Singapore And Hong Kong: From Quantum Advisories To Milestones
Singapore has dated quantum-safe milestones for critical infrastructure and promised milestones for financial institutions. Hong Kong has measured its banks and set a 2030 aim. The position as of October 2026.
Checked against primary sources and independently reviewed on . Sources are listed at the end.
Singapore and Hong Kong are two of Asia’s leading financial centres, and both moved on quantum risk in July 2026. On 16 July, Singapore’s Cyber Security Agency (CSA) published dated milestones for critical information infrastructure (CII). On 27 July, eleven days after the handbook, the Hong Kong Monetary Authority (HKMA) published the first score for its banking sector’s quantum preparedness and set an aim for 2030. A day later, on 28 July, the Monetary Authority of Singapore (MAS) said milestones for financial institutions would follow before the end of 2026.
This article explains what each authority has issued, how much legal weight each document carries, and which dates have a countdown, as of October 2026. It is general information, not legal advice. The regional overview places both cities alongside other jurisdictions.
Singapore: Critical Infrastructure First
CSA’s Quantum-Safe Handbook, version 1, dated 16 July 2026, was produced with GovTech and the Infocomm Media Development Authority (IMDA). Most of it is practical guidance, but it also states three requirements for CII owners (Supervisory, as set out by CSA in the handbook):1
- by 31 March 2027, submit a quantum-safe migration plan to CSA;
- from 1 January 2028, newly procured and implemented CII systems with a digital component should support quantum-safe algorithms or be quantum-safe ready;
- by 31 December 2031, finish migrating CII systems away from quantum-vulnerable cryptography.
The handbook calls these requirements for CII owners, but it also describes itself as informational and not mandatory. That tension is why this article labels the milestones Supervisory rather than Binding: CSA has stated them as expectations, yet the document carrying them disclaims legal force.1
The 2028 procurement milestone is easy to miss and arguably the most practical. It means that from 2028, CII owners buying new systems need vendors who can show quantum-safe support or a credible path to it, which pushes the requirement into the supply chain years before the 2031 completion date. A migration plan due in March 2027 also presupposes that an owner knows where its cryptography is, so the handbook effectively makes a cryptographic inventory a 2026 task.
CSA has also announced (22 July 2026) that it will release an updated Cybersecurity Code of Practice for CII later in 2026 to address advanced persistent threats and AI-enabled threats; no effective dates were given.2
Singapore: The Financial Sector
MAS has several layers that touch cryptography.
Technology Risk Management Guidelines (Guidance, January 2021). Sections 10.1 and 10.2 cover cryptographic algorithms and key management. Institutions should use algorithms from well-established international standards, watch developments in cryptanalysis and change algorithms or key lengths when needed, and manage keys across their lifecycle.3 Quantum computing is not mentioned.
Notice FSM-N06 on Cyber Hygiene (Binding, effective 10 May 2024). It sets six requirements covering administrative accounts, patching, security standards, network perimeter, malware protection and multi-factor authentication. None of them is about cryptography.4
Circular MAS/TCRS/2024/01 (Supervisory, 20 February 2024). This quantum advisory lists measures institutions should consider. One is to identify and maintain an inventory of cryptographic solutions, recording the algorithm, key length, owner and system.5 The wording is advisory.
Supervisory expectations to come (Announcement). On 28 July 2026, MAS Managing Director Chia Der Jiun said MAS would issue supervisory expectations later in 2026, with milestones and timelines covering a cryptographic inventory, prioritisation of vulnerable assets, and governance. MAS wants institutions to “achieve quantum resilience before the end of this decade”.6 This review found no published expectations as of 7 October 2026, so no MAS date is in the tracker below.
- MAS Quantum Advisory
Circular MAS/TCRS/2024/01. Supervisory. Inventory of cryptographic solutions among measures to consider.
- CSA Quantum-Safe Handbook
Sets CII milestones. Supervisory.
- MAS Supervisory Expectations With MilestonesProposed
Announced 28 July 2026. Not yet issued.
- CII Migration Plans Due To CSAUpcoming
Supervisory.
- New CII Systems Quantum-Safe Or Quantum-Safe ReadyUpcoming
Supervisory.
- CII Migration CompleteUpcoming
Supervisory.
Hong Kong: Measure First
The HKMA took a different route. On 27 July 2026 it published a whitepaper and launched a Quantum Preparedness Index (QPI). The first score for the banking sector was 2.3 out of 10, which the HKMA described as an early stage of preparedness. Its stated aim is full sectoral readiness, a QPI of 10, by 2030 (Announcement).7 The same release said a post-quantum cryptography toolkit would be co-developed with the business school of the Hong Kong University of Science and Technology and the industry.
The whitepaper breaks the score down further. Retail banks scored higher than non-retail banks, and challenges around vendor readiness and engagement with vendors were among those banks most often placed in their top three. Asked what help they wanted, 87 percent of surveyed banks ranked clear supervisory expectations and timelines first.8 The release places the index under the HKMA’s Fintech Promotion Blueprint, and the whitepaper links the work to the quantum resilience objective in the HKMA’s Fintech 2030 strategy of November 2025 (Guidance).9
Deadlines To Watch
- Upcoming
Singapore · Cyber Security Agency of Singapore Supervisory
Submit a quantum-safe migration plan to CSA.
- Upcoming
Singapore · Cyber Security Agency of Singapore Supervisory
New CII systems procured and implemented should support quantum-safe algorithms or be quantum-safe ready.
- Upcoming
Hong Kong · Hong Kong Monetary Authority Announcement
Aim for full sectoral quantum readiness (a Quantum Preparedness Index score of 10, up from 2.3).
- Upcoming
Singapore · Cyber Security Agency of Singapore Supervisory
Complete migration to quantum-safe cryptography.
A Note On AI
MAS issued Guidelines on Artificial Intelligence Risk Management on 7 October 2026. They are supervisory expectations, taking effect on 7 October 2027, with sections 5 and 6 to be met by 7 October 2028.10 IMDA published a Model AI Governance Framework for Agentic AI in January 2026 (Guidance).11 This review found no AI-specific statute in Hong Kong. See AI regulation at a glance and AI Governance And Regulation for more.
Reading The Two Approaches Together
Singapore is setting dates and tying them to procurement, while Hong Kong is measuring readiness and publishing a score it can track over time. For a firm active in both, the common ground is the same starting task: a cryptographic inventory with owners and priorities. That is the item the 2024 MAS circular already lists and the item MAS has said its coming expectations will cover. The HKMA whitepaper starts its own recommendations one level higher, asking boards to treat quantum risk as an enterprise risk. Cryptography Compliance explains what such an inventory needs to contain.
Footnotes
-
Cyber Security Agency of Singapore, GovTech and IMDA, “Quantum-Safe Handbook V1”, 16 July 2026, page 25. isomer-user-content.by.gov.sg ↩ ↩2
-
Cyber Security Agency of Singapore, “Cybersecurity Code of Practice for Critical Information Infrastructure to be updated to address APT and AI-enabled threats”, 22 July 2026. csa.gov.sg ↩
-
Monetary Authority of Singapore, “Technology Risk Management Guidelines”, 18 January 2021, sections 10.1 and 10.2. mas.gov.sg ↩
-
Monetary Authority of Singapore, “Notice FSM-N06 Cyber Hygiene”, effective 10 May 2024. mas.gov.sg ↩
-
Monetary Authority of Singapore, Circular MAS/TCRS/2024/01, “Advisory on Addressing the Cybersecurity Risks Associated with Quantum”, 20 February 2024. mas.gov.sg ↩
-
Monetary Authority of Singapore, Managing Director’s remarks at the MAS Annual Report 2025/2026 media conference, 28 July 2026. mas.gov.sg ↩
-
Government of the Hong Kong SAR, press release on the HKMA Quantum Preparedness Index, 27 July 2026. info.gov.hk ↩
-
Hong Kong Monetary Authority, “Quantum Preparedness of Hong Kong’s Banking Sector” whitepaper, July 2026. hkma.gov.hk ↩
-
Government of the Hong Kong SAR, press release on HKMA “Fintech 2030”, 3 November 2025. info.gov.hk ↩
-
Monetary Authority of Singapore, “MAS sets out supervisory expectations on responsible AI adoption by financial institutions”, 7 October 2026. mas.gov.sg ↩
-
Infocomm Media Development Authority, “Singapore Launches New Model AI Governance Framework for Agentic AI”, 22 January 2026. imda.gov.sg ↩
Knowledge Hub content is general information. It is not legal advice, a compliance certification, a guarantee of security or a substitute for an assessment of your own systems. Standards and rules change; check the sources for the latest position.