MAS Targets Quantum Resilience for FIs by End of Decade
Table of Contents
July 28, 2026 — Singapore’s central bank announced it will issue formal supervisory expectations later this year to guide financial institutions’ migration toward quantum-resilient cryptography, with the stated aim of achieving quantum resilience across the financial sector before the end of this decade.
MAS Managing Director Chia Der Jiun made the announcement at the MAS Annual Report FY2025/2026 media conference, outlining three sequential elements of the migration with progressive timelines. Financial institutions will be expected to establish an inventory of their cryptographic assets, develop a prioritized migration plan for vulnerable systems, and build the technical capabilities and governance frameworks to execute a quantum-safe transition. (The full speech covers quantum in paragraphs 55 through 58.)
“Our aim is for FIs to achieve quantum resilience before the end of this decade,” Chia said, framing the quantum migration alongside a parallel push to strengthen defenses against AI-enabled cyber threats.
MAS has not yet published the actual expectations document or assigned the milestones a formal legal status, but the announcement is the clearest step yet toward time-bound supervisory expectations for post-quantum cryptography (PQC) migration in the financial sector. In Singapore’s regulatory context, supervisory expectations carry de facto mandatory weight. MAS is now among a small group of regulators globally moving from guidance to formal expectations with milestones and deadlines.
The Three Phases
MAS’s supervisory expectations, expected later in 2026, will set progressive milestones across three areas.
First, financial institutions must complete a cryptographic asset inventory, cataloging where and how cryptography is used across their operations, from payment systems and customer databases to internal communications and cloud services. Every PQC migration framework identifies this as the necessary starting point, including my own Applied Quantum PQC Migration Framework, and it is the phase where most organizations discover they are further behind than they assumed.
Second, institutions must prioritize vulnerable assets for migration to quantum-resilient solutions. This is where they need to make judgments about which systems carry the greatest exposure, accounting for data sensitivity, asset lifespan, and the Harvest Now, Decrypt Later (HNDL) threat that makes data intercepted today vulnerable to future quantum decryption.
Third, institutions must build the technical capabilities and governance frameworks to execute the migration itself: the engineering, testing, vendor coordination, and organizational structures that turn an inventory and a priority list into actually deployed quantum-safe cryptography.
How MAS Got Here
This announcement follows a deliberate progression by MAS over the past two and a half years.
In February 2024, MAS issued Circular No. MAS/TCRS/2024/01, an advisory to the CEOs of all financial institutions on addressing the cybersecurity risks associated with quantum computing. That document recommended maintaining cryptographic inventories, identifying priority assets for migration, building crypto-agility, and engaging third-party vendors on quantum-safe solutions. It was guidance, not mandate.
In August 2024, MAS signed a Memorandum of Understanding with DBS, HSBC, OCBC, UOB, SPTel, and SpeQtral to launch a Quantum Key Distribution (QKD) sandbox for financial services. The sandbox tested whether QKD could be integrated into real-world financial-sector IT environments for securing sensitive communications. The technical report was published in September 2025.
MAS also completed a cross-border PQC trial with the Banque de France in November 2024, testing CRYSTALS-Dilithium and CRYSTALS-Kyber for email signing and encryption over conventional internet infrastructure between Paris and Singapore.
The move from an advisory circular in 2024 to supervisory expectations with milestones and timelines in 2026 follows the pattern I have been tracking across global PQC migration timelines: regulators start with guidance, observe the gap between awareness and action, and then convert guidance into formal expectations. FINMA’s survey of 60 Swiss financial institutions (conducted November 2025 through January 2026, published with its July 2026 guidance) found that 72% had no quantum-safe measures planned or underway despite two-thirds expecting to be directly affected within seven years. MAS has likely observed a similar gap.
Where MAS Fits in the Global Regulatory Picture
MAS’s end-of-decade quantum target aligns with a convergence of financial-sector deadlines that I have been documenting for the past year.
Consider the cluster of actions in the past eighteen months. The G7 Cyber Expert Group’s January 2026 roadmap oriented critical financial system migration to the 2030-2032 window. FINMA’s Guidance 05/2026 (published roughly three weeks before the MAS announcement) recommended PQC roadmaps by mid-2027. The ECB sent letters to bank CEOs on AI-enabled cyber threats in July 2026 and pre-announced a quantum-specific letter. Hong Kong’s HKMA announced a Quantum Preparedness Index in February 2026 and published its first results in July. The BIS quantum-readiness roadmap (July 2025) urged financial institutions to begin migration without delay, though it stopped short of setting a hard date. The Bank of Israel mandated quantum transition preparedness plans from banks by January 2026, following its January 2025 directive. The UAE’s National Encryption Policy made PQC transition plans mandatory for government entities in late 2025, one of the earliest mandatory national-level PQC requirements anywhere.
NIST’s draft IR 8547 proposes deprecating quantum-vulnerable public-key cryptography after 2030 and disallowing it after 2035. The UK NCSC set phased targets: discovery by 2028, high-priority migration by 2031, full transition by 2035. The EU’s coordinated roadmap requires high-risk systems migrated by 2030.
MAS’s “before the end of this decade” language places it squarely in the 2030 cluster alongside NIST deprecation, the EU high-risk timeline, and Australia’s ASD government-system deadline.
My Analysis
The MAS announcement is not a surprise. It is a confirmation, and in this case confirmation is the point.
Readers of this site know that I have been arguing for years that debating Q-Day arrival dates is almost irrelevant because regulators, insurers, investors, and clients are setting their own quantum clocks. MAS just added another clock, and it is a clock that matters disproportionately to its face value, for three reasons.
MAS Punches Above Its Regulatory Weight
Singapore’s financial sector manages S$6.7 trillion in assets under management (as of end-2025, per the same annual report) and is Asia’s leading FX hub with S$1.6 trillion in average daily traded volumes. Those numbers make MAS a regulator whose expectations propagate far beyond Singapore’s borders. Global banks operating in Singapore, wealth managers domiciled there, and payment networks routing through the city-state will all need to comply. Their compliance programs rarely stop at one jurisdiction’s border.
MAS has long been a reference regulator. When MAS moves on operational resilience, technology risk management, or fintech governance, other regulators across Asia study the approach and frequently adapt it. The February 2024 advisory preceded and anticipated similar guidance from the HKMA, Bank of Israel, and several ASEAN regulators. Supervisory expectations with milestones and a stated end-of-decade target will carry similar influence across the region.
For financial institutions operating across APAC, the practical effect is that the most demanding quantum migration timeline in the region now becomes the planning baseline, because a DBS or OCBC or HSBC that builds to MAS’s timeline will apply that program globally rather than maintaining parallel migration schedules per jurisdiction.
The Three-Phase Structure Is Telling
The three phases MAS outlined match the sequence that every serious PQC migration framework prescribes, including the Applied Quantum PQC Migration Framework and the G7 CEG roadmap. Inventory first, then prioritized migration planning, then execution. This is not accidental; it reflects an understanding that most financial institutions have not completed even the first phase.
FINMA’s survey data quantifies the gap: 72% of surveyed Swiss institutions had no measures planned or underway. My experience across Applied Quantum’s engagements confirms a similar picture globally. Most organizations that claim to be “monitoring” the quantum threat have not completed a cryptographic inventory. Many do not know which of their systems depend on RSA or ECC, which certificates expire when, or which third-party services embed quantum-vulnerable cryptography that the institution cannot independently upgrade.
By setting progressive timelines across these three phases rather than a single end-date, MAS is acknowledging that the inventory phase alone will be a multi-month effort for large financial institutions. That is the right approach. A regulator that demands “be quantum-safe by the end of the decade” without prescribing the intermediate steps creates a compliance target that institutions can defer until 2029 and then fail. MAS is requiring evidence of progress along the way.
MAS Treats Quantum and AI as a Single Governance Problem
MAS embedded its quantum announcement within a broader framework of responses to AI-enabled threats. In the same speech, Chia announced supervisory expectations for comprehensive assessments and action plans against AI-enabled cyber threats, a new requirement (effective July 1) for key FIs to conduct AI-assisted red teaming on critical internet-facing systems, and the formation of the ABS-ACT (AI-Driven Cyber and Tech Risk Taskforce) with major banks.
The speech’s section on AI-enabled cyber threats (paragraphs 48 through 54) argued that frontier AI models are compressing vulnerability discovery-to-exploit timelines “from weeks to days or even hours,” creating what Chia called a need for “an urgent step up in cyber-defence capabilities.” Quantum risk followed immediately (paragraphs 55 through 58), positioned as a medium-term threat requiring early preparation precisely because “transition to quantum-safe practices will take time.”
MAS is treating quantum migration not as a standalone theoretical exercise but as one component of a technology-risk governance mandate that also covers AI, operational resilience, scam defenses, and third-party risk management. Financial institutions that have been waiting for quantum to become a “real” regulatory topic will find it arriving bundled with AI governance obligations they cannot defer.
What This Means for Financial Institutions
If you are a financial institution regulated by MAS and you have not started a cryptographic inventory, you are behind. The supervisory expectations are coming later this year, and the timelines will work backward from an end-of-decade completion target.
For institutions already underway, the MAS announcement provides the executive-level validation that PQC migration programs need to secure sustained funding. Boards that have treated quantum risk as a “watch and wait” topic now have a regulatory timeline on the table. I covered the dynamics of how boards authorize PQC spending in Quantum Ready, and the pattern is consistent: boards fund obligations, not threats. MAS just provided the obligation.
For institutions outside Singapore, the signal is worth reading carefully. MAS does not operate in isolation. Every financial-sector quantum deadline I track moves in the same direction, and MAS’s end-of-decade target is consistent with where the regulatory consensus is converging.
The organizations that will meet these timelines are the ones starting their cryptographic inventories now, not the ones waiting for the supervisory expectations document to land. MAS has already outlined its core elements. The smart move is to act on the preview.