Is Your Bank Ready for Quantum Computers? We Checked the World's 100 Largest

We scanned the homepages and online-banking logins of the S&P Global top 100 banks for hybrid ML-KEM key exchange. 59 homepages and 48 logins already negotiate X25519MLKEM768, but none of the 21 Chinese banks do, and 50 hosts are still stuck on TLS 1.2.

Type: Research Report
Published: October 2026
Keywords: Banking, Financial Sector, Post-Quantum TLS, X25519MLKEM768, ML-KEM, Hybrid Key Exchange, Harvest-Now-Decrypt-Later, Online Banking, CDN, TLS 1.3, Certificates, CipherScope

Abstract

Most of the world's largest banks already protect their customers' web connections against decryption by a future quantum computer, but often as a side-effect of their CDN, and less often on the online-banking login than on the homepage. On 5–6 October 2026 we checked the homepage and the retail online-banking login of each of the world's 100 largest banks, as ranked by S&P Global Market Intelligence,[1] for post-quantum key exchange, which stops traffic recorded today from being decrypted later ("harvest now, decrypt later"). 61 banks offer it on at least one of the two sites: 59 of 100 homepages and 48 of 97 online-banking logins negotiated the hybrid group X25519MLKEM768. Adoption follows geography and infrastructure, not size. Every bank headquartered in the United States, Japan, Canada, the United Kingdom and Brazil has it on at least one host; none of the 21 Chinese banks, none of the 5 South Korean banks and none of the 4 German banks does. The strongest predictor is the network that terminates the bank's TLS connection: 101 of 110 hosts behind Akamai, Cloudflare, AWS, Imperva, Azure and Azion negotiated hybrid ML-KEM, against 4 of 68 hosts served from banks' own or domestic networks. Fifty hosts still support only TLS 1.2, which cannot carry a post-quantum key exchange at all, and no host presented a post-quantum certificate. The technical background and our methodology (194 hosts, scanned with CipherScope from a single vantage point in Europe) follow the results, in Sections 9 and 10.

Key Points at a Glance

  • Six in ten of the largest banks are already post-quantum protected. 61 of the 100 banks negotiate hybrid ML-KEM key exchange on their homepage, their online-banking login or both: 59 of 100 homepages and 48 of 97 logins.
  • Mostly because their CDN switched it on. 92% of hosts behind Akamai, Cloudflare, AWS, Imperva, Azure and Azion negotiated PQC, versus 6% of hosts on banks' own or domestic networks and none behind Chinese CDNs or Google Cloud load balancers. Akamai switched hybrid key exchange on by default in August 2026.[2]
  • A geographic divide. All US, Japanese, Canadian, UK and Brazilian banks in the sample have PQC on at least one host; Chinese (0 of 21), South Korean (0 of 5), German (0 of 4) and Russian (0 of 2) banks have none.
  • The login is protected less often than the homepage. At 11 banks only the marketing homepage negotiates PQC while the online-banking login, where credentials and payment data actually flow, stays classical.
  • TLS 1.2 is the hard blocker. 50 of 194 hosts, including the online-banking logins of China's four largest banks, accept only TLS 1.2, which cannot carry a post-quantum key exchange.
  • Certificates are still classical. All observed certificates use RSA or ECDSA keys (82% RSA-2048); no ML-DSA or SLH-DSA certificate was seen.
  • What banks should do now. Switch on hybrid key exchange wherever the CDN already offers it, retire TLS 1.2-only servers, and protect the online-banking login first (Section 7).

Short on time? The Key Points above and Figure 1 below give the full picture. Sections 1–8 present the findings and what they mean for banks; Sections 9 and 10 explain the technical background and how we ran the scan. Every bank's individual result is in Appendix A.

1. Headline Results

We asked one question: when a customer opens their bank's website or online-banking login in a current browser, is the connection protected against harvest-now, decrypt-later attacks, in which traffic recorded today is decrypted once a large quantum computer exists? Every major browser already offers the hybrid post-quantum key exchange that provides this protection, so the answer depends only on whether the bank's server accepts it. Section 9 explains how it works.

Fifty-nine of the 100 bank homepages and 48 of the 97 online-banking logins selected X25519MLKEM768 when it was offered. In total, 105 of 194 hosts (54%) are protected against harvest-now, decrypt-later attacks for customers with a current browser, and 61 of the 100 banks offer that protection on at least one of the two hosts we tested.

Figure 1: Post-Quantum Key Exchange at the 100 Largest Banks (October 2026)
59/100
bank homepages negotiate hybrid ML-KEM
48/97
online-banking logins negotiate hybrid ML-KEM
61
banks with PQC on at least one of the two hosts
50
hosts still capped at TLS 1.2
0
post-quantum certificates observed
PQC key exchange on bank homepages and online-banking loginsHomepages: 59 PQC, 0 partly, 41 classical only, 0 undetermined of 100. Online banking: 48 PQC, 0 partly, 49 classical only of 97.Homepages – PQC negotiated: 59 of 100 (59%)Homepages – Classical only: 41 of 100 (41%)59%PQC observedHomepagesn = 100 hostsOnline-banking logins – PQC negotiated: 48 of 97 (49%)Online-banking logins – Classical only: 49 of 97 (51%)49%PQC observedOnline-banking loginsn = 97 hostsPQC negotiatedClassical onlyCentre value: share of hosts where ahybrid ML-KEM group was negotiatedon all (or some) tested addresses.

Share of hosts on which the server selected a hybrid ML-KEM group when one was offered. Hover over a segment for counts. Source: PostQuantumSecurity.org scan with CipherScope; sample: S&P Global 2026 ranking.[1]

The four largest banks in the world, all Chinese, are classical only on both hosts, as are Crédit Agricole (no. 9) and Postal Savings Bank of China (no. 10). JPMorgan Chase, Bank of America, BNP Paribas and HSBC, the rest of the top 10, negotiate hybrid ML-KEM on both their homepage and their online-banking login.

⚠️ What This Scan Can and Cannot Tell You

It is a snapshot from one place. Large banks serve customers through CDNs with regional points of presence, so results can differ by country, network and date. A host classed as "classical only" may be upgraded next week.

It sees only the first hop. When a CDN terminates TLS, our result describes the browser-to-CDN connection. The CDN-to-origin connection and the bank's internal systems are invisible to any external scan.

It is not a security rating. A classical-only result does not mean a bank's website is insecure today. It means the connection is not yet protected against future decryption of recorded traffic. Mobile banking apps, APIs and payment networks were not tested.

2. Homepage vs. Online-Banking Login

For a bank customer, the online-banking login matters more than the homepage: it is where passwords, account data and payment instructions travel. Yet the login is the less protected of the two. Among the 97 banks with both hosts, 46 protect both, 38 protect neither, 11 protect only the homepage and just 2 (Morgan Stanley and Intesa Sanpaolo) protect only the login.

The "homepage only" group includes Citigroup, Sumitomo Mitsui Financial Group, Société Générale, UBS, La Banque Postale, CaixaBank, OCBC, Erste Group, ABN AMRO, Nationwide and Nomura. The pattern is consistent: corporate websites tend to sit on a modern CDN, while the transactional banking platforms behind the login were often deployed separately, sometimes years earlier, on separate infrastructure. Several of those login hosts, including Citi's US retail site, SMBC Direct and UBS e-banking, accept only TLS 1.2.

Figure 2: Does PQC Protect the Homepage, the Login, or Both?
Bank-level combination of homepage and login PQCHomepage and login: 46; Homepage only: 11; Login only: 2; Neither: 38; undetermined: 0Online-banking loginPQC observedClassical onlyHomepagePQC observedClassical onlyHomepage and login: 46 of 97 banks46Homepage and loginHomepage only: 11 of 97 banks11Homepage onlyLogin only: 2 of 97 banks2Login onlyNeither: 38 of 97 banks38Neither97 banks with both a homepage and an online-banking login.

Each of the 97 banks with both a homepage and an online-banking login, placed by its two results. "PQC observed" means hybrid ML-KEM was negotiated on the host.

3. Regional and Size Differences

The regional picture is stark. All 12 US banks, all 8 Japanese, all 6 Canadian, all 6 British and all 4 Brazilian banks offer post-quantum TLS on at least one host, and most on both. At the other end, none of the 21 mainland Chinese banks negotiated hybrid ML-KEM on any of their 42 hosts, and 27 of those hosts accept only TLS 1.2. The five South Korean financial groups, the two Russian banks and the UAE's First Abu Dhabi Bank are likewise classical only.

Europe is divided. Spain, Italy, the Netherlands, Switzerland, Austria, Belgium, Denmark and Finland have PQC at every bank in the sample, and France at four of six. Germany has none: Deutsche Bank, DZ Bank, Commerzbank and LBBW all negotiate classical key exchange only. For German readers this is notable, as the BSI's technical guideline TR-02102-1 recommends deploying post-quantum key establishment in hybrid mode.[3]

Figure 3: Results by Headquarters Region (Homepage and Login Hosts)
PQC key exchange by regionChina: 0 of 42 hosts PQC; United States: 21 of 23 hosts PQC; Japan: 13 of 15 hosts PQC; Eurozone: 24 of 41 hosts PQC; United Kingdom: 11 of 12 hosts PQC; Canada: 12 of 12 hosts PQC; Other Europe: 5 of 12 hosts PQC; Asia-Pacific (other): 11 of 28 hosts PQC; Latin America: 8 of 8 hosts PQC; Middle East: 2 of 4 hosts PQCPQC negotiatedClassical onlyChina21 banksChina – Classical only: 42 of 42 (100%)420%United States12 banksUnited States – PQC negotiated: 21 of 23 (91%)21United States – Classical only: 2 of 23 (9%)291%Japan8 banksJapan – PQC negotiated: 13 of 15 (87%)13Japan – Classical only: 2 of 15 (13%)287%Eurozone21 banksEurozone – PQC negotiated: 24 of 41 (59%)24Eurozone – Classical only: 17 of 41 (41%)1759%United Kingdom6 banksUnited Kingdom – PQC negotiated: 11 of 12 (92%)11United Kingdom – Classical only: 1 of 12 (8%)192%Canada6 banksCanada – PQC negotiated: 12 of 12 (100%)12100%Other Europe6 banksOther Europe – PQC negotiated: 5 of 12 (42%)5Other Europe – Classical only: 7 of 12 (58%)742%Asia-Pacific (other)14 banksAsia-Pacific (other) – PQC negotiated: 11 of 28 (39%)11Asia-Pacific (other) – Classical only: 17 of 28 (61%)1739%Latin America4 banksLatin America – PQC negotiated: 8 of 8 (100%)8100%Middle East2 banksMiddle East – PQC negotiated: 2 of 4 (50%)2Middle East – Classical only: 2 of 4 (50%)250%

Bars show all scanned hosts of the banks in each region; the percentage is the share with PQC observed (including "Partly").

Show data table (hosts by region)
GroupPQC negotiatedPartly (some addresses)Classical onlyUndeterminedTotalPQC share
China00420420%
United States210202391%
Japan130201587%
Eurozone2401704159%
United Kingdom110101292%
Canada1200012100%
Other Europe50701242%
Asia-Pacific (other)1101702839%
Latin America80008100%
Middle East2020450%

Size, by contrast, hardly matters. Each quarter of the ranking has between 14 and 16 banks with PQC on at least one host. The largest banks are not ahead because the very top of the list is dominated by Chinese state-owned lenders, and the smaller banks are not behind because many of them buy the same CDN services as their larger peers.

Figure 4: Results by Asset Rank
PQC key exchange by asset rankRank 1–25: 28 of 50 hosts PQC; Rank 26–50: 27 of 50 hosts PQC; Rank 51–75: 28 of 48 hosts PQC; Rank 76–100: 24 of 49 hosts PQCPQC negotiatedClassical onlyRank 1–25$77.2T assetsRank 1–25 – PQC negotiated: 28 of 50 (56%)28Rank 1–25 – Classical only: 22 of 50 (44%)2256%Rank 26–50$28.3T assetsRank 26–50 – PQC negotiated: 27 of 50 (54%)27Rank 26–50 – Classical only: 23 of 50 (46%)2354%Rank 51–75$15.9T assetsRank 51–75 – PQC negotiated: 28 of 48 (58%)28Rank 51–75 – Classical only: 20 of 48 (42%)2058%Rank 76–100$11.2T assetsRank 76–100 – PQC negotiated: 24 of 49 (49%)24Rank 76–100 – Classical only: 25 of 49 (51%)2549%

Ranks and total assets from S&P Global Market Intelligence, April 2026.[1]

Show data table (hosts by asset rank)
GroupPQC negotiatedPartly (some addresses)Classical onlyUndeterminedTotalPQC share
Rank 1–252802205056%
Rank 26–502702305054%
Rank 51–752802004858%
Rank 76–1002402504949%

4. What Drives Adoption: The Edge Network

The clearest explanation for who has PQC is where the bank's TLS connection ends. Of 110 hosts served by the large Western CDN and cloud edge networks in our sample (Akamai, Cloudflare, AWS, Imperva, Microsoft Azure and Azion), 101 negotiated hybrid ML-KEM (92%). Of 68 hosts served from the banks' own address space or a domestic telecom provider, only 4 did (6%): the homepages and logins of Danske Bank and Raiffeisen Switzerland, which run hybrid key exchange on their own infrastructure. The 9 hosts on Wangsu/CDNetworks and 2 on Tencent EdgeOne, used by Chinese banks, and the 5 German and Swedish hosts on Google Cloud load balancers were all classical only.

Akamai alone fronts 73 of the 194 hosts, and 68 of them negotiated PQC. That is no coincidence: Akamai made hybrid X25519MLKEM768 available as an opt-in in 2025 and switched it on by default for client-to-edge connections on its Enhanced TLS network in August 2026, with an opt-out.[2][4] Cloudflare has negotiated the hybrid with supporting browsers by default for longer.[5] In other words, for many banks in our sample post-quantum TLS arrived as a side-effect of their CDN contract, not of a migration programme. Four of the five Akamai-fronted hosts without PQC accept only TLS 1.2 (Citi's retail site, Morgan Stanley's homepage, SMBC Direct and OCBC's internet banking); the fifth, ABN AMRO's Dutch retail site, negotiates TLS 1.3 with classical X25519.

Figure 5: Results by the Network Terminating TLS
PQC key exchange by edge network terminating TLSAkamai: 68 of 73 hosts PQC; Own / domestic network: 4 of 68 hosts PQC; Cloudflare: 12 of 15 hosts PQC; AWS: 9 of 10 hosts PQC; Wangsu / CDNetworks: 0 of 9 hosts PQC; Imperva: 8 of 8 hosts PQC; Google Cloud: 0 of 5 hosts PQC; Other cloud/CDN: 4 of 6 hosts PQCPQC negotiatedClassical onlyAkamai73 hostsAkamai – PQC negotiated: 68 of 73 (93%)68Akamai – Classical only: 5 of 73 (7%)93%Own / domestic network68 hostsOwn / domestic network – PQC negotiated: 4 of 68 (6%)Own / domestic network – Classical only: 64 of 68 (94%)646%Cloudflare15 hostsCloudflare – PQC negotiated: 12 of 15 (80%)12Cloudflare – Classical only: 3 of 15 (20%)380%AWS10 hostsAWS – PQC negotiated: 9 of 10 (90%)9AWS – Classical only: 1 of 10 (10%)190%Wangsu / CDNetworks9 hostsWangsu / CDNetworks – Classical only: 9 of 9 (100%)90%Imperva8 hostsImperva – PQC negotiated: 8 of 8 (100%)8100%Google Cloud5 hostsGoogle Cloud – Classical only: 5 of 5 (100%)50%Other cloud/CDN6 hostsOther cloud/CDN – PQC negotiated: 4 of 6 (67%)4Other cloud/CDN – Classical only: 2 of 6 (33%)267%

Edge network identified from the origin ASN of each host's IPv4 address and from CDN CNAME records. "Own / domestic network" means the bank's own address space or a domestic telecom provider. "Other cloud/CDN" combines Microsoft Azure, Azion and Tencent EdgeOne (two hosts each).

Show data table (hosts by edge network)
GroupPQC negotiatedPartly (some addresses)Classical onlyUndeterminedTotalPQC share
Akamai680507393%
Own / domestic network40640686%
Cloudflare120301580%
AWS90101090%
Wangsu / CDNetworks009090%
Imperva80008100%
Google Cloud005050%
Microsoft Azure20002100%
Tencent EdgeOne002020%
Azion20002100%

The TLS 1.2 blocker

Fifty of our 194 hosts accept only TLS 1.2, an older version of the protocol that cannot carry a post-quantum key exchange at all, whatever software or CDN sits behind it. Of these, 27 belong to Chinese banks, including the online-banking logins of all four of China's largest banks (ICBC, Agricultural Bank of China, China Construction Bank and Bank of China) and the homepages of China Construction Bank and Bank of China. For these banks, enabling TLS 1.3 is the necessary first step before post-quantum migration can even begin; Section 9 explains the technical reason.

The other 39 classical hosts already speak TLS 1.3 but chose X25519 (37) or P-256 (2) when hybrid groups were offered. For them, post-quantum key exchange is a software update or a configuration switch away.

5. The Authentication Gap: Certificates Are Still Classical

Key exchange is only half of TLS. The certificates that prove a site's identity are still entirely classical: of the 176 hosts on which we could read the certificate, 144 use RSA-2048 keys (82%), 20 ECDSA P-256 and 12 RSA-4096. No host presented an ML-DSA or SLH-DSA certificate, and none was expected. Post-quantum certificates are not yet issued for the public web, and the industry's preferred route for HTTPS, Merkle Tree Certificates, is still in its experimental phase, as we describe in our browser analysis.

This gap is less urgent than key exchange: a forged signature only helps an attacker at the time of the connection, so certificates must be post-quantum before a cryptographically relevant quantum computer exists, not before today's traffic is recorded. But banks' certificate estates, HSMs and trust chains take years to change, so planning has to start now.

Figure 6: Public-Key Algorithms of the Banks' TLS Certificates
Server certificate public-key algorithmsRSA-2048: 144; ECDSA P-256: 20; RSA-4096: 12; no post-quantum certificate observedRSA-2048RSA-2048: 144 of 176 hosts (82%)144 (82%)ECDSA P-256ECDSA P-256: 20 of 176 hosts (11%)20 (11%)RSA-4096RSA-4096: 12 of 176 hosts (7%)12 (7%)Leaf certificate key of 176 hosts. ML-DSA / SLH-DSA certificates: 0.

Leaf (server) certificate of each host on which a certificate was observed. No host presented an ML-DSA or SLH-DSA certificate.

6. The Regulatory Clock

Supervisors have stopped treating post-quantum migration as a research topic. The G7 Cyber Expert Group published a coordinated roadmap for the financial sector in January 2026. It recommends 2035 as the overall target for migration and suggests addressing the most critical systems in 2030–32. It also points out that data intercepted today may already be at risk.[6] In the EU, the Coordinated Implementation Roadmap adopted in June 2025 asks Member States to start transitioning by the end of 2026 and to move high-risk use cases, explicitly including finance, to PQC by the end of 2030.[7] NIST's draft transition plan, IR 8547, proposes to deprecate RSA and elliptic-curve key establishment and signatures after 2030 and to disallow them after 2035.[8] Europol's Quantum Safe Financial Forum has urged banks to treat the transition as a priority now, citing store-now-decrypt-later attacks.[9] In Germany, the BSI's TR-02102-1 recommends hybrid key establishment with ML-KEM, as our BSI compliance guide explains.[3]

Measured against those deadlines, hybrid TLS on public websites is the easy part: it is standardized, supported by every major browser and often only a configuration change away. That 39 of the 100 largest banks do not offer it on either their homepage or their login, with less than five years to the EU's 2030 target for high-risk use cases and the G7's suggested window for critical systems, shows how uneven the starting line is. For many banks that already have PQC, it was switched on by their CDN; their own transactional platforms, internal links and certificates remain to be migrated.

7. Recommendations for Banks

8. Bottom Line

Post-quantum key exchange already protects the websites of 59 of the world's 100 largest banks, mostly because their CDNs turned it on. The banks that run their own TLS, and the 50 hosts still on TLS 1.2, are where the work is.

Much of today's progress came with the infrastructure: two thirds of the PQC hosts we found sit on Akamai, which enabled hybrid key exchange by default only in August 2026. The next steps are less automatic: moving legacy TLS 1.2 endpoints to TLS 1.3, bringing online-banking platforms up to the level of the corporate homepage, extending hybrid key exchange to CDN-to-origin and internal connections, and preparing certificate infrastructure for ML-DSA. We plan to repeat this scan periodically to track progress.

Check Your Own Bank, or Your Own Domain

The results above are a point-in-time snapshot. To see what a bank, or your own organisation, negotiates today, scan the domain directly:

Scan a Domain with CipherScope →

9. Technical Background: Why Banks, and Why TLS?

This section and the next are for readers who want the technical background to the results above and the details of how the scan was run.

Banks hold exactly the kind of data that an attacker would want to record today and decrypt later: account credentials, payment instructions, identity documents and the details of customers' financial lives. Much of that data stays sensitive for years. This is the harvest-now, decrypt-later threat: traffic captured now is protected only by the key exchange that set up the session, and today's classical key exchanges (ECDHE with X25519 or NIST curves) can be broken by a large enough quantum computer.

TLS is the first and most visible place to fix this. The upgrade is a hybrid key exchange: the TLS 1.3 named group X25519MLKEM768 combines classical X25519 with ML-KEM-768, the module-lattice KEM that NIST standardized in FIPS 203.[11][12] The connection stays secure as long as either component holds. Every major browser already offers this group by default, as our browser comparison shows, so the deciding factor for a customer's connection is whether the bank's server accepts it.

That makes the server side measurable from the outside. A scan cannot see a bank's internal systems, but it can see what every customer's browser sees: which TLS version and key-exchange group the bank's public servers negotiate. That is the view this report measures, for the homepage and the online-banking login of each of the world's 100 largest banks.

Technical Detail: Why TLS 1.2 Rules Out Post-Quantum Key Exchange

The hybrid ML-KEM groups are defined only for TLS 1.3: a client sends the ML-KEM encapsulation key in the TLS 1.3 key_share extension, and the server answers with a ciphertext.[10][12] TLS 1.2 has no equivalent mechanism, so a server that tops out at TLS 1.2 cannot offer post-quantum key exchange regardless of its software or CDN.

50 of our 194 hosts are in that position (Section 4). Many of these servers also lack RFC 5746 secure renegotiation,[13] a 2010 fix that modern TLS libraries now require by default.

10. Methodology

Sample

The sample is S&P Global Market Intelligence's ranking The world's largest banks by assets, 2026, published 29 April 2026. Most total assets in it are as of 31 December 2025.[1] The 100 banks hold about US$133 trillion in assets and are headquartered in 24 countries. Mainland China accounts for 21 of them, the United States for 12 and Japan for 8.

For each bank we scanned up to two hostnames:

That gives 194 unique hosts: 100 homepages and 97 online-banking logins. The full list, including every hostname, is in Appendix A.

Scanner and procedure

Every host was scanned with CipherScope, our public post-quantum readiness scanner,[14] using OpenSSL 3.6 as the TLS probe. The Standard profile opens a normal TLS connection and then a handshake that offers hybrid groups first (X25519MLKEM768, SecP256r1MLKEM768, SecP384r1MLKEM1024) alongside classical fallbacks, exactly as a modern browser would. It records the group the server actually chooses. Hosts with a post-quantum result were then re-checked with the Deep profile (with six exceptions, see below), which samples up to four IPv4 and four IPv6 addresses, tests each hybrid group separately and confirms classical fallback.

Each host receives one of four results:

ResultMeaning
PQC negotiatedThe server selected a standardized hybrid ML-KEM group on every tested address.
PartlySome tested addresses negotiated hybrid ML-KEM, others classical key exchange. This is typical of a rollout in progress or of mixed load balancers.
Classical onlyThe server chose a classical group (e.g. X25519 or P-256) although hybrid groups were offered, or the server supports only TLS 1.2, which cannot carry ML-KEM groups at all.
UndeterminedNo handshake could be completed from our vantage point (blocking, timeouts or geofencing). These hosts are reported, but not counted as either result.

For 53 hosts CipherScope's TLS stack could not complete a handshake. In nearly all cases the reason was not a network block but an old server configuration: a server limited to TLS 1.2, or one that does not implement the secure renegotiation extension of RFC 5746, which OpenSSL 3 refuses by default.[13] We resolved these hosts with a supplementary OpenSSL 3.6 handshake that offers the same hybrid groups first but tolerates legacy renegotiation. All 53 completed: 50 negotiated TLS 1.2 and 3 negotiated TLS 1.3 with a classical group. All of them are therefore reported as classical only, and are marked * in the appendix. As a cross-check, we repeated the same independent OpenSSL handshake on a random sample of 12 hosts that CipherScope had classified itself (6 PQC, 6 classical only). All 12 matched. Because of the scanner's daily limit, 100 hosts received the Deep re-check (every PQC-positive login and all PQC-positive homepages except the six lowest-ranked ones, which keep their Standard result). Every Deep re-check confirmed the result on all sampled addresses, so no host fell into the "Partly" category, and after the supplementary handshake none remained undetermined.

We also recorded the leaf certificate's public-key algorithm, and identified the network that terminates each TLS connection. For the latter we looked up the origin autonomous system (ASN) of the host's IPv4 address via Team Cymru's IP-to-ASN service,[15] using CNAME records where a CDN runs inside third-party address space. The scans ran on 5–6 October 2026 from a single vantage point in Europe.

Additional observations

All 105 PQC hosts chose X25519MLKEM768, the group browsers prefer. The Deep scan also offered each hybrid group on its own: 10 of the 99 PQC hosts it covered additionally accept SecP256r1MLKEM768, the NIST-curve variant,[12] and none accepted SecP384r1MLKEM1024.

A secondary check of the banks' public mail servers (MX hosts of the homepage domain, via STARTTLS) shows that post-quantum protection has barely reached e-mail: only BBVA's mail servers negotiated hybrid ML-KEM on all tested addresses and Nationwide's on some. Many mail servers could not be assessed from our vantage point, so we do not report a percentage.

Further Reading

For how the hybrid key exchange that protects these connections works, and why it combines a classical and a post-quantum component, read our technical analysis:

Read: X25519+ML-KEM-768 Hybrid Key Exchange →

Appendix A: Results for All 100 Banks

Ranked by total assets (S&P Global, April 2026).[1] The group shown is the key-exchange group the server selected when hybrid groups were offered first. Results marked * were resolved with the supplementary OpenSSL handshake described in Section 10. Results reflect our scans on 5–6 October 2026 and may have changed since.

#BankHQAssets (US$B)Homepage hostHomepage resultOnline-banking hostLogin result
1Industrial and Commercial Bank of China Ltd.Mainland China7,646www.icbc.com.cnClassical onlyX25519mybank.icbc.com.cnClassical onlyTLS 1.2 only *
2Agricultural Bank of China Ltd.Mainland China6,975www.abchina.comClassical onlyX25519perbank.abchina.com.cnClassical onlyTLS 1.2 only *
3China Construction Bank Corp.Mainland China6,524www.ccb.comClassical onlyTLS 1.2 only *ibsbjstar.ccb.com.cnClassical onlyTLS 1.2 only *
4Bank of China Ltd.Mainland China5,484www.boc.cnClassical onlyTLS 1.2 only *ebsnew.boc.cnClassical onlyTLS 1.2 only *
5JPMorgan Chase & Co.US4,425www.jpmorganchase.comPQC negotiatedX25519MLKEM768secure.chase.comPQC negotiatedX25519MLKEM768
6Bank of America Corp.US3,412www.bankofamerica.comPQC negotiatedX25519MLKEM768secure.bankofamerica.comPQC negotiatedX25519MLKEM768
7BNP Paribas SAFrance3,279group.bnpparibasPQC negotiatedX25519MLKEM768mabanque.bnpparibasPQC negotiatedX25519MLKEM768
8HSBC Holdings PLCUK3,212www.hsbc.comPQC negotiatedX25519MLKEM768www.hsbc.co.ukPQC negotiatedX25519MLKEM768
9Crédit Agricole GroupFrance3,149www.credit-agricole.comClassical onlyX25519www.credit-agricole.frClassical onlyTLS 1.2 only *
10Postal Savings Bank of China Co. Ltd.Mainland China2,671www.psbc.comClassical onlyX25519pbank.psbc.comClassical onlyTLS 1.2 only *
11Mitsubishi UFJ Financial Group Inc.Japan2,667www.mufg.jpPQC negotiatedX25519MLKEM768directg.s.bk.mufg.jpPQC negotiatedX25519MLKEM768
12Citigroup Inc.US2,622www.citigroup.comPQC negotiatedX25519MLKEM768www.citi.comClassical onlyTLS 1.2 only *
13Banco Santander SASpain2,252www.santander.comPQC negotiatedX25519MLKEM768particulares.bancosantander.esPQC negotiatedX25519MLKEM768
14Bank of Communications Co. Ltd.Mainland China2,223www.bankcomm.comClassical onlyTLS 1.2 only *pbank.95559.com.cnClassical onlyTLS 1.2 only *
15Wells Fargo & Co.US2,149www.wellsfargo.comPQC negotiatedX25519MLKEM768connect.secure.wellsfargo.comPQC negotiatedX25519MLKEM768
16Barclays PLCUK2,078home.barclaysPQC negotiatedX25519MLKEM768bank.barclays.co.ukPQC negotiatedX25519MLKEM768
17Sumitomo Mitsui Financial Group Inc.Japan2,020www.smfg.co.jpPQC negotiatedX25519MLKEM768direct.smbc.co.jpClassical onlyTLS 1.2 only *
18Groupe BPCEFrance1,987www.groupebpce.comPQC negotiatedX25519MLKEM768www.caisse-epargne.frPQC negotiatedX25519MLKEM768
19Mizuho Financial Group Inc.Japan1,898www.mizuhogroup.comPQC negotiatedX25519MLKEM768web.ib.mizuhobank.co.jpPQC negotiatedX25519MLKEM768
20China Merchants Bank Co. Ltd.Mainland China1,869www.cmbchina.comClassical onlyTLS 1.2 only *pbsz.ebank.cmbchina.comClassical onlyTLS 1.2 only *
21Société Générale SAFrance1,813www.societegenerale.comPQC negotiatedX25519MLKEM768particuliers.sg.frClassical onlysecp256r1 *
22Goldman Sachs Group Inc.US1,809www.goldmansachs.comPQC negotiatedX25519MLKEM768www.marcus.comPQC negotiatedX25519MLKEM768
23Royal Bank of CanadaCanada1,727www.rbc.comPQC negotiatedX25519MLKEM768secure.royalbank.comPQC negotiatedX25519MLKEM768
24Deutsche Bank AGGermany1,685www.db.comClassical onlyX25519meine.deutsche-bank.deClassical onlyX25519
25UBS Group AGSwitzerland1,617www.ubs.comPQC negotiatedX25519MLKEM768ebanking-ch.ubs.comClassical onlyTLS 1.2 only *
26Industrial Bank Co. Ltd.Mainland China1,586www.cib.com.cnClassical onlyX25519personalbank.cib.com.cnClassical onlyX25519
27Toronto-Dominion BankCanada1,548www.td.comPQC negotiatedX25519MLKEM768easyweb.td.comPQC negotiatedX25519MLKEM768
28Japan Post Bank Co. Ltd.Japan1,451www.jp-bank.japanpost.jpPQC negotiatedX25519MLKEM768direct1.jp-bank.japanpost.jpPQC negotiatedX25519MLKEM768
29China Citic Bank Corp. Ltd.Mainland China1,448www.citicbank.comClassical onlyX25519i.bank.ecitic.comClassical onlyX25519
30Crédit Mutuel GroupFrance1,442www.creditmutuel.frClassical onlyTLS 1.2 only *www.creditmutuel.fr (same host)Classical onlyTLS 1.2 only *
31Shanghai Pudong Development Bank Co. Ltd.Mainland China1,441www.spdb.com.cnClassical onlyTLS 1.2 only *ebank.spdb.com.cnClassical onlyTLS 1.2 only *
32Morgan StanleyUS1,420www.morganstanley.comClassical onlyTLS 1.2 only *login.morganstanleyclientserv.comPQC negotiatedX25519MLKEM768
33Lloyds Banking Group PLCUK1,271www.lloydsbankinggroup.comPQC negotiatedX25519MLKEM768online.lloydsbank.co.ukPQC negotiatedX25519MLKEM768
34ING Groep NVNetherlands1,238www.ing.comPQC negotiatedX25519MLKEM768mijn.ing.nlPQC negotiatedX25519MLKEM768
35Intesa Sanpaolo SpAItaly1,127group.intesasanpaolo.comClassical onlyX25519www.intesasanpaolo.comPQC negotiatedX25519MLKEM768
36China Minsheng Banking Corp. Ltd.Mainland China1,120www.cmbc.com.cnClassical onlyX25519nper.cmbc.com.cnClassical onlyTLS 1.2 only *
37Bank of Nova ScotiaCanada1,088www.scotiabank.comPQC negotiatedX25519MLKEM768auth.scotiaonline.scotiabank.comPQC negotiatedX25519MLKEM768
38Bank of MontrealCanada1,070www.bmo.comPQC negotiatedX25519MLKEM768www1.bmo.comPQC negotiatedX25519MLKEM768
39China Everbright Bank Co. Ltd.Mainland China1,024www.cebbank.comClassical onlyTLS 1.2 only *e.cebbank.comClassical onlyTLS 1.2 only *
40UniCredit SpAItaly1,022www.unicreditgroup.euPQC negotiatedX25519MLKEM768www.unicredit.itPQC negotiatedX25519MLKEM768
41Banco Bilbao Vizcaya Argentaria SASpain1,006www.bbva.comPQC negotiatedX25519MLKEM768web.bbva.esPQC negotiatedX25519MLKEM768
42NatWest Group PLCUK962www.natwestgroup.comPQC negotiatedX25519MLKEM768www.onlinebanking.natwest.comPQC negotiatedX25519MLKEM768
43Commonwealth Bank of AustraliaAustralia940www.commbank.com.auClassical onlyTLS 1.2 only *www.my.commbank.com.auClassical onlyTLS 1.2 only *
44Standard Chartered PLCUK920www.sc.comPQC negotiatedX25519MLKEM768retail.sc.comPQC negotiatedX25519MLKEM768
45State Bank of IndiaIndia877sbi.co.inClassical onlyX25519retail.onlinesbi.sbiClassical onlyX25519
46Sberbank of RussiaRussia870www.sberbank.comClassical onlysecp256r1 *online.sberbank.ruClassical onlyTLS 1.2 only *
47ANZ Group Holdings Ltd.Australia858www.anz.comPQC negotiatedX25519MLKEM768login.anz.comPQC negotiatedX25519MLKEM768
48La Banque Postale SAFrance852www.labanquepostale.frPQC negotiatedX25519MLKEM768voscomptesenligne.labanquepostale.frClassical onlyX25519
49Ping An Bank Co. Ltd.Mainland China847bank.pingan.comClassical onlyX25519ebank.pingan.com.cnClassical onlyTLS 1.2 only *
50Canadian Imperial Bank of CommerceCanada835www.cibc.comPQC negotiatedX25519MLKEM768www.cibconline.cibc.comPQC negotiatedX25519MLKEM768
51CaixaBank SASpain780www.caixabank.comPQC negotiatedX25519MLKEM768loc6.caixabank.esClassical onlyTLS 1.2 only *
52DZ Bank AGGermany777www.dzbank.deClassical onlyX25519No retail online banking
53Nordea Bank AbpFinland768www.nordea.comPQC negotiatedX25519MLKEM768netbank.nordea.fiPQC negotiatedX25519MLKEM768
54RabobankNetherlands750www.rabobank.comPQC negotiatedX25519MLKEM768bankieren.rabobank.nlPQC negotiatedX25519MLKEM768
55Westpac Banking Corp.Australia744www.westpac.com.auPQC negotiatedX25519MLKEM768banking.westpac.com.auPQC negotiatedX25519MLKEM768
56National Australia Bank Ltd.Australia734www.nab.com.auPQC negotiatedX25519MLKEM768ib.nab.com.auPQC negotiatedX25519MLKEM768
57DBS Group Holdings Ltd.Singapore698www.dbs.comPQC negotiatedX25519MLKEM768internet-banking.dbs.com.sgPQC negotiatedX25519MLKEM768
58Commerzbank AGGermany693www.commerzbank.deClassical onlyX25519kunden.commerzbank.deClassical onlyX25519
59U.S. BancorpUS692www.usbank.comPQC negotiatedX25519MLKEM768onlinebanking.usbank.comPQC negotiatedX25519MLKEM768
60Bank of Jiangsu Co. Ltd.Mainland China692www.jsbchina.cnClassical onlyX25519ebank.jsbchina.cnClassical onlyX25519
61Bank of Beijing Co. Ltd.Mainland China687www.bankofbeijing.com.cnClassical onlyTLS 1.2 only *ebank.bankofbeijing.com.cnClassical onlyTLS 1.2 only *
62Hua Xia Bank Co. Ltd.Mainland China677www.hxb.com.cnClassical onlyX25519 *psbank.hxb.com.cnClassical onlyTLS 1.2 only *
63Capital One Financial Corp.US669www.capitalone.comPQC negotiatedX25519MLKEM768verified.capitalone.comPQC negotiatedX25519MLKEM768
64PNC Financial Services Group Inc.US600www.pnc.comPQC negotiatedX25519MLKEM768www.onlinebanking.pnc.comPQC negotiatedX25519MLKEM768
65Danske Bank A/SDenmark590danskebank.comPQC negotiatedX25519MLKEM768netbank.danskebank.dkPQC negotiatedX25519MLKEM768
66Itaú Unibanco Holding SABrazil562www.itau.com.brPQC negotiatedX25519MLKEM768www.itau.com.br (same host)PQC negotiatedX25519MLKEM768
67KB Financial Group Inc.South Korea553www.kbfg.comClassical onlyTLS 1.2 only *obank.kbstar.comClassical onlyTLS 1.2 only *
68Truist Financial Corp.US548www.truist.comPQC negotiatedX25519MLKEM768dias.bank.truist.comPQC negotiatedX25519MLKEM768
69Shinhan Financial Group Co. Ltd.South Korea545www.shinhangroup.comClassical onlyX25519bank.shinhan.comClassical onlyTLS 1.2 only *
70Norinchukin BankJapan542www.nochubank.or.jpPQC negotiatedX25519MLKEM768No retail online banking
71Oversea-Chinese Banking Corp. Ltd.Singapore525www.ocbc.comPQC negotiatedX25519MLKEM768internet.ocbc.comClassical onlyTLS 1.2 only *
72Sumitomo Mitsui Trust Group Inc.Japan522www.smtg.jpPQC negotiatedX25519MLKEM768direct.smtb.jpPQC negotiatedX25519MLKEM768
73Bank of Ningbo Co. Ltd.Mainland China519www.nbcb.com.cnClassical onlyX25519e.nbcb.com.cnClassical onlyTLS 1.2 only *
74Erste Group Bank AGAustria518www.erstegroup.comPQC negotiatedX25519MLKEM768george.sparkasse.atClassical onlyX25519
75China Guangfa Bank Co. Ltd.Mainland China515www.cgbchina.com.cnClassical onlyX25519ebanks.cgbchina.com.cnClassical onlyTLS 1.2 only *
76HDFC Bank Ltd.India515www.hdfcbank.comPQC negotiatedX25519MLKEM768netbanking.hdfcbank.comPQC negotiatedX25519MLKEM768
77ABN AMRO Bank NVNetherlands511www.abnamro.comPQC negotiatedX25519MLKEM768www.abnamro.nlClassical onlyX25519
78Nationwide Building SocietyUK507www.nationwide.co.ukPQC negotiatedX25519MLKEM768onlinebanking.nationwide.co.ukClassical onlyX25519
79China Zheshang Bank Co. Ltd.Mainland China498www.czbank.comClassical onlyX25519perbank.czbank.comClassical onlyTLS 1.2 only *
80Resona Holdings Inc.Japan495www.resona-gr.co.jpPQC negotiatedX25519MLKEM768ib.resonabank.co.jpPQC negotiatedX25519MLKEM768
81Charles Schwab Corp.US491www.schwab.comPQC negotiatedX25519MLKEM768client.schwab.comPQC negotiatedX25519MLKEM768
82Bank of Shanghai Co. Ltd.Mainland China473www.bosc.cnClassical onlyTLS 1.2 only *ebanks.bankofshanghai.comClassical onlyTLS 1.2 only *
83Bank of New York Mellon Corp.US472www.bny.comPQC negotiatedX25519MLKEM768No retail online banking
84KBC Group NVBelgium472www.kbc.comPQC negotiatedX25519MLKEM768www.kbc.bePQC negotiatedX25519MLKEM768
85Hana Financial Group Inc.South Korea467www.hanafn.comClassical onlyX25519www.kebhana.comClassical onlyTLS 1.2 only *
86VTB Bank PJSCRussia466www.vtb.ruClassical onlyX25519online.vtb.ruClassical onlyTLS 1.2 only *
87National Bank of CanadaCanada447www.nbc.caPQC negotiatedX25519MLKEM768app.bnc.caPQC negotiatedX25519MLKEM768
88Banco do Brasil SABrazil445www.bb.com.brPQC negotiatedX25519MLKEM768autoatendimento.bb.com.brPQC negotiatedX25519MLKEM768
89United Overseas Bank Ltd.Singapore445www.uobgroup.comClassical onlyTLS 1.2 only *pib.uob.com.sgClassical onlyTLS 1.2 only *
90Bank of Nanjing Co. Ltd.Mainland China432www.njcb.com.cnClassical onlyTLS 1.2 only *ebank.njcb.com.cnClassical onlyTLS 1.2 only *
91Banco Bradesco SABrazil419banco.bradescoPQC negotiatedX25519MLKEM768banco.bradesco (same host)PQC negotiatedX25519MLKEM768
92NongHyup Financial Group Inc.South Korea418www.nonghyup.comClassical onlyTLS 1.2 only *banking.nonghyup.comClassical onlyTLS 1.2 only *
93Woori Financial Group Inc.South Korea417www.woorifg.comClassical onlyTLS 1.2 only *spib.wooribank.comClassical onlyTLS 1.2 only *
94Landesbank Baden-WürttembergGermany408www.lbbw.deClassical onlyX25519www.bw-bank.deClassical onlyX25519
95Raiffeisen Gruppe SwitzerlandSwitzerland407www.raiffeisen.chPQC negotiatedX25519MLKEM768ebanking.raiffeisen.chPQC negotiatedX25519MLKEM768
96Caixa Econômica FederalBrazil404www.caixa.gov.brPQC negotiatedX25519MLKEM768internetbanking.caixa.gov.brPQC negotiatedX25519MLKEM768
97Skandinaviska Enskilda Banken AB (publ)Sweden398sebgroup.comClassical onlyX25519id.seb.seClassical onlyX25519
98Nomura Holdings Inc.Japan395www.nomuraholdings.comPQC negotiatedX25519MLKEM768hometrade.nomura.co.jpClassical onlyX25519
99First Abu Dhabi Bank PJSCUAE382www.bankfab.comClassical onlyX25519online.bankfab.comClassical onlyTLS 1.2 only *
100Qatar National Bank (QPSC)Qatar382www.qnb.comPQC negotiatedX25519MLKEM768ib.qnb.comPQC negotiatedX25519MLKEM768

How to Cite This Report

APA: PostQuantumSecurity.org. (2026, October 6). Is Your Bank Ready for Quantum Computers? We Checked the World's 100 Largest. https://www.postquantumsecurity.org/publications/top100banks-pqc-report.html

IEEE: PostQuantumSecurity.org, "Is Your Bank Ready for Quantum Computers? We Checked the World's 100 Largest," Oct. 6, 2026. [Online]. Available: https://www.postquantumsecurity.org/publications/top100banks-pqc-report.html

LaTeX/BibTeX:

@misc{pqcryptography_top100banks_pqc,
  author       = {{PostQuantumSecurity.org}},
  title        = {Is Your Bank Ready for Quantum Computers? We Checked the World's 100 Largest},
  year         = {2026},
  month        = oct,
  day          = {6},
  url          = {https://www.postquantumsecurity.org/publications/top100banks-pqc-report.html}
}

References

  1. Jimenea, A., & Lozano, C. (2026, April 29). The world's largest banks by assets, 2026. S&P Global Market Intelligence. https://www.spglobal.com/market-intelligence/en/news-insights/research/2026/04/the-worlds-largest-banks-by-assets-2026
  2. Daffron, T. (2026, August). Future-Proofing the Internet: Akamai Achieves End-to-End PQC. Akamai Blog. https://www.akamai.com/blog/security/2026/aug/future-proofing-internet-akamai-achieves-end-to-end-pqc
  3. Federal Office for Information Security (BSI). (2026). Technical Guideline TR-02102-1: Cryptographic Mechanisms: Recommendations and Key Lengths, Version 2026-01. PDF copy
  4. Akamai. (2025, September 3). Akamai Enables Post-Quantum Cryptography on the Edge. Akamai Blog. https://www.akamai.com/blog/security/2025/aug/akamai-enables-post-quantum-cryptography-edge
  5. Cloudflare. (2026). Post-quantum cryptography (PQC). Cloudflare SSL/TLS documentation. https://developers.cloudflare.com/ssl/post-quantum-cryptography/
  6. G7 Cyber Expert Group. (2026, January). Statement on Advancing a Coordinated Roadmap for the Transition to Post-Quantum Cryptography in the Financial Sector. https://www.gov.uk/government/publications/advancing-a-coordinated-roadmap-for-the-transition-to-post-quantum-cryptography-in-the-financial-sector
  7. European Commission & NIS Cooperation Group. (2025, June 23). A Coordinated Implementation Roadmap for the Transition to Post-Quantum Cryptography. https://digital-strategy.ec.europa.eu/en/library/coordinated-implementation-roadmap-transition-post-quantum-cryptography
  8. Moody, D., Perlner, R., Regenscheid, A., Robinson, A., & Cooper, D. (2024, November 12). NIST IR 8547 (Initial Public Draft): Transition to Post-Quantum Cryptography Standards. https://csrc.nist.gov/pubs/ir/8547/ipd
  9. Europol. (2025, February 7). Call for action: urgent plan needed to transition to post-quantum cryptography together. https://www.europol.europa.eu/media-press/newsroom/news/call-for-action-urgent-plan-needed-to-transition-to-post-quantum-cryptography-together
  10. Rescorla, E. (2018). RFC 8446: The Transport Layer Security (TLS) Protocol Version 1.3. IETF. https://www.rfc-editor.org/rfc/rfc8446
  11. National Institute of Standards and Technology. (2024). FIPS 203: Module-Lattice-Based Key-Encapsulation Mechanism Standard. https://csrc.nist.gov/pubs/fips/203/final
  12. Kwiatkowski, K., Kampanakis, P., Westerbaan, B., & Stebila, D. Post-quantum hybrid ECDHE-MLKEM Key Agreement for TLSv1.3. IETF Internet-Draft draft-ietf-tls-ecdhe-mlkem. https://datatracker.ietf.org/doc/draft-ietf-tls-ecdhe-mlkem/
  13. Rescorla, E., Ray, M., Dispensa, S., & Oskov, N. (2010). RFC 5746: Transport Layer Security (TLS) Renegotiation Indication Extension. IETF. https://www.rfc-editor.org/rfc/rfc5746
  14. HybridCipher. (2026). CipherScope: Public PQC Readiness Scanner. https://cipherscope.hybridcipher.com/
  15. Team Cymru. IP to ASN Mapping Service. https://www.team-cymru.com/ip-asn-mapping