Hong Kong’s Quantum Readiness Score Makes the Work Visible

Quentir Defense Monitor

Evidence-based insights for quantum defense and security. Published by Quentir Systems LLC · July 28, 2026.

A modular cryptographic migration testbed in a daylight financial infrastructure operations hall

Hong Kong’s banking sector has placed a number on a problem that many institutions still discuss in general terms: its first quantum preparedness score is 2.3 out of 10. The low baseline makes the transition workload visible early enough for boards and security teams, together with suppliers, to turn concern into a governed sequence of decisions.

The official release issued for the Hong Kong Monetary Authority reports that the new Quantum Preparedness Index evaluates banks first on awareness and planning, then on pilots and practical preparedness. About 68 percent of surveyed banks have reached at least awareness or moved into planning or pilot work. Another 32 percent have yet to begin their transition, and roughly half have no formal post-quantum plan. The authority aims to move the sector to a score of 10 by 2030, supported by a practical toolkit and workshops developed with industry and the Hong Kong University of Science and Technology.

Those figures give the quantum preparedness index a useful role. It converts a diffuse future risk into a baseline that can be repeated and compared in board discussions. Its harder test begins after publication. A readiness score earns operational meaning when each higher step corresponds to evidence that an institution can produce: named owners and mapped systems; prioritized data and tested upgrades; supplier commitments with recovery plans.

A score can create a common operating picture

Financial institutions share payment rails and identity services. They also depend on software providers and certificate authorities, alongside cloud platforms and telecom networks. One bank can strengthen its own systems while remaining exposed to a dependency controlled elsewhere. A sector index gives the regulator and participating banks a common picture of where coordination is weak. It can show whether awareness is spreading and whether planning has moved beyond a small group of larger institutions.

The four QPI dimensions also reflect a sensible progression. Awareness establishes that leaders understand how future quantum computers could affect public-key cryptography. Planning assigns responsibility and resources. Pilots expose implementation constraints. Practical preparedness shows whether the institution can make controlled changes in the environment where services operate. Treating those dimensions separately helps prevent a board discussion or a single laboratory exercise from carrying more weight than it deserves.

The 2.3 baseline should therefore be read as a starting coordinate. It says that the sector has begun organizing around the issue while practical implementation remains limited. The accompanying survey gives the score texture: around half of respondents reported board-level discussion, while about one-third had begun exploring or piloting quantum-related initiatives. Discussion has reached senior leadership in many institutions, yet formal migration planning has not reached the same breadth.

That gap matters because post-quantum cryptography changes components that banks rarely replace in one coordinated move. Public-key mechanisms appear in customer channels and interbank messaging; software signing and device identity; remote administration and databases; hardware modules and third-party services. Some protect information that must remain confidential for years. Others protect transaction integrity or decide which machine may join a network. Each function carries a different failure consequence and a different replacement window.

A regulator can use later QPI rounds to make this distinction clearer. Progress in awareness is meaningful during the first measurement. Repeated measurements should give more weight to durable artifacts and exercised capabilities. A bank that can show current ownership and system coverage, supplier dependencies with migration priorities, plus test results has moved further than one that has approved a policy with little technical reach. The index becomes more credible when its rising score is difficult to earn through declarations alone.

Quantum pillar: post-quantum cryptography (migration and crypto-agility). Use posture: defensive. Technology readiness: not applicable. The development is a supervisory survey and preparedness index, so it measures institutional planning rather than advancing a specific technology on the ladder.

Discovery is where planning becomes evidence

The practical starting point is a cryptographic inventory that links cryptography to business services and protected data. NIST’s post-quantum cryptography program says organizations should identify where vulnerable algorithms are used and plan their replacement or update. It also identifies ML-KEM, ML-DSA, and SLH-DSA as the three principal standards released in 2024, while its migration work demonstrates tools for finding and prioritizing vulnerable systems.

For a bank, a useful inventory reaches beyond an algorithm name. It records the application, protocol, certificate path, key owner, implementation, data lifetime, and operational dependency associated with that use. It identifies whether a change can arrive through configuration, a library update, a hardware refresh, or a supplier release. It also shows where a shared service supports several business functions. That relationship data allows the institution to rank work by consequence and lead time.

The UK NCSC’s PQC migration timeline expects large organizations to complete discovery and assessment, define migration goals, and build an initial plan by 2028. It expects the highest-priority migration work by 2031 and broad completion by 2035. The dates are less important than the sequencing. NCSC estimates that estate discovery plus a migration strategy and initial plan can take two to three years for a large organization. A 2030 preparedness target leaves limited room for a bank that postpones estate discovery.

This is where the QPI can improve sector behavior. A planning score could require coverage measures for the cryptographic estate, with gaps kept visible. A pilot score could require a defined service and test objective, followed by recorded results. Practical preparedness could require a controlled deployment with monitoring, fallback procedures, plus evidence that connected parties can interoperate. Such markers let smaller banks learn from shared patterns while preserving responsibility for their own systems.

Pilots should answer operational questions

A pilot has value when it resolves a decision that blocks migration. It can measure message size, processing delay, certificate handling, hardware-module support, or compatibility with a payment counterparty. It can test how a dual-stack period affects monitoring and incident response. It can also reveal that a planned replacement depends on a device lifecycle or contractual renewal that begins earlier than the technical deployment.

The BIS roadmap for quantum readiness in the financial system reinforces this operational focus. Its authors describe broad awareness and cryptographic inventory as foundations. They then emphasize performance trade-offs with system integration, coordinated planning through hybrid models, and phased migration. Their central warning is practical: replacing an algorithm does not capture the scope of the change. Financial resilience depends on the surrounding infrastructure and on institutions moving together.

That coordination burden is especially relevant to defense and national security. Banks support government payments and defense suppliers, as well as deployed personnel and critical infrastructure operators. Financial channels also intersect with sanctions controls and emergency response. A migration fault that interrupts identity or transaction integrity can create real operational friction even when the underlying cryptographic choice is sound. Sector exercises should therefore test service continuity alongside algorithm performance.

Crypto-agility is the lasting outcome

The immediate task is migration away from quantum-vulnerable public-key mechanisms. The longer-lived capability is crypto-agility: the ability to change cryptographic mechanisms through controlled engineering and governance as standards, implementations, or threats evolve. An agile system exposes its cryptographic choices, supports managed updates, separates algorithms from business logic where practical, and can test a transition before committing the change.

Agility should be visible in architecture and operating practice. Teams need supported libraries and hardware, clear configuration ownership, current dependency records, and test environments that reflect important traffic. Change windows require rollback paths. Monitoring must identify negotiation failures and unexpected fallbacks. Supplier contracts need update duties and usable evidence. These elements turn “ready to migrate” into a capability that can survive the next cryptographic change as well.

Hong Kong’s planned PQC toolkit can help align these practices across institutions. A shared toolkit can define the minimum evidence behind discovery, prioritization, pilots, and practical preparation. Workshops can then focus on real obstacles found in the baseline survey. Smaller institutions benefit when templates and test patterns reduce duplicated design work, while the regulator gains a clearer view of dependencies that cross the sector.

The most useful next QPI will show movement within each dimension and explain what evidence supported it. A higher average score should reveal fewer banks without formal plans, broader inventory coverage, more pilots tied to decisions, and practical work on priority services. Publishing the baseline creates accountability for that progression. It also gives other regulated sectors a model they can examine: measure early, define what advancement requires, and connect every claimed step to work that can be inspected.

The 2.3 score is candid and therefore useful. It does not predict the arrival of a cryptographically relevant quantum computer, and the migration does not need that date to be exact. Hong Kong now has a public baseline, a 2030 objective, and a mechanism for seeing whether institutional activity is moving from discussion into capability. The strength of the index will rest on how firmly future scores connect to systems and suppliers, with tests tied to operational decisions.

Sources

Primary source: Hong Kong Monetary Authority; other material from NIST, the UK NCSC, and BIS authors Raphael Auer, Donna Dodson, Angela Dupont, Maryam Haghighi, Nicolas Margaine, Danica Marsden, Sarah McCarthy, and Andras Valko.

  1. official release issued for the Hong Kong Monetary Authority
  2. post-quantum cryptography program
  3. PQC migration timeline
  4. BIS roadmap for quantum readiness in the financial system
Previous
Previous

AI Cryptanalysis Changes Post-Quantum Assurance

Next
Next

The CBOM Turns Post-Quantum Migration Into a Map