Skip to content

47-Day Certificates Are Coming. Are You Ready?

Act Now →

Why PQC, Not QKD, Is the Enterprise Migration Path

Introduction to PQC

Quick answer: For enterprise migration planning, PQC is the practical path and QKD is not, and the reasoning comes down to deployability rather than theoretical security. PQC is a software and firmware upgrade that runs on existing computers and network equipment; QKD requires dedicated fiber optic links or line-of-sight connections and specialized quantum hardware that cannot be deployed as a cloud service or run over standard internet infrastructure. The NSA has stated it does not recommend QKD for National Security Systems, citing cost, infrastructure requirements, and unresolved technical limitations, and the UK’s National Cyber Security Centre has taken a similar public position. This guide compares the two directly across the dimensions that actually matter for an enterprise decision.

QKD gets attention because the underlying physics is genuinely elegant: a communication channel where eavesdropping is detectable by the laws of quantum mechanics rather than computational assumptions. For enterprise infrastructure planning, that elegance doesn’t translate into deployability, and conflating “theoretically interesting” with “practical migration path” is a real risk to a PQC roadmap that gets sidetracked chasing QKD pilots instead.

Key Takeaways

  • PQC deploys as a software and firmware update on existing infrastructure; QKD requires dedicated fiber or line-of-sight links and specialized quantum hardware that cannot run as a cloud service.
  • The NSA has stated it does not recommend QKD for National Security Systems, and the UK’s NCSC has taken a similar public non-endorsement position for government and military use.
  • QKD distributes only key material, not the data itself, and does not natively provide authentication, requiring classical or post-quantum cryptography alongside it regardless.
  • QKD’s practical range is limited to tens of kilometers on fiber before requiring “trusted nodes,” each of which introduces its own security and infrastructure cost.
  • PQC is standardized under finalized NIST FIPS documents with broad platform and vendor support already shipping; QKD has no equivalent enterprise standardization or vendor ecosystem maturity.

The Comparison, Dimension by Dimension

DimensionPQCQKD
DeployabilitySoftware/firmware update on existing hardwareRequires dedicated fiber or line-of-sight links plus specialized quantum hardware
InfrastructureRuns over standard internet and existing network equipmentCannot run as a cloud service; needs purpose-built physical links
AuthenticationProvides both confidentiality and authentication nativelyDistributes key material only; needs separate authentication mechanism
DistanceNo inherent distance limitTens of kilometers on fiber before requiring trusted nodes
Assurance basisComputational hardness assumptions, publicly analyzed for yearsPhysical principles, but practical implementations carry engineering vulnerabilities
CostAlgorithm and software update costSubstantial capital cost for dedicated links and specialized hardware
StandardizationFinalized NIST FIPS 203, 204, 205 standardsNo equivalent enterprise standardization; largely research and niche deployment
Enterprise use casesGeneral-purpose: TLS, VPN, PKI, code signing, every current cryptographic use caseNarrow: point-to-point links between fixed, high-value locations

PQC Advisory Services

Gain post-quantum readiness with expert-led cryptographic assessment, migration strategy, and hands-on implementation aligned to NIST standards.

Where National Security Agencies Actually Stand

The NSA has publicly stated that it does not recommend QKD or quantum cryptography for securing National Security Systems, citing quantum-resistant cryptography as a more cost-effective and easily maintained solution given QKD’s current limitations. CNSA 2.0 explicitly excludes QKD from National Security Systems entirely. The UK’s National Cyber Security Centre has taken a comparable position, stating it will not support QKD for government or military applications and recommending PQC as the primary defense against future quantum threats, while noting for civilian use that QKD should never be relied on alone and must be paired with strong classical authentication if used at all. It’s worth noting this isn’t a universal global consensus, the EU’s EuroQCI initiative and China’s own quantum communication infrastructure investment reflect a different bet, but for enterprise planning aligned with US and UK guidance specifically, the direction is unambiguous.

Why Authentication and Distance Are Disqualifying for Most Enterprise Use Cases

Two limitations matter most for a practical enterprise comparison. First, QKD distributes cryptographic key material through quantum channels, but it does not authenticate the source of that transmission; source authentication still requires classical or post-quantum asymmetric cryptography, or pre-placed keys, layered alongside it. This means QKD doesn’t replace PQC or classical cryptography even where it’s deployed; it adds a parallel, expensive key-distribution mechanism on top of infrastructure you still need anyway. Second, practical QKD range on fiber runs to tens of kilometers before requiring trusted intermediate nodes, and each trusted node is a physical location that must itself be fully secured, introducing exactly the kind of infrastructure and insider-threat cost that makes QKD impractical for anything beyond a small number of fixed, high-value point-to-point links.

What We’d Actually Recommend

Build your enterprise quantum-readiness roadmap around PQC exclusively for the general-purpose cryptographic infrastructure, TLS, VPN, PKI, code signing, that makes up the overwhelming majority of any organization’s cryptographic footprint. If your organization has a genuinely narrow, high-value, fixed-location use case where QKD’s specific properties might apply, evaluate it as a specialized, additive investment layered on top of PQC and classical authentication, not a substitute for the PQC migration your broader infrastructure requires regardless.

How Encryption Consulting Can Help

Our PQC Advisory Services build migration roadmaps around the standardized, broadly deployable path this guide describes, ensuring budget and engineering effort go toward the infrastructure that actually protects your full cryptographic footprint rather than a narrow, high-cost QKD pilot with limited applicability.

CBOM Secure maps that full cryptographic footprint, so your migration investment is sized against the general-purpose infrastructure PQC actually addresses.

Deployability Decides This, Not Theory

QKD’s physics is real and its theoretical security properties are genuinely interesting, but enterprise migration planning has to answer a different question: what can actually be deployed, broadly, on infrastructure you already have, at a cost that scales to your real environment. PQC answers that question directly, as a software and firmware update backed by finalized standards and a maturing vendor ecosystem. QKD, requiring dedicated physical links, specialized hardware, and still needing separate authentication alongside it, answers it for a narrow set of fixed, high-value point-to-point cases at best. For the general-purpose cryptographic infrastructure every enterprise actually runs, PQC is the migration path, and treating QKD as an alternative rather than a specialized niche is where roadmaps go astray.

Frequently Asked Questions

Does the NSA recommend QKD for enterprise or government use?

No. The NSA has stated it does not recommend QKD for securing National Security Systems, citing quantum-resistant cryptography as more cost-effective and easily maintained given QKD’s current limitations, and CNSA 2.0 explicitly excludes QKD from National Security Systems.

Can QKD replace PQC or classical cryptography entirely?

No. QKD distributes key material only and does not natively provide authentication. Source authentication still requires classical or post-quantum asymmetric cryptography alongside it, so QKD adds infrastructure rather than replacing the cryptography you still need.

Why can’t QKD be deployed as a cloud service the way PQC can?

QKD depends on dedicated fiber optic links or line-of-sight connections and specialized quantum hardware like single-photon detectors, which cannot be virtualized or run over standard internet infrastructure the way a software-based PQC algorithm can.

What is QKD’s practical range limitation?

Tens of kilometers on fiber before requiring trusted intermediate nodes, each of which must itself be physically secured, introducing additional infrastructure cost and insider-threat risk that limits QKD’s practicality beyond a small number of fixed, high-value links.

Is there global consensus against QKD?

No. The US and UK have taken a clear non-endorsement position for government and military use, but the EU’s EuroQCI initiative and China’s quantum communication infrastructure investment reflect significant, ongoing investment in QKD elsewhere, so the picture varies by region and policy environment.