Where QKD Makes Sense and Where It Does Not

Quantum Key Distribution appears in vendor proposals, government white papers, and board-level security briefings with a frequency that outpaces practical deployments by a significant margin. Part of the problem is that QKD's security guarantee, information-theoretic forward secrecy for key distribution, is genuinely impressive when stated in abstract terms. Part of the problem is that the conditions under which that guarantee applies are narrow enough that most organisations will never meet them.

This article is a decision framework, not a technology advocacy piece. It draws on the published positions of NSA (August 2021), NCSC (October 2020), BSI, and the January 2024 joint position paper from ANSSI, BSI, NLNCSA (Netherlands), and the Swedish National Communications Security Authority to establish where QKD has a legitimate role and where deploying it would divert resources from the PQC migration work that cannot be deferred. The goal is to give security architects a clear set of criteria they can apply to an actual procurement question or board enquiry.

The short answer: QKD is appropriate for a narrow set of government and classified deployments meeting specific topology, distance, and threat profile requirements. For enterprise WAN, distributed connectivity, digital signatures, certificate infrastructure, and any use case requiring scale or cost efficiency, PQC migration is the correct path.

What QKD Does and Does Not Provide: The Security Scope

QKD protocols, including BB84 (Bennett and Brassard, 1984), E91 (Ekert, 1991), and their variants including CV-QKD and MDI-QKD, use quantum mechanical properties of photons to establish a shared secret key between two parties. The no-cloning theorem guarantees that any interception attempt disturbs the quantum state detectably, causing elevated quantum bit error rates that reveal eavesdropping.

What QKD provides is information-theoretic security for the key establishment step over a dedicated quantum optical channel. The keys produced are then used in a classical symmetric cipher, typically AES-256-GCM, for bulk data encryption. ETSI GS QKD 014 V1.1.1, which defines the REST-based key delivery API for QKD systems, makes this layered architecture explicit.

What QKD does not provide is equally important to state precisely. It does not provide authentication of the communicating endpoints. It does not provide digital signatures, code signing, document signing, or certificate issuance. It does not protect data at rest. It does not support asymmetric cryptographic operations of any kind. NSA's August 2021 advisory explicitly lists these scope limitations.

The Authentication Dependency

Every QKD protocol requires an authenticated classical channel to prevent man-in-the-middle attacks. Without authentication, an adversary intercepts the quantum channel and substitutes their own, establishing separate keys with each party. The authentication of the classical channel must itself be cryptographically secured, historically using pre-shared symmetric keys or information-theoretically secure MACs. In practice, many QKD deployments rely on classical asymmetric authentication for this step, which is itself quantum-vulnerable.

NCSC's October 2020 QKD white paper identifies the classical authentication and control channels required for QKD as additional attack surfaces not covered by the quantum security proof. This is not a minor caveat. The practical security of a QKD deployment depends heavily on the security of the classical authentication layer that QKD theory requires as a precondition.

Where QKD Makes Sense: Three Genuine Use Cases

Classified Government Point-to-Point Links

The clearest legitimate use case for QKD is a short-distance, point-to-point link between two government or defence facilities with a specific threat profile: an adversary with long-term data collection capability, the computational resources to eventually attack classical key exchange, and no ability to compromise the physical QKD hardware or the authentication layer. The NSA QKD FAQ implicitly acknowledges this context by noting that QKD provides forward secrecy over the quantum channel in ways that complement physical key transport alternatives.

The relevant comparison point here is not PQC. It is the physical key transport via courier that classified government networks have used for decades. Where a permanent fibre infrastructure already exists between two fixed, continuously staffed facilities, QKD can replace or supplement courier-based key distribution. That is a legitimate security gain in a very specific context.

The distance constraint matters. Direct fibre QKD without trusted node relays is practical up to roughly 100 to 150 km before photon attenuation reduces key generation rates to impractical levels. Commercial QKD systems achieve key rates of approximately 10 to 100 kbps over metropolitan distances of 10 to 50 km; rates drop sharply beyond that. Research into twin-field QKD (Lucamarini et al., Nature 557, 2018) has extended the theoretical range, but commercial systems operate within these constraints today.

Regulated Financial Sector Pilots

Some central banks have explored quantum-safe payment infrastructure in research programmes (BIS Innovation Hub, ECB-CTA pilots), though no production deployments are documented. No regulatory body has mandated QKD for any payment rail. Financial institutions considering QKD should treat it as a complement to PQC evaluation, not a substitute for it. These evaluation activities exist precisely because central banks want to understand the technology's constraints before any deployment decision.

Research and Scientific QKD Networks

Academic and national quantum research networks, including UKQN (funded through EPSRC) and EuroQCI (the European Quantum Communication Infrastructure programme launched by the European Commission in 2021), deploy QKD for foundational research into quantum network architectures, entanglement distribution, and quantum repeater development. These networks explicitly frame current deployments as research infrastructure. This is a valid use case: the goal is to learn what works at scale, not to secure production systems. The outputs from these networks inform the design of quantum repeater technology that could eventually remove the distance limitation.

Where QKD Does Not Make Sense

Enterprise WAN and Distributed Connectivity

Enterprise WAN environments require connectivity between many sites, devices, and users. QKD requires a dedicated optical fibre pair for each communicating pair of endpoints. A company with 50 sites would require 1,225 dedicated fibre links for full mesh QKD coverage. The scaling problem is O(n2): adding nodes multiplies the infrastructure requirement. No enterprise with distributed offices, remote workers, mobile users, SaaS applications, or cloud connectivity can address those use cases with QKD.

NSA states in its August 2021 advisory that QKD alone cannot address the key management, authentication, and access control requirements of complex enterprise networks. Branch networking, remote access, and cloud connectivity are architecturally incompatible with QKD. These use cases require PQC migration.

Beyond 100 km Without Trusted Nodes: The Security Break

When distance exceeds practical fibre limits, the only way to extend QKD range is through trusted nodes: intermediate relay points that receive, measure, re-encode, and retransmit quantum keys. ETSI GS QKD 007 V1.1.1 defines the trusted node architecture and its implications.

A trusted node is classical computing equipment that temporarily holds plaintext key material. If a trusted node is compromised, the entire security chain breaks. Introducing trusted nodes means the system is no longer unconditionally secure. Security now depends on the trustworthiness of every intermediate node, which is a classical security assumption, not a quantum one. Both NCSC's October 2020 paper and NSA's August 2021 advisory explicitly identify trusted nodes as the primary mechanism by which QKD's unconditional security guarantee is voided in practice.

Throughput and Cost

Commercial QKD systems in 2026 generate keys at rates between roughly 10 kbps and several hundred kbps over metropolitan distances. This is orders of magnitude below the throughput requirements of high-speed networking. Capital expenditure for a metropolitan QKD link typically runs to six figures in sterling or euros for hardware alone, plus ongoing maintenance and dedicated dark fibre leasing. These costs are appropriate for a classified government facility with a specific threat profile. They are not appropriate for securing an organisation's general enterprise communications estate.

Agency Positions: What NSA, NCSC, and BSI Actually Say

The published positions of major security agencies are unambiguous and worth quoting directly rather than paraphrasing into a softer version.

NSA (August 2021): “NSA does not support the usage of QKD or QC to protect communications in National Security Systems (NSS), and does not consider QKD a practical security solution.” The NSA cites high cost, limited scalability, authentication dependency, and the maturity of PQC as the viable alternative.

NCSC (UK, October 2020): NCSC does not endorse QKD for government or military applications, citing the authentication dependency, trusted node vulnerabilities, physical implementation attack surface, and lack of open standards compared to PQC.

BSI's cryptographic recommendations (TR-02102 series) recommend NIST-standardised PQC as the primary quantum migration path. The January 2024 joint position paper from ANSSI, BSI, NLNCSA (Netherlands), and the Swedish National Communications Security Authority recommended NIST PQC algorithms as the primary migration path, treating QKD as complementary for specific government use cases only. The joint position paper is available at bsi.bund.de.

Decision Framework: Should You Deploy QKD?

Run through these six questions before any QKD procurement evaluation:

  1. Is the use case a dedicated point-to-point link between two fixed, permanently staffed facilities? If not, QKD is not appropriate.
  2. Is the distance below 150 km, or is a trusted-node relay chain with fully vetted physical security acceptable? If neither applies, QKD's unconditional security guarantee does not hold.
  3. Is the primary security need key establishment only, not authentication, signatures, or data-at-rest encryption? If the need extends beyond key distribution, QKD cannot address it.
  4. Is the specific threat model a cryptographically relevant quantum computer combined with long-term traffic capture, and is PQC migration unavailable for this specific link? If PQC can address the link, it should.
  5. Is the budget, infrastructure, and operational overhead acceptable? Six-figure capital investment plus dark fibre and maintenance is the realistic entry point.
  6. If all of the above conditions are met: QKD may add value as a complement to PQC on that specific link. Not as a replacement. Both should be evaluated together.

What QKD Does Not Replace: The PQC Migration Obligation Remains

Even where QKD is deployed, it addresses exactly one security function: key distribution over one dedicated link. It does not address digital signatures, certificate infrastructure, code signing, or data at rest. An organisation that deploys QKD for one inter-site connection still needs ML-KEM (FIPS 203), ML-DSA (FIPS 204), and SLH-DSA (FIPS 205) across its entire cryptographic estate. NIST IR 8547 IPD deprecation timelines apply regardless of QKD deployment.

The practical conclusion for most organisations is straightforward. Invest in PQC migration first and completely. Then, if a specific link meets all six criteria above, consider QKD as an additional layer for that link. The sequence matters because QKD on one link while the rest of the estate remains quantum-vulnerable is an expensive way to secure a small fraction of the risk. For an explanation of why QKD and PQC address fundamentally different problems across the full cryptographic estate, see Why QKD Is Not a Substitute for PQC Migration. For practical guidance on how to start migration planning, see How to Start Your PQC Migration and QKD Practical Limitations for Enterprise.

QSECDEF's advisory programme supports organisations evaluating both QKD and PQC decisions in the context of their specific threat model and compliance obligations. Expert Membership provides structured access to that programme for organisations working through procurement decisions now.