THALES BLOG

HKMA’s Quantum Preparedness Index: What Hong Kong Banks Should Do Next

September 17, 2026

Sabrina Ma Sabrina Ma | Regional Sales Director, Hong Kong, Macau & Mongolia More About This Author >

The Hong Kong Monetary Authority (HKMA) has put a figure on the banking sector’s current level of quantum preparedness: 2.3 out of 10.

The score comes from the new Quantum Preparedness Index (QPI), released alongside the Whitepaper on Quantum Preparedness of Hong Kong’s Banking Sector. The index looks at four areas: awareness, planning, pilots, and practical preparedness.

Around 68% of banks surveyed are aware of quantum risks or have begun planning or running pilots. The remaining 32% have yet to begin their transition, and around half of banks lack a formal post-quantum plan. The HKMA has committed to supporting the banking sector's transition toward quantum readiness by 2030 through practical guidance, training, industry collaboration, and capability-building initiatives.

The whitepaper builds on HKMA's Fintech 2030 strategy, which identifies quantum resilience as a strategic priority for Hong Kong's financial sector. It expands that vision by providing Authorized Institutions (AIs) with a practical four-stage roadmap – from Awareness and Planning to Pilot and Practical Preparedness – to prepare for their transition to post-quantum cryptography (PQC). Here’s what Hong Kong banks should know.

Start With a Cryptographic Inventory

Before deciding what to migrate, banks need to know where vulnerable cryptography is in use. That includes algorithms, keys, certificates, cryptographic libraries, and protocols, as well as the applications and infrastructure that depend on them.

Some will be relatively easy to find. Others may sit inside older applications, cloud services, payment systems, network connections, or products supplied and maintained by third-parties.

Once banks know what they have, they can work out what needs attention first. A system processing high-value transactions or protecting information that must remain confidential for many years may need to take precedence over a lower-risk application.

The inventory – often referred to as a Cryptographic Bill of Materials (CBOM) – should be treated as a living record. It provides the visibility needed to prioritize migration activities and manage cryptographic risk over time. As applications evolve, certificates are renewed, infrastructure is modernized, and new services are introduced, the CBOM must be continuously updated to ensure banks retain visibility into the cryptography they will eventually need to replace.

Build Cryptographic Agility

PQC algorithms will replace cryptography that quantum computers could eventually break, but banks also need a practical way to implement those changes across large, complex environments.

HKMA's Fintech 2030 strategy identifies cryptographic agility as one of the sector's priorities. The Authority is also working with the Hong Kong University of Science and Technology and the banking industry on a PQC toolkit to support transition planning and cryptographic agility.

Banks are unlikely to switch every application and system to PQC at the same time. Classical and post-quantum algorithms may need to coexist during migration. Providing cryptographic services through an infrastructure that supports multiple algorithms gives banks more flexibility to make changes without redesigning every application that uses them.

There are practical issues to test as well. PQC algorithms can have different key, signature, and certificate sizes, as well as different performance characteristics. Banks need to see how those differences affect their own applications, infrastructure, and transaction volumes.

Protect Long-Lived Sensitive Data

The risk to some data begins before a cryptographically relevant quantum computer exists.

That’s why the HKMA also highlights Mosca's Theorem, which emphasizes that organizations must consider not only when quantum computers arrive, but also how long sensitive data must remain confidential and how long migration will take.

With a harvest now, decrypt later (HNDL) attack, an adversary collects encrypted information and keeps it until the technology exists to break the cryptography protecting it. Data intercepted today could still be valuable to attackers years from now if it must remain confidential over a long period.

The 2026 Thales Data Threat Report found that 61% of organizations globally identify HNDL attacks as their leading quantum-related concern. In response, the report also found that 59% are already prototyping or evaluating PQC algorithms.

For banks, a useful starting point is to identify data that will remain sensitive several years from now and to establish how it is protected. Customer information, financial records, authentication material, and other long-lived sensitive data may not all have the same confidentiality period.

That gives banks another way to decide what belongs near the front of the migration queue.

Engage Technology Vendors Early

The HKMA survey found that dependencies on critical third-parties were the most frequently cited barrier to PQC readiness, reinforcing the importance of engaging vendors early. Because many cryptographic services reside within third-party platforms and shared infrastructure, migration planning cannot be completed in isolation.

For example, a bank’s PQC transition will depend in part on the technology it buys and the services it uses. Cloud providers, software vendors, payment platforms, network providers, certificate authorities, and other technology partners can all introduce cryptographic dependencies. Even when the bank is ready to migrate, a product it relies on may not yet support the required algorithms.

Banks can use vendor discussions to determine which standardized PQC algorithms are supported, what upgrades will be required, and whether hybrid deployments can be tested before a wider migration. They should also ask how vendors plan to handle subsequent algorithm changes.

Why Crypto Agility Is the Goal

Crypto agility extends beyond the initial PQC migration. As standards mature and future cryptographic vulnerabilities emerge, organizations need the ability to update algorithms, keys, and protocols without significant operational disruption. Building that flexibility today helps reduce the risk of future migration.

As the HKMA rightly highlights, successful PQC migration is about much more than replacing algorithms. Organizations need visibility into their cryptographic assets, crypto-agile infrastructure, and trusted partners who can help them navigate this transition with confidence.

How Thales Supports the Quantum Readiness Journey

The HKMA's recommendations highlight that quantum readiness requires both strategic planning and practical implementation. This is where experienced technology partners can help accelerate the journey.

As financial institutions progress through the HKMA's four-stage quantum readiness journey—from Awareness to Practical Preparedness—Thales helps build the trusted cryptographic foundation needed for a successful transition. Thales enables Authorized Institutions to:

  • Discover and manage cryptographic assets across hybrid and cloud environments
  • Protect sensitive data with centralized key management, encryption, and FIPS-certified Hardware Security Modules (HSMs) which is production-ready and NIST-approved post-quantum cryptography (PQC)
  • Build cryptographic agility to simplify future algorithm transitions
  • Evaluate PQC technologies through practical pilot engagements
  • Develop a phased migration strategy aligned with emerging industry standards

In addition to the technology solutions, the Quantum-Safe Financial Enterprise eBook offers guidance on how financial institutions can prepare, including prioritizing cryptographic changes based on data sensitivity, confidentiality requirements, and business criticality.

Banks that want to test PQC in their own environments can also join the Thales PQC Pilot Program. The pilot aligns closely with the HKMA's recommendation for controlled proofs-of-concept (PoC) that validate interoperability, performance, and migration approaches before large-scale deployment.

Examples include:

HKMA PoC AreaThales Solution
Websites and APIsThales Cloud WAF can help organizations evaluate the protection of internet-facing applications while preparing for future quantum-safe architectures.
Legal Document SignaturesLuna HSM provides a trusted cryptographic foundation for digital signing and supports organizations evaluating post-quantum signature use cases.
Cloud Key ManagementCipherTrust Key Manager and Luna HSM support secure key management and TLS 1.3 environments, helping organizations assess hybrid cryptographic approaches and future PQC adoption.
Internet-Facing Systems via CDNThales Cloud WAF can help secure customer-facing applications and APIs while organizations test quantum-safe migration strategies.
Distributed Ledger ConnectivityLuna HSM provides hardware-rooted key protection for digital assets, tokenization platforms, and distributed ledger environments evaluating post-quantum readiness.