The Economics of QKD Deployment: Cost, Infrastructure, and Return

Every QKD vendor pitch begins with the physics. Quantum key distribution uses the properties of photons to establish a shared secret key such that any eavesdropping attempt disturbs the channel detectably. The security proof is real. The procurement decision, however, is not a physics decision. It is a cost and return decision, and the full cost structure of QKD deployment is almost never presented in vendor materials.

Node hardware from the two leading commercial suppliers, Toshiba and ID Quantique, is priced at approximately $100,000 to $150,000 per site. That figure is the starting point for a conversation, not the total cost. Dedicated fibre, multiplexing equipment, trusted-node physical security, vendor maintenance contracts, key management integration, and specialist staffing each add to the total. For a five-node metropolitan network over a three-year period, total cost of ownership can reach $930,000 to $1.44 million for a local deployment, rising to $3 million to $5 million for extended inter-city networks requiring trusted-node infrastructure.

This article gives CISOs, CFOs, and procurement leads the cost picture that vendor materials omit, sets it against the cost of the alternative, and identifies the three scenarios where QKD provides a return that justifies that expenditure. For the remaining 95 per cent of organisations, NIST PQC, specifically ML-KEM (FIPS 203), ML-DSA (FIPS 204), and SLH-DSA (FIPS 205), finalised in August 2024, is the correct and substantially cheaper migration path.

The Price of a QKD Node and What That Number Hides

Hardware Acquisition Cost

Toshiba's commercial QKD systems, based on its multiplexed continuous-variable and discrete-variable QKD platforms and deployed in the Tokyo QKD Network and in BT's Cambridge trial, are priced at approximately $100,000 to $150,000 per node. ID Quantique's Cerberis XG, the company's flagship enterprise QKD product, is priced at approximately $100,000 per node and above depending on configuration. These figures are corroborated by the UK NCSC's 2020 whitepaper on quantum key distribution, which provides an independent reference for commercial QKD system pricing.

A point-to-point QKD link requires two nodes. A minimal protected network topology covering three locations requires at least four nodes. The hardware cost for a minimal enterprise deployment therefore starts at $200,000 to $600,000 before any infrastructure, integration, or operational costs are added. That figure is often what first moves a procurement discussion from curiosity to sticker shock.

Fibre Infrastructure

QKD systems require either dedicated dark fibre, which is unlit optical fibre leased without active wavelength services, or a carefully managed wavelength-division multiplexing arrangement. The quantum channel signal operates at single-photon or near-single-photon level. Raman scattering noise from classical channels co-propagating on the same fibre constrains how much traffic can share the wavelength before the quantum channel becomes unusable. Research by Patel et al. (Physical Review X, 2012) established the technical limits of classical and quantum signal co-propagation on standard fibre, and those limits impose real engineering constraints on shared fibre deployments.

Dark fibre leasing in UK metropolitan areas costs approximately £8,000 to £25,000 per year per route kilometre depending on location and provider. A five-site metropolitan network with an average of 5 km between nodes requires approximately 20 km of dark fibre. The annual fibre cost alone can reach £160,000 to £500,000 for such a network, on top of the hardware acquisition cost. This figure should be confirmed with current UK infrastructure providers before committing to a procurement.

For distances beyond approximately 100 km, trusted-node architecture is required. Measurement-device-independent QKD (MDI-QKD), developed by Lo, Curty, and Qi in 2012, requires Bell state measurement hardware at each intermediate node. BSM equipment adds approximately $50,000 to $100,000 per trusted node beyond the basic QKD transceiver cost, as documented in European Quantum Internet Alliance technical reports from 2021 to 2023.

The Trusted-Node Cost Multiplier

Trusted nodes are the infrastructure element that converts QKD from a point-to-point technology into a network technology. They are also the element that most significantly inflates both cost and security complexity. Each trusted node must be physically secured in a dedicated secure facility, not a standard data centre cabinet. It must be staffed or continuously remote-monitored. It requires vendor support contracts and hardware maintenance access.

The NSA's August 2021 QKD FAQ identifies trusted-node physical security as both a cost driver and a vulnerability. The document is explicit: “QKD networks rely on trusted nodes, which introduce vulnerabilities similar to those in conventional networks.” The security implication matters as much as the cost implication. A trusted node that is compromised gives an adversary access to all key material transiting through it. The unconditional security property of the quantum channel, which is the primary justification for deploying QKD, does not extend through a compromised trusted node.

Government QKD network deployments provide the most reliable cost reference data. The SECOQC network in Vienna, documented by Peev et al. in the New Journal of Physics (2009), and the Tokyo QKD Network, reported by NTT and Toshiba in IEEE publications between 2011 and 2014, both show that trusted-node networks cost approximately 10 to 100 times more per protected kilometre than a point-to-point QKD link, due to physical security, real estate, monitoring, and maintenance overhead. That multiplier is not a theoretical estimate. It is derived from the documented operational costs of the largest QKD network deployments to date.

Operating Costs and Total Cost of Ownership

Vendor SLA maintenance contracts for commercial QKD systems typically run at 15 to 20 per cent of hardware acquisition cost per year. For a four-node deployment at $400,000 in hardware, annual maintenance contracts total approximately $60,000 to $80,000. UK Quantum Technologies Programme procurement guidance corroborates this range, though publicly available QKD-specific SLA pricing schedules are not published by vendors, so this figure should be treated as an order-of-magnitude planning estimate.

Key management integration is a separate cost item. The options are: deploy a Key Management System from the QKD vendor, which is proprietary and typically priced as a separate line item; or integrate with existing enterprise key management infrastructure using the ETSI GS QKD 014 REST API specification. The ETSI API route (standardised in ETSI GS QKD 014 v1.1.1, published in 2019) avoids vendor lock-in but requires significant integration engineering effort from staff familiar with both photonic hardware and enterprise key management systems. That expertise is not available in most enterprise IT teams, and recruiting or contracting for it adds further cost.

Assembling the full three-year total cost of ownership for a five-node metropolitan QKD network produces the following range: hardware, $500,000 to $750,000; fibre and facilities, $150,000 to $250,000; maintenance contracts, $180,000 to $240,000; integration, training, and professional services, $100,000 to $200,000. Total: $930,000 to $1.44 million. For extended inter-city networks with trusted nodes, the range rises to $3 million to $5 million. These are planning estimates derived from the itemised cost components above, not commercial quotations from vendors.

The PQC Comparison

Post-quantum cryptography, specifically the NIST standards FIPS 203 (ML-KEM), FIPS 204 (ML-DSA), and FIPS 205 (SLH-DSA) finalised in August 2024, is implemented in software. Deploying PQC in an enterprise network involves updating TLS libraries, VPN appliances, and key management systems as vendors ship PQC-enabled versions. The marginal cost of the algorithm change itself is effectively zero. The Open Quantum Safe project's liboqs library, an open source reference implementation, is available at no cost to development teams building against the NIST standards.

The real cost of PQC migration is cryptographic discovery, prioritisation, and legacy system replacement, not algorithm licensing or dedicated hardware. A PQC migration programme for a 5,000-employee enterprise is estimated in the range of $500,000 to $2 million in total, covering cryptographic discovery tooling, professional services, and HSM replacement for critical systems. This estimate is derived from published NIST NCCoE migration guidance (SP 1800-38) and industry analyst ranges from Gartner, IDC, and ISACA publications from 2023 to 2024.

The comparison is not strictly like for like. QKD provides information-theoretic key establishment. PQC provides computational security against quantum adversaries. But for threat models involving HNDL against enterprise data with a Q-Day horizon of 2033 to 2035, per the GRI 2024 expert survey, NIST PQC migration addresses the risk at a fraction of QKD deployment cost, at enterprise scale, without physical infrastructure dependencies. The NCSC's 2020 QKD whitepaper and the NSA's August 2021 QKD FAQ both reach the same conclusion: PQC is the practical migration path for the vast majority of organisations. For the technical case on where each technology operates, see our article on the practical limitations of QKD in enterprise environments.

The Limited Scenarios Where QKD Delivers Return

The NSA's August 2021 position is precise and worth quoting directly: “NSA does not support the usage of QKD as the sole quantum-resistant solution for national security systems. However, NSA does see value in QKD for research and limited government/military applications.” Three scenarios fit within that framing.

The first is government and defence communications where HNDL risk is immediate and the threat model explicitly requires information-theoretic key establishment. This means a government body that has assessed that its adversary is or will be capable of breaking PQC in the future, has the capital to fund QKD infrastructure, and cannot accept the residual computational security assumption that PQC carries. The UK GCHQ and NCSC have acknowledged that QKD may have a role in specific government applications, with the caveat that it must be supplemented by classical security measures, not used in isolation.

The second scenario is regulated financial infrastructure where both counterparties and the regulator mandate quantum-secured settlement rails. The Bank for International Settlements and European Central Bank have run QKD pilot experiments for interbank settlements. Singapore's Monetary Authority included QKD in quantum security framework pilots. These are regulated payment rail scenarios where the decision is driven by regulator mandate and bilateral counterparty agreement, not by individual procurement calculation. For most financial institutions, the PQC migration path under DORA and NIS2 applies instead.

The third scenario is research networks with a formal requirement for information-theoretic security, typically academic and national laboratory collaboration networks where the research sensitivity justifies the cost and where government funding is available. The Pan-European OPENQKD project and the UK Quantum Network are examples of this category.

The Hybrid Architecture Question

Some organisations ask whether a hybrid PQC-QKD architecture captures the benefits of both. The architecture is technically feasible: PQC handles the computational security layer using ML-KEM key exchange in TLS, while QKD provides quantum-secured rekeying for the most sensitive channels. ETSI publications and government pilot documentation describe this hybrid approach.

The practical problem with hybrid deployment is additive cost. Both systems must be deployed, maintained, and managed. The QKD layer does not replace the PQC layer; it supplements it. An organisation that cannot justify QKD on its own merits does not improve the cost case by adding it on top of a PQC migration programme. The incremental security benefit of QKD over a properly implemented PQC layer is real but narrow, and it costs $1 million or more to obtain.

The exception is forward secrecy in very high-sensitivity contexts. A PQC-QKD hybrid provides defence in depth if either the PQC algorithm or the QKD implementation is later found to be vulnerable. For organisations with a formal defence-in-depth requirement at that level, hybrid architecture is a rational choice. In practice, those organisations sit almost exclusively within the government and regulated financial categories described above.

A Decision Framework for QKD Evaluation

Three questions determine whether QKD belongs in scope for an organisation's security programme. First: is the threat model an adversary with the resources to collect encrypted traffic today and decrypt it post-Q-Day? If not, the HNDL risk that motivates QKD does not apply, and PQC migration is the appropriate response. For most commercial enterprises, this question resolves to no. For classified government communications and high-value financial infrastructure, it may resolve to yes.

Second: does the use case require information-theoretic security for key establishment, meaning unconditional security rather than computationally bounded security? PQC provides computational security against quantum adversaries, which is sufficient for almost all commercial applications. Information-theoretic security adds cost and operational complexity that is only justified where the adversary is assumed capable of breaking PQC in the future.

Third: can the organisation bear $1 million to $5 million in infrastructure cost, plus ongoing operational cost, for QKD? For most organisations, the answer to the third question makes the first two moot. If the organisation answers yes to all three, QKD belongs in scope. If any answer is no, PQC migration is the correct path. For guidance on starting that migration, see How to Start a PQC Migration Programme and our coverage of NIST PQC standards for enterprise.

About the Author

Steven Vaile is a quantum security and post-quantum cryptography consultant and the founder of Quantum Security Defence. He advises enterprises and government bodies on PQC migration strategy, cryptographic governance, and quantum risk assessment. He has spoken at international security conferences on the intersection of quantum computing and critical infrastructure protection.