HKMA Gives Hong Kong Banks a 2.3 Out of 10 on Quantum Readiness, Targets Full Migration by 2030
Table of Contents
27 July 2026, Hong Kong — The Hong Kong Monetary Authority has published the most granular regulator-led assessment of banking-sector post-quantum cryptography readiness to date. Its 56-page whitepaper, launched alongside the first Quantum Preparedness Index (QPI) at the eighth edition of its FiNETech conference series, reports an aggregate PQC readiness score of 2.3 out of 10 among responding Authorized Institutions (AIs). The HKMA invited all AIs operating in Hong Kong to participate in the underlying survey; the whitepaper does not disclose the number of respondents or the response rate, and notes that percentages represent the proportion of respondents rather than the entire banking sector.
The bottom line: Hong Kong’s banks know they have a problem. Most of them have not started fixing it.
The QPI measures readiness across four dimensions, each broken into scored sub-indices covering governance, funding, training, risk assessment, cryptographic inventory, testing, and migration readiness. Awareness scored 2.4/10, Planning 2.5/10, Pilots 1.8/10, and Practical Preparedness 2.3/10. The HKMA’s target is a score of 10 by 2030, a goal Carmen Chu, Executive Director (Banking Supervision), announced at FiNETech8 to an audience of over 300 finance and technology practitioners.
The survey, conducted in early 2026, found that 68% of respondents possess at least basic awareness of quantum computing, and half have discussed it at board level. But awareness has not translated into action. 68% of respondents reported no quantum-related initiatives in place. 71% have never conducted or planned any proof-of-concept or live testing of post-quantum cryptography algorithms or cryptographic agility solutions. 45% have no formal cryptographic bill of materials (CBOM). 66% have not assessed their quantum-related exposure. 64% have provided no workforce training on quantum threats or PQC.
The Pilots dimension, at 1.8/10, is the weakest score in the entire index. Among the 29% of respondents that reported some testing activity (conducted or planned), only 39% of that group described completed proof-of-concept exercises. The rest were at various stages of planning or execution. The report describes five completed pilots in detail: PQC applied to websites, APIs, and legal document signatures; cloud key management readiness; a content delivery network integration; distributed ledger connectivity; and cryptographic inventory tooling deployment.
Barriers: Vendors Dominate the Obstacle List
The whitepaper’s most operationally significant finding is in the barrier analysis. Respondents were asked to rank their top three obstacles across four domains: risk assessment, cryptographic inventory, roadmap development, and vendor engagement.
Vendor and third-party dependencies dominated. 87% of respondents ranked dependencies on critical third parties as a top-three barrier to industry engagement, and 85% cited the absence of clear PQC roadmaps from technology providers. For cryptographic inventory, 79% pointed to technical complexity across legacy IT environments, and 71% cited the sheer scale of applications and systems. For risk assessment, 73% identified the lack of established frameworks and methodologies.
These findings reinforce a point that practitioners know from experience: banks cannot migrate in isolation. Core banking platforms, payment processors, hardware security modules, certificate authorities, and financial market infrastructures sit outside any single institution’s control. Without coordinated vendor roadmaps, individual bank plans stall at the third-party boundary.
HKMA Support Measures
The HKMA announced three support initiatives. First, a PQC toolkit to be co-developed with the Hong Kong University of Science and Technology (HKUST), intended to help banks identify transition priorities and provide reference architecture for cryptographic agility. Second, training and workshops on quantum risk, cryptographic inventory development, and migration planning. Third, industry collaboration forums through FiNETech events and other platforms to support coordination between banks, vendors, and FMIs.
The whitepaper positions PQC readiness as an extension of existing supervisory frameworks, specifically the HKMA’s Supervisory Policy Manual (TM-G-1) for technology risk management, the Cyber Resilience Assessment Framework (C-RAF), and operational resilience guidance under OR-2. Banks are encouraged to embed quantum risk into these standing processes rather than building separate governance structures.
International Context
The HKMA report includes a useful compilation of government PQC migration programmes across nine jurisdictions (ten entries, with India appearing for both critical infrastructure and enterprises), distinguishing mandatory requirements from guidance and stated targets. The June 2026 US executive order directs federal agencies to migrate high-value assets and high-impact systems to PQC for key establishment by December 31, 2030 and for digital signatures by December 31, 2031. The UK’s NCSC targets planning and discovery completion by 2028, early and highest-priority migration by 2031, and full migration by 2035. The EU’s coordinated roadmap calls for high-risk systems to be migrated by 2030 and as many systems as possible by 2035. Singapore’s charted requirement is a transition plan for critical information infrastructure operators by March 31, 2027. Australia’s ASD recommends organizations complete PQC transition by the end of 2030.
The report correctly notes that these timelines are subject to revision as quantum hardware advances. It references Google’s March 2026 announcement of 2029 as its internal PQC migration deadline.
My Analysis
The Data Is the Story
Most regulatory publications on quantum risk follow a predictable formula: explain what quantum computing is, describe Shor’s algorithm, invoke the Harvest Now, Decrypt Later threat, and recommend that organizations start planning. The HKMA report does all of this. What makes it different is Section 3: an unusually detailed 18-page survey analysis with quantified results from an entire jurisdiction’s respondent population.
Few financial regulators have published comparable sector-wide data. FINMA in Switzerland released survey findings from 60 Swiss institutions earlier in July 2026, reporting that 72% had not planned or implemented quantum-safe measures and only 8% had a specific roadmap. The Monetary Authority of Singapore issued a three-page advisory in February 2024 telling banks to start preparing, and followed up with a QKD sandbox and a cross-border PQC experiment with the Banque de France. The ECB raised PQC through the Euro Cyber Resilience Board. The Bank for International Settlements published a roadmap in mid-2025. The G7 Cyber Expert Group issued a non-binding financial-sector PQC coordination statement in January 2026. What distinguishes the HKMA publication from all of these is its granularity: a four-dimensional readiness index with 12 scored sub-indices, detailed barrier rankings, and descriptions of five completed pilots.
A sector-wide PQC readiness score of 2.3/10 is a number that boards and risk committees can understand without a briefing deck. The sub-index breakdowns are even more instructive. Risk & Vulnerability Management scores 1.9/10. Monitoring scores 1.9/10. Cryptography Migration Testing scores 1.8/10. Training & Education scores 1.9/10. Funding scores 2.0/10. Most sub-indices that involve spending money or doing technical work score below the already-low overall average (the exceptions are Cryptographic Discovery & Inventory at 2.7 and PQC Controls & Assurance at 2.5). The relatively higher score for Policies & Procedures (3.0/10) suggests that respondents have written some things down. They have not done much with what they wrote.
The FINMA data points in the same direction. I expect regulators in Singapore, the EU, or the UK would find similar results if they ran the same survey. Hong Kong’s banks are not uniquely unprepared. Their regulator has been unusually transparent about the problem, because it asked the questions and published the answers. FINMA has now done the same. Others should follow.
The 2030 Target Deserves Scrutiny
The HKMA has set a target of QPI 10/10 by 2030. The urgency signal is exactly right, but the operational path from here to there is not specified.
Moving from 2.3 to 10 in roughly four years means that the respondent population needs to go from “we have basic awareness and some policies on paper” to full sectoral readiness. The survey data says 71% have never tested PQC. 45% have no formal CBOM. 66% have not assessed their exposure. Half have no formal remediation strategy. Roughly two-thirds have no dedicated staff or tools for PQC migration. And here is the number that makes the timeline hardest to defend: in her FiNETech8 speech, Carmen Chu herself noted that banks with existing transition plans estimate an average implementation timeframe of 5.6 years. That figure alone exceeds the time remaining before 2030.
The international timelines the HKMA itself cites tell a similar story. The UK NCSC, which has done some of the most detailed migration planning of any national authority, sets three milestones spread across seven years: planning and discovery complete by 2028, highest-priority migration by 2031, full migration by 2035. The US executive order sets 2030 for key establishment and 2031 for signatures, applying to federal high-value assets and high-impact systems with centralized governance that commercial banks do not have. The EU targets 2035 for full completion.
The 2030 target is deliberately aggressive, and the urgency it signals is welcome. But it is operationally under-specified. Without a reproducible scoring methodology and dated intermediate milestones, institutions cannot readily translate a sector-level aspiration into programme plans, budgets, and vendor commitments. A more operationally honest approach would set intermediate targets: governance, material inventory coverage, exposure assessment, initial pilots, and critical-vendor roadmaps by 2028; high-priority migrations, tested crypto-agility, operational monitoring, and contractual vendor commitments by 2030; residual-estate completion and sustained BAU integration by 2033 to 2035. The HKMA may intend this kind of graduated approach and simply chose to publicize the end-state target for maximum urgency. If so, the messaging will need to evolve. A target that practitioners cannot build a programme plan against risks being treated as aspirational rather than operational.
What the Report Misses
Three gaps weaken the whitepaper’s analytical value.
The signature-forgery threat is acknowledged but not treated as a distinct risk track. The report covers HNDL thoroughly, explaining how adversaries harvest encrypted data today for future decryption. Page 14 explicitly recognizes that a CRQC able to forge digital signatures could push malicious code updates, gain access to critical systems, and impersonate trusted entities. But the report gives this a single paragraph and does not use it to structure prioritization, trust-infrastructure migration, or signature-lifetime analysis. For a banking-sector publication, this gap matters. A CRQC that can break elliptic curve cryptography can forge transaction authorizations the day the capability arrives, with no advance warning and no takebacks. The forgery threat has a different urgency profile than the harvest threat and deserves treatment as a co-equal risk track. I first described this signature-side risk in 2018 as “Sign Today, Forge Tomorrow“; the industry now more commonly calls it Trust Now, Forge Later (TNFL). A whitepaper that frames quantum risk for banking without giving CISOs a distinct framework for the forgery threat leaves their prioritization incomplete.
The body of the report never names the NIST-standardized algorithms. ML-KEM (formerly CRYSTALS-Kyber), ML-DSA (formerly CRYSTALS-Dilithium), and SLH-DSA (formerly SPHINCS+) appear in the abbreviations appendix on page 54, but the main text refers only to generic “PQC algorithms” and mathematical families (lattice-based, hash-based, code-based). FN-DSA, the Falcon-derived signature standard under development at NIST for FIPS 206, is absent entirely. Nearly two years after NIST finalized FIPS 203, 204, and 205, a banking migration paper should connect its recommendations to the actual standards institutions are expected to evaluate and deploy. Banks need to know which algorithms to test and procure. Telling them “adopt PQC” without naming the standards is like telling them “use modern encryption” without specifying AES.
China’s sovereign PQC standardization program is barely mentioned. Hong Kong banks operate at the junction of international and Chinese financial systems. China’s Institute of Commercial Cryptography Standards (ICCS) launched a programme for next-generation cryptographic algorithms in February 2025 and released performance self-assessment guidelines in June 2026. China’s resulting standards may differ from NIST selections, potentially creating future procurement, protocol, and interoperability complexity for Hong Kong institutions operating across both ecosystems. The whitepaper gives this a single factual paragraph on page 20 without analyzing the implications for Hong Kong’s unique position. For a jurisdiction whose banking sector straddles two cryptographic ecosystems, this deserved more attention.
The QKD Section Is Overweighted
Section 2.2.3 devotes a full page to quantum key distribution, cataloging deployments in Hong Kong, China, Japan, Spain, and the UK before noting that the NSA does not recommend QKD for national security systems. The weighting is difficult to justify for a banking audience. PQC is the immediately deployable migration path identified by the BIS, and the NCSC, NSA, and Australia’s ASD all give PQC clear practical priority over QKD, citing cost, authentication dependencies, and assurance limitations. The HKMA whitepaper acknowledges several of those limitations, but only after devoting extensive space to deployments and potential applications. Stating the hierarchy clearly in one paragraph would have served readers better than building a case for QKD’s potential before walking it back.
The Introductory Quantum Computing Section Weakens the Report
The seven-page introductory section (Introduction to Quantum Computing, Quantum Use Cases for Financial Services, Current State of Quantum Computing) could appear in any quantum report written for any audience. The explanations of superposition and entanglement, the financial use case descriptions (portfolio optimization, fraud detection, sales optimization, risk management), and the vendor comparison table add little for the CISO or CTO who needs to act on this document. The report includes the necessary caveats that most applications remain at the exploratory or pilot stage, but the space devoted to small, vendor-associated experiments risks giving them more strategic weight than their maturity warrants. The Citi/Classiq portfolio optimization study explicitly claims no quantum advantage over classical methods. The HSBC/IBM algorithmic trading experiment used quantum data embedding to train a classical model. Cutting this section to two pages and expanding the barrier analysis, the migration approach, or the vendor coordination challenge would have produced a more useful document.
What the Report Gets Right, and What Others Should Copy
The vendor dependency finding is the most actionable insight in the entire whitepaper. The survey quantifies what practitioners have known anecdotally: banks are stuck at the third-party boundary. 87% of respondents ranked third-party dependencies as a top-three barrier. 85% cited the lack of vendor PQC roadmaps. The HKMA’s recommendation to embed quantum-readiness clauses in procurement contracts and to treat cryptographic transparency as a vendor selection criterion is concrete, practical, and immediately executable. Every financial regulator should be saying this. Few are.
The regulatory timeline compilation (Figure 5) is one of the best single-page summaries of global PQC migration programmes I have seen. It maps nine jurisdictions with milestone types (plan in place, high-priority migrated, full migration, commence transition) clearly differentiated by status (mandatory, guidance, stated target). I’ve been maintaining a similar global PQC migration timeline on PostQuantum.com, and the HKMA’s visualization adds useful clarity on which milestones are binding and which are aspirational. For organizations operating across multiple jurisdictions, this chart answers the question “which deadline do I plan against?” The answer, as the report itself recommends: the most demanding applicable timeline, interpreted against the systems and milestones actually in scope.
The four-stage framework (Awareness, Planning, Pilot, Practical Preparedness) aligns with the broader consensus in migration frameworks, including the Applied Quantum PQC Migration Framework, the BIS roadmap, the UK NCSC’s phased approach, and the PQC Coalition’s migration roadmap. The HKMA adds value by scoring each stage with sub-indices, creating a measurable baseline that can be tracked over time. If the HKMA publishes updated QPI scores annually, the trajectory will tell a more honest story than any single snapshot.
Deadlines, Not Predictions
This report is the latest in a rapid-fire sequence of financial-sector quantum actions in 2026. The G7 Cyber Expert Group published a financial-sector PQC coordination statement in January. The US executive order set binding migration deadlines for federal systems in June. FINMA published sector-wide readiness data and a mid-2027 roadmap expectation in July. And now the HKMA has quantified the readiness gap in Hong Kong.
The pattern confirms the thesis I have been advancing on PostQuantum.com for the past two years: the debate over when Q-Day arrives is being overtaken by ecosystem-driven deadlines. Regulators, standards bodies, insurers, and procurement frameworks are setting their own clocks. The HKMA’s 2030 target, ambitious as it is, joins a growing list of deadlines and targets that organizations must plan against regardless of their view on CRQC timelines.
The practical implication for any financial institution operating in or connected to Hong Kong: the HKMA has published the score and set the clock. The four immediate actions the whitepaper recommends (engage the board, appoint an accountable owner, commission a cryptographic inventory, engage critical vendors) can generally begin without significant expenditure and do not require waiting for every implementation question to be settled. They require a decision to start. The survey data suggests that for a majority of respondents, substantive execution has not yet begun.
The question now is whether the HKMA’s transparency about the problem will accelerate the solution, or whether a 2.3/10 score will be treated as someone else’s problem until the next survey lands.