of England, “The Bank of England’s approach to innovation in artificial intelligence, distributed ledger technology, and quantum computing”, 15 October 2025. bankofengland.co.uk ↩
-
UK Parliament, Cyber Security and Resilience (Network and Information Systems) Bill, bill 4035. bills.parliament.uk ↩
-
FINMA, Circular 2023/1 “Operational risks and resilience: banks”, 7 December 2022. finma.ch ↩
-
Federal Office for Cyber Security (BACS), “Gesetzliche Grundlagen zur Meldepflicht”. bacs.admin.ch ↩
-
UK Parliament, Hansard, House of Lords Grand Committee, “AI Regulation Bill” (question for short debate), 4 June 2026. hansard.parliament.uk ↩
-
Swiss Federal Council, press release on the regulation of artificial intelligence, 12 February 2025. admin.ch; Federal Office of Justice, “Künstliche Intelligenz”, accessed October 2026. bj.admin.ch ↩
Knowledge Hub content is general information. It is not legal advice, a compliance certification, a guarantee of security or a substitute for an assessment of your own systems. Standards and rules change; check the sources for the latest position.