Breaking Data · Regulatory Intelligence
Hong Kong Banks Score 2.3/10 on Quantum Readiness. US Banks Are No Different, and the Clock Is Running.
August 4, 2026 · PQCClear Editorial · 9 minute read
Banks with existing transition plans estimate an average implementation timeframe of 5.6 years. That single figure, published last week by the Hong Kong Monetary Authority in the most detailed regulator-led PQC readiness assessment ever produced, exceeds the time remaining before the 2030 deadline on its own. If your institution has not started, you are already behind schedule for a deadline you cannot move.
The Score: 2.3 Out of 10
The HKMA invited all Authorized Institutions operating in Hong Kong to participate in the survey underlying the QPI. The aggregate PQC readiness score across all respondents: 2.3 out of 10.The HKMA’s target is 10 by 2030.
2.3
Aggregate PQC readiness score across all respondents
10
HKMA target score for the same institutions by 2030
5.6 yrs
Average implementation timeframe estimated by banks that already have a plan
The sub-dimensions tell a consistent story. Institutions have written some things down. They have not done much with what they wrote.
| Dimension | Score | What the score reflects |
|---|---|---|
| Awareness | 2.4 / 10 | The highest of the four headline dimensions, and still barely a quarter of the way to the 2030 target. |
| Planning | 2.5 / 10 | Some documentation exists, but execution has not followed it. |
| Pilots | 1.8 / 10 | The weakest dimension. Only 29% of respondents have conducted or planned any proof-of-concept testing. |
| Practical preparedness | 2.3 / 10 | The overall aggregate: what institutions have actually done to protect themselves today. |
| Policies and procedures | 3.0 / 10 | The strongest sub-index, which is itself the finding. Writing a policy is the cheapest step available. |
| Risk and vulnerability mgmt | 1.9 / 10 | Quantum exposure is largely absent from existing risk registers. |
| Cryptography migration testing | 1.8 / 10 | Almost nothing has been validated in a live or test environment. |
| Training and education | 1.9 / 10 | The workforce that would run a migration has not been prepared to run one. |
| Funding | 2.0 / 10 | Budget has not been allocated, which is the constraint that gates every other dimension. |
The Numbers Behind the Score
The survey data translates the aggregate score into institution-level behaviour. The pattern is consistent, and it is not subtle.
68%
reported no quantum-related initiatives in place at all
71%
have never conducted or planned any testing of PQC algorithms
45%
have no cryptographic bill of materials, so no inventory of what they encrypt or with what
66%
have not assessed their quantum-related exposure at all
50%
have had no board-level discussion of quantum risk
64%
have provided no workforce training on quantum threats or PQC
The Finding That Matters Most: Vendors
The whitepaper asked respondents to rank their top three obstacles across four domains: risk assessment, cryptographic inventory, roadmap development, and vendor engagement. Vendor and third-party dependencies dominated every category.
Third-party dependencies named a top-three barrier to industry engagement
87%
Absence of clear PQC roadmaps from technology providers
85%
Technical complexity across legacy IT environments
79%
Lack of established frameworks and methodologies
73%
Scale of applications and systems requiring inventory
71%
Banks cannot migrate in isolation. Core banking platforms, payment processors, hardware security modules, certificate authorities, and financial market infrastructures all sit outside any single institution’s control. Without coordinated vendor roadmaps and a systematic way to assess vendor cryptographic posture, an otherwise sound migration plan stalls at the third-party boundary.
The HKMA’s own recommendation, to embed quantum-readiness clauses in procurement contracts and treat cryptographic transparency as a vendor selection criterion, is concrete, practical, and executable this quarter. It is also the precise workflow PQCClear automates.
This Is Not a Hong Kong Problem
It would be tempting to read 2.3/10 and conclude that Hong Kong’s banks have a particular problem. The evidence says otherwise. Their regulator has simply been unusually transparent, because it asked the questions and published the answers.
One month before the QPI, FINMA, Switzerland’s financial regulator, published Guidance 05/2026 on quantum computing, summarizing its own survey of 60 Swiss financial institutions conducted between November 2025 and January 2026.
72%
of Swiss institutions have not planned or implemented any quantum-safe encryption measures
8%
of Swiss institutions have a specific roadmap for quantum-safe encryption
68%
of Hong Kong respondents have no quantum-related initiatives at all
Two of the world’s most sophisticated, well-regulated financial centres, surveyed within months of each other, producing almost identical results. The pattern is not jurisdictional. It is universal.
Run the same survey on US community banks and credit unions, institutions that typically have smaller security teams, greater reliance on third-party vendors, and less dedicated quantum risk awareness than their Hong Kong and Swiss counterparts, and the numbers would almost certainly be worse. The FFIEC has not yet published equivalent sector-wide PQC readiness data. When it does, the US community banking sector should not expect to be the exception to an emerging global pattern.
A Global Regulatory Convergence
The HKMA report includes a compilation of government PQC migration programmes across nine jurisdictions. Read together, they describe a regulatory environment converging rapidly on the same requirements.
| Jurisdiction | Key milestone | Date |
|---|---|---|
| US · EO 14412 | PQC key establishment for federal high value assets and contractors | Dec 31, 2030 |
| US · FAR Council | Contractor PQC compliance rule published | Dec 19, 2026 |
| EU · coordinated roadmap | High-risk systems quantum-safe | Dec 31, 2030 |
| Singapore · MAS | Transition plan for critical infrastructure operators | Mar 31, 2027 |
| Australia · ASD | PQC transition complete | Dec 31, 2030 |
| UK · NCSC | Planning and discovery complete | 2028 |
| UK · NCSC | Highest-priority systems migrated | 2031 |
| Hong Kong · HKMA | QPI target: full readiness | 2030 |
| Switzerland · FINMA | Roadmap expectation for institutions | Mid-2027 |
As Marin Ivezic observed in his analysis of the report, the debate over when Q-Day arrives is being overtaken by ecosystem-driven deadlines. Regulators, standards bodies, insurers, and procurement frameworks are setting their own clocks. For any institution operating across multiple jurisdictions, the practical planning answer is to work against the most demanding applicable deadline, which for most banks with federal contracts or connections to federal payment systems is December 31, 2030.
What the Report Gets Definitively Right
The HKMA’s most actionable recommendation is also its most important: embed quantum-readiness clauses in procurement contracts, and treat cryptographic transparency as a vendor selection criterion.
This is not a novel idea. DORA Article 28 creates exactly this obligation for EU financial entities. The FFIEC third-party risk framework creates the same obligation through the lens of information security. The executive order signed June 22, 2026 makes it explicit for federal contractors. What the HKMA has done is translate an abstract requirement into a concrete procurement practice that any institution, in any jurisdiction, can implement before the end of this quarter.
- 01
Add a quantum readiness assessment to your vendor onboarding process, so new relationships are scored before they are signed rather than remediated afterwards.
- 02
Request each critical vendor's PQC migration roadmap in writing, and document the response you get.
- 03
Include the right to conduct cryptographic assessments in new and renewed contracts, while the renewal is still open and you have leverage.
- 04
Track vendor progress over successive assessment cycles, so a stalled roadmap is visible as a trend rather than a surprise.
None of these actions require a quantum computer to exist. None require your institution to have completed its own internal migration. They require a decision to begin, and the documentation that you began. That documentation is what your examiner will ask for in 2027.
The Immediate Implication for US Banks and Credit Unions
The HKMA has published a score and set a clock. The FFIEC has not yet published equivalent survey data for US institutions, but the global pattern makes the conclusion hard to avoid. The regulatory timeline is the same. The vendor dependency problem is the same. The harvest-now-decrypt-later risk is the same.
The four immediate actions the whitepaper recommends apply to every US bank and credit union regardless of asset size:
- 01
Engage the board. If quantum cryptographic risk has not been discussed at board level since the June 22, 2026 executive order, schedule a briefing this quarter. Reference EO 14412 and OMB M-26-15 by name.
- 02
Appoint an accountable owner. PQC migration without a named internal owner does not happen. Someone must own the inventory, the roadmap, and the vendor engagement programme.
- 03
Commission a cryptographic inventory. CISA's CBOM minimum elements guidance arrives March 19, 2027. Institutions that begin their inventory now will be compliant before the standard is formally required.
- 04
Engage critical vendors. Contact your three most critical fintech vendors this quarter. Ask specifically for their PQC migration roadmap. Document the response, or the non-response. Both are examination-relevant evidence.
The vendor dependency problem is solvable
87% of Hong Kong’s banks named third-party vendor dependencies their biggest barrier to PQC readiness. PQCClear automates the cryptographic assessment of every fintech vendor in your portfolio, producing a Quantum Readiness Score, a full CBOM, and an examination-ready report for each one. The barrier the HKMA identified is exactly what we built to remove.
Request accessThis post represents the editorial analysis of PQCClear as of August 4, 2026. It should not be construed as legal advice. Financial institutions should consult legal counsel and compliance advisors regarding their specific regulatory obligations.
Key sources: HKMA Quantum Preparedness Index whitepaper (hkma.gov.hk, July 27, 2026); Marin Ivezic analysis (postquantum.com, August 3, 2026); FINMA Guidance 05/2026 (finma.ch, July 9, 2026); Executive Order 14412 (whitehouse.gov, June 22, 2026); OMB M-26-15 (whitehouse.gov, June 24, 2026). The 5.6-year average implementation timeframe is drawn from the QPI whitepaper survey data as cited in Carmen Chu’s FiNETech8 opening remarks, July 27, 2026.