Results of Quantum Preparedness Index Survey (2026-07-27)

Circulars Email: HKMA E-mail Alert of 28 July 2026 (05:00 p.m. HKT)

Document Information

Title: Results of Quantum Preparedness Index Survey (2026-07-27)

Type: Circulars

URL: https://brdr.hkma.gov.hk/eng/doc-ldg/current/20260727-1-EN

Email Received: 2026-07-28 19:12

Summary Created: 2026-07-28 14:00

English Summary
Quick section switch
Management Summary
  • Purpose / Background: The HKMA has assessed the banking sector's readiness for the "Quantum Era." While quantum computing offers significant potential for financial modeling and optimization, its ability to break current cryptographic standards—specifically through Cryptographically Relevant Quantum Computers (CRQC)—poses an urgent risk to secure communications, customer data, and payment systems.
  • One-line conclusion: AIs must transition from awareness to actionable Post-Quantum Cryptography (PQC) readiness by establishing formal governance, cryptographic inventories, and vendor management strategies immediately.
  • Key Changes:
  • Shift from viewing quantum computing purely as a research topic to a critical enterprise risk.
  • Requirement to perform comprehensive cryptographic inventories to identify vulnerabilities.
  • Mandatory integration of "quantum readiness" into third-party/vendor risk management and new contracts.
  • Adoption of a phased "Awareness, Planning, Pilot, Practical Preparedness" framework.
  • Proactive engagement with FMIs and regulators to ensure ecosystem-wide interoperability.
  • Key Dates / Deadlines: No specific calendar deadline provided; however, the HKMA emphasizes "immediate attention" and a "multi-year" transition requirement, urging AIs to start foundational work now.
  • Applicability / Impact scope: All Authorized Institutions (AIs) operating in Hong Kong, including their third-party dependencies, payment networks, and financial market infrastructure (FMI).
  • Recommended management actions:
  • Appoint an executive owner with cross-functional authority for quantum readiness.
  • Include quantum risk as a permanent agenda item in board/senior risk governance meetings.
  • Commission an initial (iterative) cryptographic inventory to map current encryption usage.
  • Embed PQC roadmap requirements into all new and renewed third-party vendor contracts.
  • Participate in upcoming HKMA-led workshops, PQC toolkits, and industry forums to align on standards.
Detailed Summary
  1. Document overview: This paper outlines the findings of the HKMA’s Quantum Preparedness Survey 2026. It assesses the sector’s current maturity in quantum computing and PQC and provides a strategic roadmap for AIs to mitigate risks while preparing for future technological advantages.
  1. Main requirements:
  • Governance: Establish senior management oversight. Quantum risk must be treated as an enterprise-level risk.
  • Inventory: Develop a "cryptographic inventory." AIs must identify where and how encryption is used across systems and data.
  • Third-Party Risk: Engage vendors to obtain their PQC roadmaps and ensure new contracts include quantum-readiness clauses.
  • Operational Alignment: Embed PQC transition into existing Business-as-Usual (BAU) processes (e.g., cyber risk management, operational resilience).
  1. Key changes:
  • Recognition of the "Harvest Now, Decrypt Later" (HNDL) risk, where sensitive data stolen today could be decrypted by future quantum computers.
  • Shift from passive observation to active "cryptographic agility"—the ability to easily update or swap cryptographic algorithms as standards evolve.
  1. Important dates & transition:
  • The transition is a multi-year effort. Immediate actions (governance, inventory, vendor engagement) are required now, well in advance of widespread CRQC availability, to manage the transition timeline and technical debt.
  1. Impact and risks:
  • Cybersecurity: Potential compromise of existing public-key infrastructure (PKI) and digital signatures.
  • Operational: Complexity of replacing legacy systems that rely on hard-coded or outdated cryptographic standards.
  • Strategic: Need for talent development and internal expertise in PQC.
  1. Compliance action checklist:
  • [ ] Assign a senior executive owner.
  • [ ] Add quantum risk to the Risk Governance framework.
  • [ ] Initiate the cryptographic discovery/inventory phase.
  • [ ] Review procurement templates to mandate vendor PQC roadmaps.
  • [ ] Participate in HKMA industry sharing sessions.
  1. Appendices/attachments summary:
  • Appendix 05 (Technical/Financial Use Cases): Provides deep-dive technical explanations of quantum mechanics (superposition and entanglement) and a categorization of financial use cases (Optimization, Simulation, Machine Learning). It also lists major quantum algorithms (e.g., Shor’s, QAOA) and provides technical detail on why current asymmetric encryption is vulnerable. (Covers ~15% of the document content).
中文摘要
快速切換摘要區塊
管理層摘要
  • 目的/背景 香港金融管理局(HKMA)為應對量子計算技術的發展,旨在提升銀行業的技術韌性。量子計算雖帶來風險建模與優化的潛力,但其「密碼分析」能力亦可能威脅現行加密技術(如 RSA, ECC),導致金融系統的關鍵數據面臨「先儲存,後解密」(HNDL)的長期風險。
  • 一句話結論 銀行業必須立即啟動量子韌性準備工作,特別是建立加密資產清單與過渡至「後量子密碼學」(PQC),將量子風險納入企業風險治理框架。
  • 關鍵變更
  1. 將量子威脅從單純的技術問題提升為「企業級風險」。
  2. 強制性要求: 需建立並迭代「加密資產清單」(Cryptographic Inventory)。
  3. 要求將量子韌性要求整合至第三方供應商管理與新簽署合同中。
  4. 明確過渡路徑: 需經歷意識建立、規劃、試驗及實作四階段。
  5. 金管局將透過工作坊、工具包與產業論壇提供監管引導。
  • 重要日期 / 截止日 本文件無單一強制性截止日期,但要求「立即行動」。過渡期預計跨越多年,需建立長期遷移藍圖。
  • 適用對象 / 影響範圍 所有在香港營運的認可機構(AIs)。影響涵蓋網絡安全、IT 基礎設施、數據治理及第三方風險管理。
  • 管理層建議行動
  1. 董事會介入 將量子風險列為風險治理的常設議題。
  2. 指派負責人 任命具有跨職能權限的量子韌性負責人。
  3. 啟動加密資產清單盤點 即使初步版本不完美,也要立即開始迭代。
  4. 供應商溝通 要求關鍵供應商提供 PQC 發展路徑圖,並在合同中加入量子韌性條款。
  5. 能力建構 對技術團隊進行 PQC 及量子計算基本概念培訓。
詳細摘要

1) 文檔概述
本文為金管局針對銀行業「量子準備度」(Quantum Preparedness)的指導報告,性質屬於策略方針與執行框架,旨在確保香港金融系統在量子計算演進過程中的韌性與誠信。

2) 主要要求

  • 風險治理 必須將量子風險整合至現有的營運韌性與網絡安全體系中。
  • 數據保護 識別高敏感性、長壽命數據(Long-lived confidential data),防範 HNDL(先截獲,後解密)攻擊。
  • 供應鏈韌性 與金融市場基礎設施(FMI)、技術服務供應商及交易對手協調,共同定義遷移路徑與互操作性測試。

3) 關鍵變更

  • 思維轉變 由將量子計算視為「遙遠的研發專案」轉變為「立即性的加密韌性挑戰」。
  • 管理強度 從缺乏正式架構,轉向要求建立正規的治理框架、專項資金及審計監測機制。

4) 重要日期與過渡安排
無硬性截止日,採取「階段性演進」:

  • 階段一(意識) 完成內部管理層對量子風險的認知建立。
  • 階段二(規劃) 建立加密資產清單並進行量子風險暴露評估。
  • 階段三(試驗) 針對核心系統進行 PQC 兼容性驗證與回滾機制測試。
  • 階段四(實作) 全面導入 PQC 於業務運作流程。

5) 對機構的影響與風險

  • IT 與資料 需要大規模識別與更換遺留基礎設施中的舊式加密算法。
  • 營運 技術負債(Technical Debt)可能拖累遷移進度。
  • 合規與報告 需不斷更新針對量子安全標準的合規檢核。

6) 合規動作清單 (Checklist)

  • [ ] 設立量子韌性工作小組及執行負責人。
  • [ ] 提交董事會關於量子風險的影響報告。
  • [ ] 建立銀行內部的加密功能清單(Inventory)。
  • [ ] 針對第三方廠商發出 PQC 問卷調查。
  • [ ] 將「量子準備度條款」納入供應商採購標準。

7) 附件/附錄摘要

  • 技術附錄(Appendix 5.1-5.3) 詳細解釋了量子疊加(Superposition)、糾纏(Entanglement)機制及 Shor's/Grover's 算法對現有加密(RSA/AES)的威脅原理,幫助技術團隊進行科學評估。
  • 金融應用案例(Appendix 5.2) 彙整了投資組合優化、詐欺偵測、風險建模等領域的具體算法應用,為機構進行概念驗證(PoC)提供技術參考。