
Hong Kong’s banking industry received a Quantum Preparedness Index score of 2.3 out of 10 on July 27, showing that lenders remain at an early stage of preparing for quantum-related cyber risks.
Summary
- Hong Kong banks scored 2.3 out of 10 on the HKMA’s inaugural preparedness index.
- 32% of surveyed banks had not started preparing for post-quantum cryptography risks or migration efforts.
- HKMA targets full sector readiness by 2030 through a toolkit, workshops and coordinated industry guidance.
The Hong Kong Monetary Authority published the benchmark alongside its first whitepaper on quantum preparedness at the eighth FiNETech conference. The index uses four categories: awareness, planning, pilot programmes and practical preparedness. The regulator said banks were largely focused on building basic knowledge and governance rather than deploying quantum-resistant systems.
Hong Kong banks remain early in quantum readiness
The HKMA’s early-2026 survey found that 68% of responding banks had developed some awareness or moved into planning or pilot stages. The remaining 32% had not started their transition journey. Around half lacked a formal plan for adopting post-quantum cryptography.
Notably, Governance activity was more advanced than technical implementation. Around half of surveyed banks had discussed quantum computing at board level, while roughly one-third had started exploring or testing related initiatives. The HKMA did not disclose the names or individual scores of participating banks in its public announcement.
The 2.3 score does not mean that Hong Kong banks have suffered quantum attacks or that current banking encryption has already failed. It measures how prepared the sector is to identify vulnerable systems, create transition plans, test replacements and move them into practical use.
Quantum risks already affect long-term banking data
A sufficiently powerful quantum computer could eventually break widely used public-key encryption that protects financial transactions, communications and stored information. The timing remains uncertain, but financial institutions may need years to identify old cryptography and replace it across payment systems, customer platforms and third-party services.
The more immediate concern is known as “harvest now, decrypt later.” Attackers can collect encrypted information today and retain it until future quantum hardware can decrypt it. The Bank for International Settlements therefore treats quantum migration as a current data-protection issue, particularly when financial information must remain confidential for many years.
The BIS has already completed two phases of Project Leap. The first tested hybrid post-quantum encryption between central banks, while the second applied quantum-resistant digital signatures to liquidity transfers in an operational payment environment. The experiments found that quantum-safe payment systems were technically feasible, although further performance testing was needed.
Blockchain networks face a related challenge because Bitcoin and other digital assets also rely on cryptographic signatures. Researchers warned that Bitcoin’s quantum migration could require years of planning, even though no existing machine can currently break its cryptography.
HKMA aims for full preparedness by 2030
The HKMA wants the banking sector to reach a QPI score of 10 by 2030. This is a sectoral objective rather than a published legal deadline for every lender. The regulator has not announced penalties for institutions that fail to reach a particular score.
Its first support measure will be a post-quantum cryptography toolkit developed with the Hong Kong University of Science and Technology’s business school and industry participants. The toolkit is intended to help banks identify transition priorities and improve cryptographic agility, meaning their ability to replace vulnerable algorithms without rebuilding entire systems.
The HKMA will also run workshops covering transition planning, technical capabilities and responsible uses of quantum technology. Future QPI readings should show whether banks are moving from awareness and governance discussions into inventories, pilots and production deployment.
Moreover, Hong Kong’s timetable broadly follows international policy. NIST has finalised three post-quantum cryptography standards and says organisations should begin implementing them now. The standards cover encryption and digital signatures designed to resist attacks from both classical and quantum computers.
The U.S. also accelerated its transition in June. President Donald Trump signed an executive order directing federal systems towards NIST-approved post-quantum standards and requiring agencies to establish cryptographic inventories and prioritised migration plans. As crypto.news reported, the order accompanied a wider U.S. quantum computing initiative.
The next verified milestones will be the release of the HKMA toolkit, the start of industry workshops and later QPI assessments. The regulator has not yet published dates for those measures or indicated how frequently it will update the index.




Be the first to comment