HKMA Quantum Preparedness Index: Hong Kong's Banks Scored 2.3 and Pointed at Their Vendors
Hong Kong's banking sector scored 2.3 out of 10 on the HKMA's first Quantum Preparedness Index, with 87% naming third-party dependencies as a top barrier.
The Bright Recap
The Hong Kong Monetary Authority published its first Quantum Preparedness Index on 27 July 2026, scoring the banking sector 2.3 out of 10 on readiness to migrate to post-quantum cryptography. The Index rates four dimensions: Awareness 2.4, Planning 2.5, Pilots 1.8, Practical Preparedness 2.3. The target is a score of 10 by 2030.
Across the four challenge areas surveyed, banks ranked dependencies on critical third parties highest at 87 per cent and vendor readiness second at 85 per cent, above legacy systems at 71 per cent. Seventy-one per cent had neither run nor planned any post-quantum test, and 60 per cent had no process for assessing whether their vendors were ready.
To know more about this topic, read our related articles:
Bright Answers
What is the HKMA Quantum Preparedness Index?
It is a benchmark published by the Hong Kong Monetary Authority on 27 July 2026 that scores the readiness of Hong Kong's banking sector to migrate to post-quantum cryptography. It rates four dimensions, Awareness, Planning, Pilots and Practical Preparedness, on a scale of 0 to 10, based on a survey of authorized institutions conducted in early 2026.
Why did Hong Kong's banks score only 2.3 out of 10?
Because most institutions have not moved past awareness into testing. Seventy-one per cent had neither conducted nor planned any proof-of-concept or live test of post-quantum cryptography, and nearly three quarters had not validated their migration plans or fallback arrangements. Banks attribute much of the delay to third parties, ranking dependencies on critical providers as their single biggest obstacle at 87 per cent.
The Hong Kong Monetary Authority (HKMA) has put a number on something supervisors normally describe with adjectives. Its first Quantum Preparedness Index, published on 27 July, scores the territory's banking sector 2.3 out of 10 on its readiness to replace the cryptography its business runs on.
Underneath that score sits a survey the HKMA invited every authorized institution in Hong Kong to join, and the two obstacles those institutions ranked highest both sit outside their own perimeter.
What the index counts
The Index rates four dimensions on a ten-point scale. Awareness, which measures governance arrangements, funding and staff training rather than mere familiarity with the threat, scored 2.4. Planning scored 2.5, Practical Preparedness 2.3, and Pilots came last at 1.8. Retail banks outscored non-retail institutions on every dimension, reaching 3.0 on Practical Preparedness against 2.1.
The measurement was announced in February as one of four flagship projects in a blueprint designed to push banks deeper into advanced financial technology rather than wider across it. Five months later, the baseline arrived with a target attached.
The pilot score is the one that moves
Pilots measures a single thing: whether an institution has run or scheduled any proof-of-concept or live test of post-quantum cryptography (PQC) or cryptographic agility. Seventy-one per cent had done neither. Nearly three quarters had not validated their migration plans, their fallback arrangements, or how their systems would behave if a cryptographic component failed.
That is where the gap between the dimensions becomes legible. The full white paper treats pilot activity as the stage where assumptions meet hardware, and it is the stage almost nobody has entered.
The barriers that outrank everything internal
Banks were asked to rank the challenges constraining them across four areas. Legacy systems and accumulated technical debt reached the top three for 71 per cent, and the difficulty of finding and mapping cryptographic assets across sprawling estates reached it for 79 per cent. Both were outranked by dependencies on critical third parties at 87 per cent and by vendor readiness at 85 per cent, the two highest figures recorded across all four challenge areas.
Sixty per cent of respondents had no process for assessing whether their vendors were quantum-ready, and 28 per cent could not see what cryptography their third parties were using at all. That dependency runs through hardware security modules, cloud key management, certificate providers, payment infrastructure and the shared utilities banks connect to.
An institution can finish every task on its own list and still be unable to switch algorithms, because concentration in shared infrastructure sets the pace for everyone attached to it.
Why 87 per cent asked for a date
Banks were also asked what external support would help them most. Clear supervisory expectations and timelines topped that list at 87 per cent, ahead of practical guidance at 77 per cent and industry forums at 48 per cent. A published deadline outranked both tools and technique.
The HKMA set that target at 2030 for full sectoral readiness, defined as a score of 10. A date is the one instrument that moves a bank, its suppliers and its counterparties on the same clock, which is why institutions that cannot compel their vendors asked a regulator to do it for them.
What a scored deadline does for a customer
The cryptography under discussion protects customer authentication, payment instructions and stored records. The report's nearest-term concern is Harvest Now, Decrypt Later, where encrypted material is intercepted and stored today against the arrival of a machine capable of reading it.
Experts surveyed for the report put the likelihood of such a machine appearing within ten years of 2025 at between 28 and 49 per cent, rising to between 51 and 70 per cent within fifteen years. Records that must stay confidential across that span are the ones the report says should move first.
Publishing a score with a date attached turns an acknowledged risk into a measured one. A board that was briefed on quantum risk now sits at a specific point on a public scale, and it will sit somewhere else when the next reading is taken. The same cryptography secures Hong Kong's tokenised green bonds and the tokenised deposit trials running under Project Ensemble, both set out in the February fintech blueprint, where distributed ledger adoption among surveyed banks rose from 30 per cent in 2022 to 45 per cent in 2025.
What the date cannot reach
The HKMA's answer is not a supervisory one: a post-quantum toolkit co-developed with the Hong Kong University of Science and Technology's School of Business and Management, a workshop programme, and forums that put banks, technology vendors and financial market infrastructures in the same room. Its scoring reaches its own licensees.
The report groups secure payment networks together with blockchain and distributed ledger applications, on the grounds that both rely on cryptography for their core functions and both would face severe operational disruption if those protections were compromised. One institution has already completed a proof-of-concept testing whether post-quantum protections could be introduced across distributed ledger connectivity without materially affecting network performance. That test told the bank something about its own systems.
The Index scores banks one at a time, and the obstacle they ranked above every other challenge is one that no single bank owns.
Editor's note
Every piece published on The Bright Minded goes through careful verification, but mistakes can happen. If you spot an error, have additional information, or want to flag anything, write to rosalia@thebrightminded.com.