Telecommunications operators in Mainland China are also exploring quantum-resistant and quantum-secure communication scenarios. For example, public reporting on China Telecom Quantum Group described work on post-quantum cryptography chips, systems combining Optical Transport Network (OTN) with Quantum Key Distribution (QKD), and commercial cryptography systems integrating QKD and PQC. These examples indicate that telecom-sector exploration is moving beyond algorithm research into communication, transmission and product scenarios.
These examples show that the industry and professional ecosystem is already investigating what approaches may be suitable, which algorithm families and implementation approaches may be suitable for future quantum-resistant security, how they should be evaluated, and how they may eventually be implemented in real-world systems. This also reinforces a practical message for organisations: the field is developing quickly, and PQC readiness should be built on continuous monitoring, cryptographic inventory and the ability to adapt as standards and technologies mature.
Hong Kong Is Beginning to Advance Post-Quantum Readiness
Although Hong Kong has not yet established comprehensive mandatory requirements for PQC migration, regulators, research institutions and related industry stakeholders have already started promoting quantum-security readiness from multiple perspectives, including risk management, capability building and technology research.
One notable development is the release of the Whitepaper on Quantum Preparedness of Hong Kong's Banking Sector and the first Quantum Preparedness Index (QPI) by the Hong Kong Monetary Authority (HKMA) in 2026. The QPI assesses the banking sector's readiness across four dimensions: Awareness, Planning, Pilots and Practical Preparedness. Survey results showed an initial QPI score of 2.3 out of 10, indicating that the sector is still in the early stages of preparedness. Approximately 32% of surveyed banks had not yet begun quantum-related transition activities, while around half had not established formal PQC planning. The HKMA has stated its intention to continue supporting the banking sector through guidance, training and industry engagement, with the aim of improving sector-wide readiness by 2030.
Meanwhile, Hong Kong's research community is actively exploring quantum-secure technologies. In 2025, the Research Institute for Quantum Technology (RIQT) at The Hong Kong Polytechnic University announced the successful completion of Hong Kong's first chip-based quantum communication network test. The research team used a self-developed quantum communication chip to conduct a Quantum Key Distribution (QKD) demonstration over approximately 55 kilometres of existing optical fibre infrastructure. While QKD and PQC represent different technological approaches, both are regarded as important components of the future quantum-security ecosystem. QKD focuses on protecting key exchange through the principles of quantum mechanics, whereas PQC uses new cryptographic algorithms designed to resist quantum attacks.
Taken together, these developments suggest that Hong Kong's quantum-security efforts are gradually progressing from conceptual research towards practical planning and technology validation. From sector-wide readiness assessments and maturity-building initiatives to quantum-secure communication research, quantum risk is increasingly being recognised as a long-term strategic issue rather than merely a future technology discussion.
PQC Is Promising, But the Field Continues to Evolve
Post-quantum cryptography is one of the most important tools for preparing for future quantum-related security risks. However, organisations should understand that cryptography is a living field. Confidence in cryptographic algorithms comes from open evaluation, standardisation, implementation experience and continued research.
This is why standards bodies and industry participants continue to evaluate algorithms, implementation approaches and migration options. Even after major standards are published, further research may continue, additional algorithms may be evaluated, and future cryptanalysis may influence parameter choices or deployment recommendations.
For organisations, the lesson is not that PQC should be avoided. The lesson is that PQC should be approached through standards-based planning, testing and agility. It is not enough to choose a single algorithm and assume the issue is solved permanently.
In simple terms, PQC readiness is not only about finding “the final answer”. It is about building the capability to monitor developments, evaluate practical options and adjust when cryptographic technologies evolve.
Why Cryptographic Inventory Matters More Than Algorithm Names
For most organisations, the most useful action today is not to deploy PQC everywhere. The most useful action is to understand where cryptography exists. Without this visibility, organisations will struggle to plan future migration, engage vendors or prioritise risk.
A cryptographic inventory records which systems use cryptography, what algorithms are used, who owns the systems, whether the systems can be upgraded and whether third-party vendors are involved. This may sound technical, but the management purpose is simple: identify future migration exposure before it becomes urgent.
Organisations should begin by identifying systems that use or depend on:
- RSA certificates
- ECC certificates
- Diffie-Hellman or ECDH key exchange
- RSA or ECDSA digital signatures
- Internal or external certificate authorities
- Cryptographic libraries embedded inside applications
- Hardware security modules (HSMs)
- VPN, remote access and secure communications platforms
- Smart cards, tokens and authentication devices
- Embedded systems, appliances and operational technology environments
For each system, organisations should record:
- The business owner and technical owner
- The cryptographic algorithms in use
- The key lengths and certificate types
- The certificate authority or trust chain involved
- The product or software version
- The vendor or service provider
- The expected system lifetime
- Whether the system supports algorithm updates
- Whether PQC support would require configuration changes, software updates or hardware replacement
The cryptographic inventory does not need to be perfect on the first day. Even a basic inventory can help organisations identify critical dependencies, prioritise long-life systems and avoid discovering cryptographic constraints only when migration becomes urgent.
What Hong Kong Organisations Can Learn

(Image generated by generative AI and reviewed under professional human supervision.)
As an international business and technology hub, Hong Kong organisations can benefit from understanding internationally recognised standards, developments within Mainland China, and emerging quantum-security initiatives taking place locally. This does not require choosing one technology direction over another. Rather, organisations can learn from structured guidance, observe how different sectors are approaching quantum readiness, and monitor how practical deployment models continue to evolve.
International and Mainland Chinese standards, guidance and industry initiatives provide an important management lesson: begin with discovery, identify quantum-affected cryptographic assets, prioritise high-risk systems and establish migration plans. Recent developments in Hong Kong reinforce the same message. Whether through banking-sector quantum-readiness assessments, maturity-building efforts, or research into quantum-secure communications, quantum readiness is increasingly becoming a governance, planning and technology-management issue rather than solely a research topic.
For Hong Kong organisations, the combined message is practical and balanced:
- Do not assume PQC migration can be completed quickly when the need becomes urgent.
- Do not assume every product labelled “post-quantum” will be suitable for every environment.
- Do not focus only on algorithm names; focus on inventory, agility, vendor support and testing.
- Do not wait for perfect certainty before taking low-risk preparation steps.
Instead, organisations should use today’s developments as an opportunity to strengthen long-term cyber resilience. The same activities that support PQC readiness, such as cryptographic inventory, vendor management, certificate lifecycle review and secure system architecture, also improve general cybersecurity governance.
Although Hong Kong has not yet introduced comprehensive PQC migration requirements across all sectors, local financial regulators have already begun assessing quantum-readiness, while industry and research institutions continue to explore relevant technologies and practices. These developments suggest that quantum-security readiness is not a distant concern, but a long-term capability-building effort that benefits from early planning.
As business operations, cloud services and supply chains become increasingly interconnected across borders, organisations may face growing expectations from both mainland and international customers, parent companies, regulators, cloud providers and business partners to demonstrate their understanding of quantum-related risks and their plans for managing them. Even when these expectations initially take the form of risk assessments, inventory requests or migration planning discussions, developing visibility and governance over cryptographic assets today can help organisations respond more effectively to future business, compliance and security requirements.
Regular cryptographic inventory reviews and quantum-readiness assessments can therefore serve as practical steps towards building long-term governance capabilities for quantum-security risks.
Build Cryptographic Agility Into Future Systems
Cryptographic agility is the ability to replace or update cryptographic algorithms without redesigning the entire system. It is one of the most important concepts for PQC readiness because the field will continue to evolve.
A system with poor cryptographic agility may hard-code RSA or ECC in ways that are difficult to change. A cryptographically agile system should allow algorithms, libraries, certificate types or protocol configurations to be updated through supported upgrade paths, configuration changes or software updates.
When procuring new systems or modernising existing ones, organisations should avoid:
- Hard-coded cryptographic algorithms
- Unsupported cryptographic libraries
- Products that cannot change certificate types
- Systems without clear upgrade paths
- Long-term dependencies on outdated protocols
Organisations should prefer systems that:
- Use modern and supported cryptographic libraries
- Allow algorithms and key lengths to be updated
- Support certificate lifecycle management
- Provide clear vendor roadmaps for future standards
- Can be tested safely before production deployment
- Support migration through software or configuration changes where possible
For SMEs, this does not mean building cryptographic systems from scratch. It means asking vendors better questions, avoiding unnecessary lock-in and ensuring that important systems have realistic upgrade paths.
Questions to Ask Vendors and Service Providers
Many organisations will depend on technology suppliers, managed service providers, cloud platforms and software vendors for PQC support. Asking whether a product is simply “post-quantum” may not be enough. Organisations should ask more specific questions.
- Which components of the product use public-key cryptography?
- Does the product use RSA, ECC, Diffie-Hellman, ECDH or ECDSA?
- Is there a roadmap for PQC or hybrid cryptography support?
- Will PQC support require software updates, configuration changes, licence changes or hardware replacement?
- Will the product support standardised algorithms such as ML-KEM, ML-DSA or SLH-DSA where appropriate?
- How will interoperability with older clients, browsers, devices or applications be handled?
- Will certificate types, trust stores or PKI integrations need to change?
- What testing guidance will be provided before production deployment?
- Will performance, bandwidth, storage or hardware requirements change?
- What is the vendor’s long-term support plan for cryptographic updates?
For critical systems, these questions should be included in procurement, renewal and architecture discussions. PQC readiness is not only a cybersecurity issue; it is also a vendor management and technology lifecycle issue.
PQC Readiness for Large Enterprises and SMEs
PQC readiness is not only a challenge for governments, financial institutions or large enterprises. Organisations of all sizes rely on digital systems, cloud services, software platforms and third-party providers that may eventually be affected by the transition to post-quantum cryptography.
The key difference is not whether organisations need to prepare, but how they should prepare. Large enterprises often manage complex technology environments, large cryptographic estates and long system lifecycles. Their priorities may include building cryptographic inventories, conducting risk assessments and developing phased migration roadmaps.
SMEs are often more dependent on commercial products, cloud platforms and managed services. Their priorities may include understanding which critical systems they rely upon, engaging vendors on PQC roadmaps and avoiding products that cannot support future cryptographic upgrades.
Security Recommendations
A HKCERT Suggested Timeline for PQC Readiness
While Hong Kong has yet to establish a specific schedule for PQC migration, local organisations should not merely stand by. On the contrary, they must actively initiate preparations for the upcoming transition. There is broad agreement that cryptographic migration itself can take many years. As a result, PQC readiness planning should not be driven by predictions about when a quantum breakthrough may occur, but by the practical time required for system migration, supplier coordination and technology refresh cycles.
For most organisations, activities such as cryptographic inventory, risk assessment, vendor engagement, testing and deployment involve multiple business units, technology platforms and third-party products. Many critical systems also have lifecycles measured in years or even decades. Consequently, even if quantum-related risks are not considered immediate, preparation should not be postponed until the last moment.
Taking reference from international migration roadmaps and the Hong Kong Monetary Authority's objective of improving banking-sector quantum readiness by 2030, organisations may consider:
- Initiating cryptographic inventories and risk assessments in 2027;
- Developing migration roadmaps, vendor-engagement plans and technical evaluations between 2028 and 2030;
- Progressively migrating higher-priority and longer-lifecycle systems after 2030, based on business risk and technology maturity.
The objective is not necessarily to complete a full migration by a specific date. Rather, it is to ensure that when migration becomes necessary, organisations already possess the visibility, planning capabilities and technical readiness required to manage quantum-related risks in an orderly manner.
How Organisations of Different Sizes Can Start Preparing for PQC
PQC readiness is not only relevant to banks, government departments or large enterprises. Regardless of size, any organisation that relies on computer systems, cloud services, online communications or third-party software may be affected by future cryptographic transition.
Actions for All Organisations
PQC readiness should not be treated simply as a technical replacement exercise. Organisations should first understand which information may face long-term risks from advances in quantum computing, and establish basic follow-up and decision-making arrangements so that future preparation can proceed in an orderly manner based on standards, product support and the organisation’s own risk profile.
- Review Long-Term Sensitive Data
Organisations should identify information that must remain confidential for many years, such as personal data, health records, financial records, legal documents, intellectual property, strategic business information and regulated information.
Such information may face “harvest now, decrypt later” risks, where attackers intercept or store encrypted data today and attempt to decrypt it in the future when quantum computing capabilities mature. The longer information needs to remain confidential, the earlier it should be considered as part of PQC readiness planning.
- Monitor Standards and Industry Developments
Organisations should continue to monitor PQC-related standards, regulatory guidance and support from major technology vendors, particularly updates relating to browsers, operating systems, cloud platforms, network devices, identity services, certificate services and security products.
As PQC readiness will depend on standards maturity, product support, platform interoperability and vendor upgrade arrangements, organisations should avoid making long-term technical decisions based solely on individual product claims or vendor marketing. A more prudent approach is to continue tracking public standards and major platform developments, and prepare gradually based on the organisation’s own risks and business needs.
- Assign Responsibility and Establish Follow-Up Arrangements
Organisations should clearly assign responsibility for following up on PQC readiness, such as to information technology, cybersecurity, risk management, procurement or compliance functions. Even for smaller organisations, a responsible person should be assigned to regularly monitor vendor notifications, product updates, regulatory guidance and industry developments.
This helps avoid a situation where PQC readiness is not coordinated because it involves multiple areas, including technology, procurement, contracts and risk management. For large organisations, this can provide a basis for cross-functional coordination. For SMEs, it helps ensure that PQC-related matters are not only dealt with reactively during system renewals, product replacements or incidents.
- Adopt a Cautious and Phased Approach
PQC standards and product support are still maturing. Organisations do not need to replace all relevant systems at once, and should not make major changes in production before they have sufficiently understood compatibility, performance, support arrangements and rollback options.
A more appropriate approach is to first establish basic awareness and follow-up arrangements, and then proceed in phases based on data sensitivity, business criticality, system lifespan, vendor support and available resources.
Actions for Large Organisations
Large organisations typically have more complex IT environments, internally developed systems and longer technology lifecycles. They should therefore place greater emphasis on building cryptographic inventories, conducting risk assessments and planning phased migration roadmaps, including:
- Build and Maintain a Cryptographic Inventory
Build a more comprehensive cryptographic inventory to identify systems that use public-key cryptography, including RSA, ECC, Diffie-Hellman, ECDH and ECDSA.
The inventory should, where possible, record system owners, business purposes, vendors, algorithms, certificate types, product versions and upgrade paths. For more complex environments, organisations may also record system dependencies, data types, compliance requirements, key management arrangements and third-party integrations to support subsequent risk assessment and migration planning.
- Prioritise Systems Based on Risk and Lifespan
Prioritise systems based on their criticality, data sensitivity, external exposure, technology lifecycle and upgrade complexity.
Priority should be given to systems that protect sensitive information, support critical business processes, face the internet, or are expected to remain in service for many years. For core systems, legacy platforms, internally developed applications or systems with long technology lifecycles, organisations should allow sufficient time for assessment, testing, modification and migration.
- Plan a Phased Migration Roadmap
Should not treat PQC migration as a one-off technical replacement. Instead, they should develop a phased migration roadmap based on system risk, business impact, technical feasibility and vendor support.
The roadmap may include asset discovery, risk classification, proof of concept, deployment in test environments, vendor coordination, certificate and key management changes, production rollout arrangements and rollback plans. This can help reduce the impact of large-scale changes on business operations, system compatibility and service stability.
- Design for Cryptographic Agility
New systems should avoid hard-coded cryptographic dependencies and should, where possible, support future algorithm replacement through standard update or configuration mechanisms.
For internally developed systems or long-term internal platforms, organisations may consider adopting more modular cryptographic designs, allowing algorithms, certificates, key lengths and related parameters to be adjusted in the future based on standards or business needs, without requiring major rewrites of applications or system architecture.
- Test Before Deployment
Before deploying PQC or hybrid cryptographic mechanisms in production, organisations should conduct compatibility, performance and security testing in controlled environments.
Testing may cover applications, browsers, network devices, identity systems, APIs, certificate management, logging and monitoring, backup systems and third-party integrations. As PQC or hybrid cryptography may involve larger keys, signatures or message sizes, organisations should also assess potential impacts on performance, bandwidth, latency and storage.
- Avoid Premature Lock-In to Specific Solutions
Avoid becoming prematurely dependent on a single vendor, proprietary implementation or PQC solution that lacks interoperability. Preference should be given to approaches that are based on public standards, clearly documented, testable, reversible and interoperable with existing systems and other platforms.
Organisations should pay particular attention to the long-term switching costs that may arise if standards change, vendor strategies shift, products are discontinued or cross-platform integration becomes necessary. For core systems, identity services, certificate management and cross-departmental platforms, organisations should preserve flexibility to change algorithms, products or vendors in the future.
SMEs Should Stay Informed About PQC
While PQC migration may not be an immediate priority for many SMEs, organisations should remain aware of developments and consider PQC readiness as part of their longer-term technology planning. A practical and phased approach can help minimise costs and operational impact. SMEs may focus on identifying critical business systems and services, engaging vendors and managed service providers on their PQC roadmap and upgrade plans, and incorporating PQC-related considerations into future procurement and contract renewal processes. By maintaining visibility of key systems and supplier dependencies, SMEs can gradually align with future cryptographic requirements while avoiding unnecessary complexity.
Common Misconceptions
As PQC becomes more widely discussed, organisations should avoid both unnecessary alarm and false confidence.
Myth: Quantum computers will immediately break all encryption.
Reality: The main concern is with certain public-key cryptographic algorithms. Properly configured symmetric encryption is generally considered less directly affected, although organisations should continue following recognised cryptographic best practices.
Myth: PQC migration means replacing every system now.
Reality: For most organisations, the immediate priority is inventory, planning, vendor engagement and cryptographic agility, not immediate mass deployment.
Myth: Once one PQC algorithm is selected, the problem is solved forever.
Reality: Cryptography continues to evolve. Standards bodies, researchers and industry participants continue to evaluate algorithms, implementation approaches and deployment models.
Myth: PQC readiness is only a technical issue.
Reality: PQC readiness also involves governance, procurement, vendor management, asset management, risk assessment, system architecture and long-term technology planning.
Conclusion
Post-quantum cryptography is becoming a practical long-term cybersecurity issue. International standards and guidance are helping organisations understand how to prepare, while industry bodies and technology organisations are exploring algorithms, architectures, interoperability and deployment models.
The most important lesson is not that every organisation must immediately deploy PQC. The more important lesson is that organisations should know where cryptography is used, understand which systems may be affected, and ensure that future technology decisions do not make migration unnecessarily difficult.
For Hong Kong organisations, this is an opportunity to take a balanced and practical approach. As an international business and technology hub, Hong Kong can benefit from internationally recognised standards and from practical industry developments taking place across different markets. Together, these perspectives point to the same conclusion: preparation should begin with visibility, agility and continuous monitoring.
The post-quantum transition will continue to evolve. Algorithms, products and deployment practices may mature over time. Organisations that maintain cryptographic inventories, engage vendors, protect long-term sensitive data and design systems for future algorithm changes will be better positioned to adapt with confidence.
In the post-quantum era, the strongest organisations will not necessarily be those that move the fastest. They will be those that understand their cryptographic foundations and can adapt when the technology landscape changes.