Abstract
X25519MLKEM768. Adoption follows geography and infrastructure, not size. Every bank headquartered in the United States, Japan, Canada, the United Kingdom and Brazil has it on at least one host; none of the 21 Chinese banks, none of the 5 South Korean banks and none of the 4 German banks does. The strongest predictor is the network that terminates the bank's TLS connection: 101 of 110 hosts behind Akamai, Cloudflare, AWS, Imperva, Azure and Azion negotiated hybrid ML-KEM, against 4 of 68 hosts served from banks' own or domestic networks. Fifty hosts still support only TLS 1.2, which cannot carry a post-quantum key exchange at all, and no host presented a post-quantum certificate. The technical background and our methodology (194 hosts, scanned with CipherScope from a single vantage point in Europe) follow the results, in Sections 9 and 10.
Key Points at a Glance
- Six in ten of the largest banks are already post-quantum protected. 61 of the 100 banks negotiate hybrid ML-KEM key exchange on their homepage, their online-banking login or both: 59 of 100 homepages and 48 of 97 logins.
- Mostly because their CDN switched it on. 92% of hosts behind Akamai, Cloudflare, AWS, Imperva, Azure and Azion negotiated PQC, versus 6% of hosts on banks' own or domestic networks and none behind Chinese CDNs or Google Cloud load balancers. Akamai switched hybrid key exchange on by default in August 2026.[2]
- A geographic divide. All US, Japanese, Canadian, UK and Brazilian banks in the sample have PQC on at least one host; Chinese (0 of 21), South Korean (0 of 5), German (0 of 4) and Russian (0 of 2) banks have none.
- The login is protected less often than the homepage. At 11 banks only the marketing homepage negotiates PQC while the online-banking login, where credentials and payment data actually flow, stays classical.
- TLS 1.2 is the hard blocker. 50 of 194 hosts, including the online-banking logins of China's four largest banks, accept only TLS 1.2, which cannot carry a post-quantum key exchange.
- Certificates are still classical. All observed certificates use RSA or ECDSA keys (82% RSA-2048); no ML-DSA or SLH-DSA certificate was seen.
- What banks should do now. Switch on hybrid key exchange wherever the CDN already offers it, retire TLS 1.2-only servers, and protect the online-banking login first (Section 7).
Short on time? The Key Points above and Figure 1 below give the full picture. Sections 1–8 present the findings and what they mean for banks; Sections 9 and 10 explain the technical background and how we ran the scan. Every bank's individual result is in Appendix A.
1. Headline Results
We asked one question: when a customer opens their bank's website or online-banking login in a current browser, is the connection protected against harvest-now, decrypt-later attacks, in which traffic recorded today is decrypted once a large quantum computer exists? Every major browser already offers the hybrid post-quantum key exchange that provides this protection, so the answer depends only on whether the bank's server accepts it. Section 9 explains how it works.
Fifty-nine of the 100 bank homepages and 48 of the 97 online-banking logins selected X25519MLKEM768 when it was offered. In total, 105 of 194 hosts (54%) are protected against harvest-now, decrypt-later attacks for customers with a current browser, and 61 of the 100 banks offer that protection on at least one of the two hosts we tested.
Share of hosts on which the server selected a hybrid ML-KEM group when one was offered. Hover over a segment for counts. Source: PostQuantumSecurity.org scan with CipherScope; sample: S&P Global 2026 ranking.[1]
The four largest banks in the world, all Chinese, are classical only on both hosts, as are Crédit Agricole (no. 9) and Postal Savings Bank of China (no. 10). JPMorgan Chase, Bank of America, BNP Paribas and HSBC, the rest of the top 10, negotiate hybrid ML-KEM on both their homepage and their online-banking login.
⚠️ What This Scan Can and Cannot Tell You
It is a snapshot from one place. Large banks serve customers through CDNs with regional points of presence, so results can differ by country, network and date. A host classed as "classical only" may be upgraded next week.
It sees only the first hop. When a CDN terminates TLS, our result describes the browser-to-CDN connection. The CDN-to-origin connection and the bank's internal systems are invisible to any external scan.
It is not a security rating. A classical-only result does not mean a bank's website is insecure today. It means the connection is not yet protected against future decryption of recorded traffic. Mobile banking apps, APIs and payment networks were not tested.
2. Homepage vs. Online-Banking Login
For a bank customer, the online-banking login matters more than the homepage: it is where passwords, account data and payment instructions travel. Yet the login is the less protected of the two. Among the 97 banks with both hosts, 46 protect both, 38 protect neither, 11 protect only the homepage and just 2 (Morgan Stanley and Intesa Sanpaolo) protect only the login.
The "homepage only" group includes Citigroup, Sumitomo Mitsui Financial Group, Société Générale, UBS, La Banque Postale, CaixaBank, OCBC, Erste Group, ABN AMRO, Nationwide and Nomura. The pattern is consistent: corporate websites tend to sit on a modern CDN, while the transactional banking platforms behind the login were often deployed separately, sometimes years earlier, on separate infrastructure. Several of those login hosts, including Citi's US retail site, SMBC Direct and UBS e-banking, accept only TLS 1.2.
Each of the 97 banks with both a homepage and an online-banking login, placed by its two results. "PQC observed" means hybrid ML-KEM was negotiated on the host.
3. Regional and Size Differences
The regional picture is stark. All 12 US banks, all 8 Japanese, all 6 Canadian, all 6 British and all 4 Brazilian banks offer post-quantum TLS on at least one host, and most on both. At the other end, none of the 21 mainland Chinese banks negotiated hybrid ML-KEM on any of their 42 hosts, and 27 of those hosts accept only TLS 1.2. The five South Korean financial groups, the two Russian banks and the UAE's First Abu Dhabi Bank are likewise classical only.
Europe is divided. Spain, Italy, the Netherlands, Switzerland, Austria, Belgium, Denmark and Finland have PQC at every bank in the sample, and France at four of six. Germany has none: Deutsche Bank, DZ Bank, Commerzbank and LBBW all negotiate classical key exchange only. For German readers this is notable, as the BSI's technical guideline TR-02102-1 recommends deploying post-quantum key establishment in hybrid mode.[3]
Bars show all scanned hosts of the banks in each region; the percentage is the share with PQC observed (including "Partly").
Show data table (hosts by region)
| Group | PQC negotiated | Partly (some addresses) | Classical only | Undetermined | Total | PQC share |
|---|---|---|---|---|---|---|
| China | 0 | 0 | 42 | 0 | 42 | 0% |
| United States | 21 | 0 | 2 | 0 | 23 | 91% |
| Japan | 13 | 0 | 2 | 0 | 15 | 87% |
| Eurozone | 24 | 0 | 17 | 0 | 41 | 59% |
| United Kingdom | 11 | 0 | 1 | 0 | 12 | 92% |
| Canada | 12 | 0 | 0 | 0 | 12 | 100% |
| Other Europe | 5 | 0 | 7 | 0 | 12 | 42% |
| Asia-Pacific (other) | 11 | 0 | 17 | 0 | 28 | 39% |
| Latin America | 8 | 0 | 0 | 0 | 8 | 100% |
| Middle East | 2 | 0 | 2 | 0 | 4 | 50% |
Size, by contrast, hardly matters. Each quarter of the ranking has between 14 and 16 banks with PQC on at least one host. The largest banks are not ahead because the very top of the list is dominated by Chinese state-owned lenders, and the smaller banks are not behind because many of them buy the same CDN services as their larger peers.
Ranks and total assets from S&P Global Market Intelligence, April 2026.[1]
Show data table (hosts by asset rank)
| Group | PQC negotiated | Partly (some addresses) | Classical only | Undetermined | Total | PQC share |
|---|---|---|---|---|---|---|
| Rank 1–25 | 28 | 0 | 22 | 0 | 50 | 56% |
| Rank 26–50 | 27 | 0 | 23 | 0 | 50 | 54% |
| Rank 51–75 | 28 | 0 | 20 | 0 | 48 | 58% |
| Rank 76–100 | 24 | 0 | 25 | 0 | 49 | 49% |
4. What Drives Adoption: The Edge Network
The clearest explanation for who has PQC is where the bank's TLS connection ends. Of 110 hosts served by the large Western CDN and cloud edge networks in our sample (Akamai, Cloudflare, AWS, Imperva, Microsoft Azure and Azion), 101 negotiated hybrid ML-KEM (92%). Of 68 hosts served from the banks' own address space or a domestic telecom provider, only 4 did (6%): the homepages and logins of Danske Bank and Raiffeisen Switzerland, which run hybrid key exchange on their own infrastructure. The 9 hosts on Wangsu/CDNetworks and 2 on Tencent EdgeOne, used by Chinese banks, and the 5 German and Swedish hosts on Google Cloud load balancers were all classical only.
Akamai alone fronts 73 of the 194 hosts, and 68 of them negotiated PQC. That is no coincidence: Akamai made hybrid X25519MLKEM768 available as an opt-in in 2025 and switched it on by default for client-to-edge connections on its Enhanced TLS network in August 2026, with an opt-out.[2][4] Cloudflare has negotiated the hybrid with supporting browsers by default for longer.[5] In other words, for many banks in our sample post-quantum TLS arrived as a side-effect of their CDN contract, not of a migration programme. Four of the five Akamai-fronted hosts without PQC accept only TLS 1.2 (Citi's retail site, Morgan Stanley's homepage, SMBC Direct and OCBC's internet banking); the fifth, ABN AMRO's Dutch retail site, negotiates TLS 1.3 with classical X25519.
Edge network identified from the origin ASN of each host's IPv4 address and from CDN CNAME records. "Own / domestic network" means the bank's own address space or a domestic telecom provider. "Other cloud/CDN" combines Microsoft Azure, Azion and Tencent EdgeOne (two hosts each).
Show data table (hosts by edge network)
| Group | PQC negotiated | Partly (some addresses) | Classical only | Undetermined | Total | PQC share |
|---|---|---|---|---|---|---|
| Akamai | 68 | 0 | 5 | 0 | 73 | 93% |
| Own / domestic network | 4 | 0 | 64 | 0 | 68 | 6% |
| Cloudflare | 12 | 0 | 3 | 0 | 15 | 80% |
| AWS | 9 | 0 | 1 | 0 | 10 | 90% |
| Wangsu / CDNetworks | 0 | 0 | 9 | 0 | 9 | 0% |
| Imperva | 8 | 0 | 0 | 0 | 8 | 100% |
| Google Cloud | 0 | 0 | 5 | 0 | 5 | 0% |
| Microsoft Azure | 2 | 0 | 0 | 0 | 2 | 100% |
| Tencent EdgeOne | 0 | 0 | 2 | 0 | 2 | 0% |
| Azion | 2 | 0 | 0 | 0 | 2 | 100% |
The TLS 1.2 blocker
Fifty of our 194 hosts accept only TLS 1.2, an older version of the protocol that cannot carry a post-quantum key exchange at all, whatever software or CDN sits behind it. Of these, 27 belong to Chinese banks, including the online-banking logins of all four of China's largest banks (ICBC, Agricultural Bank of China, China Construction Bank and Bank of China) and the homepages of China Construction Bank and Bank of China. For these banks, enabling TLS 1.3 is the necessary first step before post-quantum migration can even begin; Section 9 explains the technical reason.
The other 39 classical hosts already speak TLS 1.3 but chose X25519 (37) or P-256 (2) when hybrid groups were offered. For them, post-quantum key exchange is a software update or a configuration switch away.
5. The Authentication Gap: Certificates Are Still Classical
Key exchange is only half of TLS. The certificates that prove a site's identity are still entirely classical: of the 176 hosts on which we could read the certificate, 144 use RSA-2048 keys (82%), 20 ECDSA P-256 and 12 RSA-4096. No host presented an ML-DSA or SLH-DSA certificate, and none was expected. Post-quantum certificates are not yet issued for the public web, and the industry's preferred route for HTTPS, Merkle Tree Certificates, is still in its experimental phase, as we describe in our browser analysis.
This gap is less urgent than key exchange: a forged signature only helps an attacker at the time of the connection, so certificates must be post-quantum before a cryptographically relevant quantum computer exists, not before today's traffic is recorded. But banks' certificate estates, HSMs and trust chains take years to change, so planning has to start now.
Leaf (server) certificate of each host on which a certificate was observed. No host presented an ML-DSA or SLH-DSA certificate.
6. The Regulatory Clock
Supervisors have stopped treating post-quantum migration as a research topic. The G7 Cyber Expert Group published a coordinated roadmap for the financial sector in January 2026. It recommends 2035 as the overall target for migration and suggests addressing the most critical systems in 2030–32. It also points out that data intercepted today may already be at risk.[6] In the EU, the Coordinated Implementation Roadmap adopted in June 2025 asks Member States to start transitioning by the end of 2026 and to move high-risk use cases, explicitly including finance, to PQC by the end of 2030.[7] NIST's draft transition plan, IR 8547, proposes to deprecate RSA and elliptic-curve key establishment and signatures after 2030 and to disallow them after 2035.[8] Europol's Quantum Safe Financial Forum has urged banks to treat the transition as a priority now, citing store-now-decrypt-later attacks.[9] In Germany, the BSI's TR-02102-1 recommends hybrid key establishment with ML-KEM, as our BSI compliance guide explains.[3]
Measured against those deadlines, hybrid TLS on public websites is the easy part: it is standardized, supported by every major browser and often only a configuration change away. That 39 of the 100 largest banks do not offer it on either their homepage or their login, with less than five years to the EU's 2030 target for high-risk use cases and the G7's suggested window for critical systems, shows how uneven the starting line is. For many banks that already have PQC, it was switched on by their CDN; their own transactional platforms, internal links and certificates remain to be migrated.
7. Recommendations for Banks
- Turn it on where it is a switch. If your edge provider already supports
X25519MLKEM768, enable it for every customer-facing hostname, logins and APIs included, and make sure no legacy opt-out is still in place.[2][5] - Retire TLS 1.2-only endpoints. TLS 1.2 cannot carry a post-quantum key exchange at all. Moving to TLS 1.3 is the prerequisite for PQC and closes older weaknesses at the same time; our TLS vulnerability analysis lists them.[10]
- Treat the login as the priority host. Credentials, account data and payment instructions travel over the online-banking host, not the marketing homepage. It deserves the protection first.
- Check every hop. Confirm that the CDN-to-origin and internal service connections are also hybrid, since browser-facing PQC says nothing about them.
- Inventory certificates now. Post-quantum certificates are not yet available on the public web, but certificate automation, HSMs and trust stores take years to change. Plan the signature migration separately from key exchange; our article on key exchange vs. signatures covers the two timelines.
- Verify from outside, continuously. Re-scan after every configuration change, from more than one region.
8. Bottom Line
Much of today's progress came with the infrastructure: two thirds of the PQC hosts we found sit on Akamai, which enabled hybrid key exchange by default only in August 2026. The next steps are less automatic: moving legacy TLS 1.2 endpoints to TLS 1.3, bringing online-banking platforms up to the level of the corporate homepage, extending hybrid key exchange to CDN-to-origin and internal connections, and preparing certificate infrastructure for ML-DSA. We plan to repeat this scan periodically to track progress.
Check Your Own Bank, or Your Own Domain
The results above are a point-in-time snapshot. To see what a bank, or your own organisation, negotiates today, scan the domain directly:
9. Technical Background: Why Banks, and Why TLS?
This section and the next are for readers who want the technical background to the results above and the details of how the scan was run.
Banks hold exactly the kind of data that an attacker would want to record today and decrypt later: account credentials, payment instructions, identity documents and the details of customers' financial lives. Much of that data stays sensitive for years. This is the harvest-now, decrypt-later threat: traffic captured now is protected only by the key exchange that set up the session, and today's classical key exchanges (ECDHE with X25519 or NIST curves) can be broken by a large enough quantum computer.
TLS is the first and most visible place to fix this. The upgrade is a hybrid key exchange: the TLS 1.3 named group X25519MLKEM768 combines classical X25519 with ML-KEM-768, the module-lattice KEM that NIST standardized in FIPS 203.[11][12] The connection stays secure as long as either component holds. Every major browser already offers this group by default, as our browser comparison shows, so the deciding factor for a customer's connection is whether the bank's server accepts it.
That makes the server side measurable from the outside. A scan cannot see a bank's internal systems, but it can see what every customer's browser sees: which TLS version and key-exchange group the bank's public servers negotiate. That is the view this report measures, for the homepage and the online-banking login of each of the world's 100 largest banks.
Technical Detail: Why TLS 1.2 Rules Out Post-Quantum Key Exchange
The hybrid ML-KEM groups are defined only for TLS 1.3: a client sends the ML-KEM encapsulation key in the TLS 1.3 key_share extension, and the server answers with a ciphertext.[10][12] TLS 1.2 has no equivalent mechanism, so a server that tops out at TLS 1.2 cannot offer post-quantum key exchange regardless of its software or CDN.
50 of our 194 hosts are in that position (Section 4). Many of these servers also lack RFC 5746 secure renegotiation,[13] a 2010 fix that modern TLS libraries now require by default.
10. Methodology
Sample
The sample is S&P Global Market Intelligence's ranking The world's largest banks by assets, 2026, published 29 April 2026. Most total assets in it are as of 31 December 2025.[1] The 100 banks hold about US$133 trillion in assets and are headquartered in 24 countries. Mainland China accounts for 21 of them, the United States for 12 and Japan for 8.
For each bank we scanned up to two hostnames:
- Homepage: the group's official public website as linked from its investor and corporate pages, e.g.
www.jpmorganchase.comorwww.icbc.com.cn. - Online-banking login: the host that serves the retail customer sign-in. We found it by following the bank's own "Log in" or "Online banking" link from its home-market retail site and recording the final hostname after redirects, e.g.
secure.chase.com. For groups with several retail brands we used the main home-market brand. Three banks (DZ Bank, Norinchukin Bank and BNY) operate no retail online banking of their own and were excluded from the login sample. At three banks the login form sits on the homepage host itself; that host was scanned once and counted in both samples.
That gives 194 unique hosts: 100 homepages and 97 online-banking logins. The full list, including every hostname, is in Appendix A.
Scanner and procedure
Every host was scanned with CipherScope, our public post-quantum readiness scanner,[14] using OpenSSL 3.6 as the TLS probe. The Standard profile opens a normal TLS connection and then a handshake that offers hybrid groups first (X25519MLKEM768, SecP256r1MLKEM768, SecP384r1MLKEM1024) alongside classical fallbacks, exactly as a modern browser would. It records the group the server actually chooses. Hosts with a post-quantum result were then re-checked with the Deep profile (with six exceptions, see below), which samples up to four IPv4 and four IPv6 addresses, tests each hybrid group separately and confirms classical fallback.
Each host receives one of four results:
| Result | Meaning |
|---|---|
| PQC negotiated | The server selected a standardized hybrid ML-KEM group on every tested address. |
| Partly | Some tested addresses negotiated hybrid ML-KEM, others classical key exchange. This is typical of a rollout in progress or of mixed load balancers. |
| Classical only | The server chose a classical group (e.g. X25519 or P-256) although hybrid groups were offered, or the server supports only TLS 1.2, which cannot carry ML-KEM groups at all. |
| Undetermined | No handshake could be completed from our vantage point (blocking, timeouts or geofencing). These hosts are reported, but not counted as either result. |
For 53 hosts CipherScope's TLS stack could not complete a handshake. In nearly all cases the reason was not a network block but an old server configuration: a server limited to TLS 1.2, or one that does not implement the secure renegotiation extension of RFC 5746, which OpenSSL 3 refuses by default.[13] We resolved these hosts with a supplementary OpenSSL 3.6 handshake that offers the same hybrid groups first but tolerates legacy renegotiation. All 53 completed: 50 negotiated TLS 1.2 and 3 negotiated TLS 1.3 with a classical group. All of them are therefore reported as classical only, and are marked * in the appendix. As a cross-check, we repeated the same independent OpenSSL handshake on a random sample of 12 hosts that CipherScope had classified itself (6 PQC, 6 classical only). All 12 matched. Because of the scanner's daily limit, 100 hosts received the Deep re-check (every PQC-positive login and all PQC-positive homepages except the six lowest-ranked ones, which keep their Standard result). Every Deep re-check confirmed the result on all sampled addresses, so no host fell into the "Partly" category, and after the supplementary handshake none remained undetermined.
We also recorded the leaf certificate's public-key algorithm, and identified the network that terminates each TLS connection. For the latter we looked up the origin autonomous system (ASN) of the host's IPv4 address via Team Cymru's IP-to-ASN service,[15] using CNAME records where a CDN runs inside third-party address space. The scans ran on 5–6 October 2026 from a single vantage point in Europe.
Additional observations
All 105 PQC hosts chose X25519MLKEM768, the group browsers prefer. The Deep scan also offered each hybrid group on its own: 10 of the 99 PQC hosts it covered additionally accept SecP256r1MLKEM768, the NIST-curve variant,[12] and none accepted SecP384r1MLKEM1024.
A secondary check of the banks' public mail servers (MX hosts of the homepage domain, via STARTTLS) shows that post-quantum protection has barely reached e-mail: only BBVA's mail servers negotiated hybrid ML-KEM on all tested addresses and Nationwide's on some. Many mail servers could not be assessed from our vantage point, so we do not report a percentage.
Further Reading
For how the hybrid key exchange that protects these connections works, and why it combines a classical and a post-quantum component, read our technical analysis:
Read: X25519+ML-KEM-768 Hybrid Key Exchange →Appendix A: Results for All 100 Banks
Ranked by total assets (S&P Global, April 2026).[1] The group shown is the key-exchange group the server selected when hybrid groups were offered first. Results marked * were resolved with the supplementary OpenSSL handshake described in Section 10. Results reflect our scans on 5–6 October 2026 and may have changed since.
| # | Bank | HQ | Assets (US$B) | Homepage host | Homepage result | Online-banking host | Login result |
|---|---|---|---|---|---|---|---|
| 1 | Industrial and Commercial Bank of China Ltd. | Mainland China | 7,646 | www.icbc.com.cn | Classical onlyX25519 | mybank.icbc.com.cn | Classical onlyTLS 1.2 only * |
| 2 | Agricultural Bank of China Ltd. | Mainland China | 6,975 | www.abchina.com | Classical onlyX25519 | perbank.abchina.com.cn | Classical onlyTLS 1.2 only * |
| 3 | China Construction Bank Corp. | Mainland China | 6,524 | www.ccb.com | Classical onlyTLS 1.2 only * | ibsbjstar.ccb.com.cn | Classical onlyTLS 1.2 only * |
| 4 | Bank of China Ltd. | Mainland China | 5,484 | www.boc.cn | Classical onlyTLS 1.2 only * | ebsnew.boc.cn | Classical onlyTLS 1.2 only * |
| 5 | JPMorgan Chase & Co. | US | 4,425 | www.jpmorganchase.com | PQC negotiatedX25519MLKEM768 | secure.chase.com | PQC negotiatedX25519MLKEM768 |
| 6 | Bank of America Corp. | US | 3,412 | www.bankofamerica.com | PQC negotiatedX25519MLKEM768 | secure.bankofamerica.com | PQC negotiatedX25519MLKEM768 |
| 7 | BNP Paribas SA | France | 3,279 | group.bnpparibas | PQC negotiatedX25519MLKEM768 | mabanque.bnpparibas | PQC negotiatedX25519MLKEM768 |
| 8 | HSBC Holdings PLC | UK | 3,212 | www.hsbc.com | PQC negotiatedX25519MLKEM768 | www.hsbc.co.uk | PQC negotiatedX25519MLKEM768 |
| 9 | Crédit Agricole Group | France | 3,149 | www.credit-agricole.com | Classical onlyX25519 | www.credit-agricole.fr | Classical onlyTLS 1.2 only * |
| 10 | Postal Savings Bank of China Co. Ltd. | Mainland China | 2,671 | www.psbc.com | Classical onlyX25519 | pbank.psbc.com | Classical onlyTLS 1.2 only * |
| 11 | Mitsubishi UFJ Financial Group Inc. | Japan | 2,667 | www.mufg.jp | PQC negotiatedX25519MLKEM768 | directg.s.bk.mufg.jp | PQC negotiatedX25519MLKEM768 |
| 12 | Citigroup Inc. | US | 2,622 | www.citigroup.com | PQC negotiatedX25519MLKEM768 | www.citi.com | Classical onlyTLS 1.2 only * |
| 13 | Banco Santander SA | Spain | 2,252 | www.santander.com | PQC negotiatedX25519MLKEM768 | particulares.bancosantander.es | PQC negotiatedX25519MLKEM768 |
| 14 | Bank of Communications Co. Ltd. | Mainland China | 2,223 | www.bankcomm.com | Classical onlyTLS 1.2 only * | pbank.95559.com.cn | Classical onlyTLS 1.2 only * |
| 15 | Wells Fargo & Co. | US | 2,149 | www.wellsfargo.com | PQC negotiatedX25519MLKEM768 | connect.secure.wellsfargo.com | PQC negotiatedX25519MLKEM768 |
| 16 | Barclays PLC | UK | 2,078 | home.barclays | PQC negotiatedX25519MLKEM768 | bank.barclays.co.uk | PQC negotiatedX25519MLKEM768 |
| 17 | Sumitomo Mitsui Financial Group Inc. | Japan | 2,020 | www.smfg.co.jp | PQC negotiatedX25519MLKEM768 | direct.smbc.co.jp | Classical onlyTLS 1.2 only * |
| 18 | Groupe BPCE | France | 1,987 | www.groupebpce.com | PQC negotiatedX25519MLKEM768 | www.caisse-epargne.fr | PQC negotiatedX25519MLKEM768 |
| 19 | Mizuho Financial Group Inc. | Japan | 1,898 | www.mizuhogroup.com | PQC negotiatedX25519MLKEM768 | web.ib.mizuhobank.co.jp | PQC negotiatedX25519MLKEM768 |
| 20 | China Merchants Bank Co. Ltd. | Mainland China | 1,869 | www.cmbchina.com | Classical onlyTLS 1.2 only * | pbsz.ebank.cmbchina.com | Classical onlyTLS 1.2 only * |
| 21 | Société Générale SA | France | 1,813 | www.societegenerale.com | PQC negotiatedX25519MLKEM768 | particuliers.sg.fr | Classical onlysecp256r1 * |
| 22 | Goldman Sachs Group Inc. | US | 1,809 | www.goldmansachs.com | PQC negotiatedX25519MLKEM768 | www.marcus.com | PQC negotiatedX25519MLKEM768 |
| 23 | Royal Bank of Canada | Canada | 1,727 | www.rbc.com | PQC negotiatedX25519MLKEM768 | secure.royalbank.com | PQC negotiatedX25519MLKEM768 |
| 24 | Deutsche Bank AG | Germany | 1,685 | www.db.com | Classical onlyX25519 | meine.deutsche-bank.de | Classical onlyX25519 |
| 25 | UBS Group AG | Switzerland | 1,617 | www.ubs.com | PQC negotiatedX25519MLKEM768 | ebanking-ch.ubs.com | Classical onlyTLS 1.2 only * |
| 26 | Industrial Bank Co. Ltd. | Mainland China | 1,586 | www.cib.com.cn | Classical onlyX25519 | personalbank.cib.com.cn | Classical onlyX25519 |
| 27 | Toronto-Dominion Bank | Canada | 1,548 | www.td.com | PQC negotiatedX25519MLKEM768 | easyweb.td.com | PQC negotiatedX25519MLKEM768 |
| 28 | Japan Post Bank Co. Ltd. | Japan | 1,451 | www.jp-bank.japanpost.jp | PQC negotiatedX25519MLKEM768 | direct1.jp-bank.japanpost.jp | PQC negotiatedX25519MLKEM768 |
| 29 | China Citic Bank Corp. Ltd. | Mainland China | 1,448 | www.citicbank.com | Classical onlyX25519 | i.bank.ecitic.com | Classical onlyX25519 |
| 30 | Crédit Mutuel Group | France | 1,442 | www.creditmutuel.fr | Classical onlyTLS 1.2 only * | www.creditmutuel.fr (same host) | Classical onlyTLS 1.2 only * |
| 31 | Shanghai Pudong Development Bank Co. Ltd. | Mainland China | 1,441 | www.spdb.com.cn | Classical onlyTLS 1.2 only * | ebank.spdb.com.cn | Classical onlyTLS 1.2 only * |
| 32 | Morgan Stanley | US | 1,420 | www.morganstanley.com | Classical onlyTLS 1.2 only * | login.morganstanleyclientserv.com | PQC negotiatedX25519MLKEM768 |
| 33 | Lloyds Banking Group PLC | UK | 1,271 | www.lloydsbankinggroup.com | PQC negotiatedX25519MLKEM768 | online.lloydsbank.co.uk | PQC negotiatedX25519MLKEM768 |
| 34 | ING Groep NV | Netherlands | 1,238 | www.ing.com | PQC negotiatedX25519MLKEM768 | mijn.ing.nl | PQC negotiatedX25519MLKEM768 |
| 35 | Intesa Sanpaolo SpA | Italy | 1,127 | group.intesasanpaolo.com | Classical onlyX25519 | www.intesasanpaolo.com | PQC negotiatedX25519MLKEM768 |
| 36 | China Minsheng Banking Corp. Ltd. | Mainland China | 1,120 | www.cmbc.com.cn | Classical onlyX25519 | nper.cmbc.com.cn | Classical onlyTLS 1.2 only * |
| 37 | Bank of Nova Scotia | Canada | 1,088 | www.scotiabank.com | PQC negotiatedX25519MLKEM768 | auth.scotiaonline.scotiabank.com | PQC negotiatedX25519MLKEM768 |
| 38 | Bank of Montreal | Canada | 1,070 | www.bmo.com | PQC negotiatedX25519MLKEM768 | www1.bmo.com | PQC negotiatedX25519MLKEM768 |
| 39 | China Everbright Bank Co. Ltd. | Mainland China | 1,024 | www.cebbank.com | Classical onlyTLS 1.2 only * | e.cebbank.com | Classical onlyTLS 1.2 only * |
| 40 | UniCredit SpA | Italy | 1,022 | www.unicreditgroup.eu | PQC negotiatedX25519MLKEM768 | www.unicredit.it | PQC negotiatedX25519MLKEM768 |
| 41 | Banco Bilbao Vizcaya Argentaria SA | Spain | 1,006 | www.bbva.com | PQC negotiatedX25519MLKEM768 | web.bbva.es | PQC negotiatedX25519MLKEM768 |
| 42 | NatWest Group PLC | UK | 962 | www.natwestgroup.com | PQC negotiatedX25519MLKEM768 | www.onlinebanking.natwest.com | PQC negotiatedX25519MLKEM768 |
| 43 | Commonwealth Bank of Australia | Australia | 940 | www.commbank.com.au | Classical onlyTLS 1.2 only * | www.my.commbank.com.au | Classical onlyTLS 1.2 only * |
| 44 | Standard Chartered PLC | UK | 920 | www.sc.com | PQC negotiatedX25519MLKEM768 | retail.sc.com | PQC negotiatedX25519MLKEM768 |
| 45 | State Bank of India | India | 877 | sbi.co.in | Classical onlyX25519 | retail.onlinesbi.sbi | Classical onlyX25519 |
| 46 | Sberbank of Russia | Russia | 870 | www.sberbank.com | Classical onlysecp256r1 * | online.sberbank.ru | Classical onlyTLS 1.2 only * |
| 47 | ANZ Group Holdings Ltd. | Australia | 858 | www.anz.com | PQC negotiatedX25519MLKEM768 | login.anz.com | PQC negotiatedX25519MLKEM768 |
| 48 | La Banque Postale SA | France | 852 | www.labanquepostale.fr | PQC negotiatedX25519MLKEM768 | voscomptesenligne.labanquepostale.fr | Classical onlyX25519 |
| 49 | Ping An Bank Co. Ltd. | Mainland China | 847 | bank.pingan.com | Classical onlyX25519 | ebank.pingan.com.cn | Classical onlyTLS 1.2 only * |
| 50 | Canadian Imperial Bank of Commerce | Canada | 835 | www.cibc.com | PQC negotiatedX25519MLKEM768 | www.cibconline.cibc.com | PQC negotiatedX25519MLKEM768 |
| 51 | CaixaBank SA | Spain | 780 | www.caixabank.com | PQC negotiatedX25519MLKEM768 | loc6.caixabank.es | Classical onlyTLS 1.2 only * |
| 52 | DZ Bank AG | Germany | 777 | www.dzbank.de | Classical onlyX25519 | No retail online banking | |
| 53 | Nordea Bank Abp | Finland | 768 | www.nordea.com | PQC negotiatedX25519MLKEM768 | netbank.nordea.fi | PQC negotiatedX25519MLKEM768 |
| 54 | Rabobank | Netherlands | 750 | www.rabobank.com | PQC negotiatedX25519MLKEM768 | bankieren.rabobank.nl | PQC negotiatedX25519MLKEM768 |
| 55 | Westpac Banking Corp. | Australia | 744 | www.westpac.com.au | PQC negotiatedX25519MLKEM768 | banking.westpac.com.au | PQC negotiatedX25519MLKEM768 |
| 56 | National Australia Bank Ltd. | Australia | 734 | www.nab.com.au | PQC negotiatedX25519MLKEM768 | ib.nab.com.au | PQC negotiatedX25519MLKEM768 |
| 57 | DBS Group Holdings Ltd. | Singapore | 698 | www.dbs.com | PQC negotiatedX25519MLKEM768 | internet-banking.dbs.com.sg | PQC negotiatedX25519MLKEM768 |
| 58 | Commerzbank AG | Germany | 693 | www.commerzbank.de | Classical onlyX25519 | kunden.commerzbank.de | Classical onlyX25519 |
| 59 | U.S. Bancorp | US | 692 | www.usbank.com | PQC negotiatedX25519MLKEM768 | onlinebanking.usbank.com | PQC negotiatedX25519MLKEM768 |
| 60 | Bank of Jiangsu Co. Ltd. | Mainland China | 692 | www.jsbchina.cn | Classical onlyX25519 | ebank.jsbchina.cn | Classical onlyX25519 |
| 61 | Bank of Beijing Co. Ltd. | Mainland China | 687 | www.bankofbeijing.com.cn | Classical onlyTLS 1.2 only * | ebank.bankofbeijing.com.cn | Classical onlyTLS 1.2 only * |
| 62 | Hua Xia Bank Co. Ltd. | Mainland China | 677 | www.hxb.com.cn | Classical onlyX25519 * | psbank.hxb.com.cn | Classical onlyTLS 1.2 only * |
| 63 | Capital One Financial Corp. | US | 669 | www.capitalone.com | PQC negotiatedX25519MLKEM768 | verified.capitalone.com | PQC negotiatedX25519MLKEM768 |
| 64 | PNC Financial Services Group Inc. | US | 600 | www.pnc.com | PQC negotiatedX25519MLKEM768 | www.onlinebanking.pnc.com | PQC negotiatedX25519MLKEM768 |
| 65 | Danske Bank A/S | Denmark | 590 | danskebank.com | PQC negotiatedX25519MLKEM768 | netbank.danskebank.dk | PQC negotiatedX25519MLKEM768 |
| 66 | Itaú Unibanco Holding SA | Brazil | 562 | www.itau.com.br | PQC negotiatedX25519MLKEM768 | www.itau.com.br (same host) | PQC negotiatedX25519MLKEM768 |
| 67 | KB Financial Group Inc. | South Korea | 553 | www.kbfg.com | Classical onlyTLS 1.2 only * | obank.kbstar.com | Classical onlyTLS 1.2 only * |
| 68 | Truist Financial Corp. | US | 548 | www.truist.com | PQC negotiatedX25519MLKEM768 | dias.bank.truist.com | PQC negotiatedX25519MLKEM768 |
| 69 | Shinhan Financial Group Co. Ltd. | South Korea | 545 | www.shinhangroup.com | Classical onlyX25519 | bank.shinhan.com | Classical onlyTLS 1.2 only * |
| 70 | Norinchukin Bank | Japan | 542 | www.nochubank.or.jp | PQC negotiatedX25519MLKEM768 | No retail online banking | |
| 71 | Oversea-Chinese Banking Corp. Ltd. | Singapore | 525 | www.ocbc.com | PQC negotiatedX25519MLKEM768 | internet.ocbc.com | Classical onlyTLS 1.2 only * |
| 72 | Sumitomo Mitsui Trust Group Inc. | Japan | 522 | www.smtg.jp | PQC negotiatedX25519MLKEM768 | direct.smtb.jp | PQC negotiatedX25519MLKEM768 |
| 73 | Bank of Ningbo Co. Ltd. | Mainland China | 519 | www.nbcb.com.cn | Classical onlyX25519 | e.nbcb.com.cn | Classical onlyTLS 1.2 only * |
| 74 | Erste Group Bank AG | Austria | 518 | www.erstegroup.com | PQC negotiatedX25519MLKEM768 | george.sparkasse.at | Classical onlyX25519 |
| 75 | China Guangfa Bank Co. Ltd. | Mainland China | 515 | www.cgbchina.com.cn | Classical onlyX25519 | ebanks.cgbchina.com.cn | Classical onlyTLS 1.2 only * |
| 76 | HDFC Bank Ltd. | India | 515 | www.hdfcbank.com | PQC negotiatedX25519MLKEM768 | netbanking.hdfcbank.com | PQC negotiatedX25519MLKEM768 |
| 77 | ABN AMRO Bank NV | Netherlands | 511 | www.abnamro.com | PQC negotiatedX25519MLKEM768 | www.abnamro.nl | Classical onlyX25519 |
| 78 | Nationwide Building Society | UK | 507 | www.nationwide.co.uk | PQC negotiatedX25519MLKEM768 | onlinebanking.nationwide.co.uk | Classical onlyX25519 |
| 79 | China Zheshang Bank Co. Ltd. | Mainland China | 498 | www.czbank.com | Classical onlyX25519 | perbank.czbank.com | Classical onlyTLS 1.2 only * |
| 80 | Resona Holdings Inc. | Japan | 495 | www.resona-gr.co.jp | PQC negotiatedX25519MLKEM768 | ib.resonabank.co.jp | PQC negotiatedX25519MLKEM768 |
| 81 | Charles Schwab Corp. | US | 491 | www.schwab.com | PQC negotiatedX25519MLKEM768 | client.schwab.com | PQC negotiatedX25519MLKEM768 |
| 82 | Bank of Shanghai Co. Ltd. | Mainland China | 473 | www.bosc.cn | Classical onlyTLS 1.2 only * | ebanks.bankofshanghai.com | Classical onlyTLS 1.2 only * |
| 83 | Bank of New York Mellon Corp. | US | 472 | www.bny.com | PQC negotiatedX25519MLKEM768 | No retail online banking | |
| 84 | KBC Group NV | Belgium | 472 | www.kbc.com | PQC negotiatedX25519MLKEM768 | www.kbc.be | PQC negotiatedX25519MLKEM768 |
| 85 | Hana Financial Group Inc. | South Korea | 467 | www.hanafn.com | Classical onlyX25519 | www.kebhana.com | Classical onlyTLS 1.2 only * |
| 86 | VTB Bank PJSC | Russia | 466 | www.vtb.ru | Classical onlyX25519 | online.vtb.ru | Classical onlyTLS 1.2 only * |
| 87 | National Bank of Canada | Canada | 447 | www.nbc.ca | PQC negotiatedX25519MLKEM768 | app.bnc.ca | PQC negotiatedX25519MLKEM768 |
| 88 | Banco do Brasil SA | Brazil | 445 | www.bb.com.br | PQC negotiatedX25519MLKEM768 | autoatendimento.bb.com.br | PQC negotiatedX25519MLKEM768 |
| 89 | United Overseas Bank Ltd. | Singapore | 445 | www.uobgroup.com | Classical onlyTLS 1.2 only * | pib.uob.com.sg | Classical onlyTLS 1.2 only * |
| 90 | Bank of Nanjing Co. Ltd. | Mainland China | 432 | www.njcb.com.cn | Classical onlyTLS 1.2 only * | ebank.njcb.com.cn | Classical onlyTLS 1.2 only * |
| 91 | Banco Bradesco SA | Brazil | 419 | banco.bradesco | PQC negotiatedX25519MLKEM768 | banco.bradesco (same host) | PQC negotiatedX25519MLKEM768 |
| 92 | NongHyup Financial Group Inc. | South Korea | 418 | www.nonghyup.com | Classical onlyTLS 1.2 only * | banking.nonghyup.com | Classical onlyTLS 1.2 only * |
| 93 | Woori Financial Group Inc. | South Korea | 417 | www.woorifg.com | Classical onlyTLS 1.2 only * | spib.wooribank.com | Classical onlyTLS 1.2 only * |
| 94 | Landesbank Baden-Württemberg | Germany | 408 | www.lbbw.de | Classical onlyX25519 | www.bw-bank.de | Classical onlyX25519 |
| 95 | Raiffeisen Gruppe Switzerland | Switzerland | 407 | www.raiffeisen.ch | PQC negotiatedX25519MLKEM768 | ebanking.raiffeisen.ch | PQC negotiatedX25519MLKEM768 |
| 96 | Caixa Econômica Federal | Brazil | 404 | www.caixa.gov.br | PQC negotiatedX25519MLKEM768 | internetbanking.caixa.gov.br | PQC negotiatedX25519MLKEM768 |
| 97 | Skandinaviska Enskilda Banken AB (publ) | Sweden | 398 | sebgroup.com | Classical onlyX25519 | id.seb.se | Classical onlyX25519 |
| 98 | Nomura Holdings Inc. | Japan | 395 | www.nomuraholdings.com | PQC negotiatedX25519MLKEM768 | hometrade.nomura.co.jp | Classical onlyX25519 |
| 99 | First Abu Dhabi Bank PJSC | UAE | 382 | www.bankfab.com | Classical onlyX25519 | online.bankfab.com | Classical onlyTLS 1.2 only * |
| 100 | Qatar National Bank (QPSC) | Qatar | 382 | www.qnb.com | PQC negotiatedX25519MLKEM768 | ib.qnb.com | PQC negotiatedX25519MLKEM768 |
How to Cite This Report
APA: PostQuantumSecurity.org. (2026, October 6). Is Your Bank Ready for Quantum Computers? We Checked the World's 100 Largest. https://www.postquantumsecurity.org/publications/top100banks-pqc-report.html
IEEE: PostQuantumSecurity.org, "Is Your Bank Ready for Quantum Computers? We Checked the World's 100 Largest," Oct. 6, 2026. [Online]. Available: https://www.postquantumsecurity.org/publications/top100banks-pqc-report.html
LaTeX/BibTeX:
@misc{pqcryptography_top100banks_pqc,
author = {{PostQuantumSecurity.org}},
title = {Is Your Bank Ready for Quantum Computers? We Checked the World's 100 Largest},
year = {2026},
month = oct,
day = {6},
url = {https://www.postquantumsecurity.org/publications/top100banks-pqc-report.html}
}
References
- Jimenea, A., & Lozano, C. (2026, April 29). The world's largest banks by assets, 2026. S&P Global Market Intelligence. https://www.spglobal.com/market-intelligence/en/news-insights/research/2026/04/the-worlds-largest-banks-by-assets-2026
- Daffron, T. (2026, August). Future-Proofing the Internet: Akamai Achieves End-to-End PQC. Akamai Blog. https://www.akamai.com/blog/security/2026/aug/future-proofing-internet-akamai-achieves-end-to-end-pqc
- Federal Office for Information Security (BSI). (2026). Technical Guideline TR-02102-1: Cryptographic Mechanisms: Recommendations and Key Lengths, Version 2026-01. PDF copy
- Akamai. (2025, September 3). Akamai Enables Post-Quantum Cryptography on the Edge. Akamai Blog. https://www.akamai.com/blog/security/2025/aug/akamai-enables-post-quantum-cryptography-edge
- Cloudflare. (2026). Post-quantum cryptography (PQC). Cloudflare SSL/TLS documentation. https://developers.cloudflare.com/ssl/post-quantum-cryptography/
- G7 Cyber Expert Group. (2026, January). Statement on Advancing a Coordinated Roadmap for the Transition to Post-Quantum Cryptography in the Financial Sector. https://www.gov.uk/government/publications/advancing-a-coordinated-roadmap-for-the-transition-to-post-quantum-cryptography-in-the-financial-sector
- European Commission & NIS Cooperation Group. (2025, June 23). A Coordinated Implementation Roadmap for the Transition to Post-Quantum Cryptography. https://digital-strategy.ec.europa.eu/en/library/coordinated-implementation-roadmap-transition-post-quantum-cryptography
- Moody, D., Perlner, R., Regenscheid, A., Robinson, A., & Cooper, D. (2024, November 12). NIST IR 8547 (Initial Public Draft): Transition to Post-Quantum Cryptography Standards. https://csrc.nist.gov/pubs/ir/8547/ipd
- Europol. (2025, February 7). Call for action: urgent plan needed to transition to post-quantum cryptography together. https://www.europol.europa.eu/media-press/newsroom/news/call-for-action-urgent-plan-needed-to-transition-to-post-quantum-cryptography-together
- Rescorla, E. (2018). RFC 8446: The Transport Layer Security (TLS) Protocol Version 1.3. IETF. https://www.rfc-editor.org/rfc/rfc8446
- National Institute of Standards and Technology. (2024). FIPS 203: Module-Lattice-Based Key-Encapsulation Mechanism Standard. https://csrc.nist.gov/pubs/fips/203/final
- Kwiatkowski, K., Kampanakis, P., Westerbaan, B., & Stebila, D. Post-quantum hybrid ECDHE-MLKEM Key Agreement for TLSv1.3. IETF Internet-Draft draft-ietf-tls-ecdhe-mlkem. https://datatracker.ietf.org/doc/draft-ietf-tls-ecdhe-mlkem/
- Rescorla, E., Ray, M., Dispensa, S., & Oskov, N. (2010). RFC 5746: Transport Layer Security (TLS) Renegotiation Indication Extension. IETF. https://www.rfc-editor.org/rfc/rfc5746
- HybridCipher. (2026). CipherScope: Public PQC Readiness Scanner. https://cipherscope.hybridcipher.com/
- Team Cymru. IP to ASN Mapping Service. https://www.team-cymru.com/ip-asn-mapping