Loading market data...

HKMA Launches Quantum Preparedness Index for Banks, Sets 2030 Deadline

HKMA Launches Quantum Preparedness Index for Banks, Sets 2030 Deadline

Hong Kong's de facto central bank, the Hong Kong Monetary Authority (HKMA), this week introduced a Quantum Preparedness Index and accompanying whitepaper aimed at helping the city's banks get ready for the cryptographic challenges posed by quantum computing. The HKMA wants lenders to achieve post-quantum cryptography readiness by 2030.

What the index measures

The Quantum Preparedness Index is a framework the HKMA designed to let banks assess where they stand today and track progress. The whitepaper lays out the technical and operational steps institutions should take to migrate away from current encryption standards that quantum computers could eventually break. The index covers areas like cryptographic inventory, risk assessment, and migration planning.

Why 2030

The 2030 deadline isn't arbitrary. Quantum computing is advancing fast enough that experts worry today's encrypted data could be harvested now and decrypted later — a 'store now, decrypt later' threat. The HKMA wants Hong Kong's financial system to have its new defenses in place before that window closes. The timeline gives banks about four years to audit their systems, test new algorithms, and swap out vulnerable crypto.

What banks need to do

The whitepaper doesn't mandate a single solution. Instead it walks banks through a phased approach: inventory all cryptographic assets, prioritize the most sensitive data and systems, run pilot migrations with post-quantum algorithms, and then roll out across the organization. The HKMA says it will update the index periodically as standards evolve. Banks that lag behind could face regulatory scrutiny, though the HKMA hasn't spelled out penalties yet.

Next steps

The HKMA plans to hold workshops and tabletop exercises with banks over the coming months to test the index in practice. A formal consultation on the whitepaper is expected later this year. For now, the message is clear: start planning, because 2030 will be here before most IT departments are ready.