QKD vs Post-Quantum Cryptography: Why Agencies Prefer Math
Two answers to one problem
A big, error corrected quantum computer running Shor's algorithm could break the public key math behind much of today's secure internet (see RSA explained). The world has two families of defense. Post-quantum cryptography (PQC) swaps in new math problems that quantum computers are not known to solve quickly. Quantum key distribution (QKD) uses the physics of single photons to share secret keys. If you want the basics of QKD first, read QKD explained.
The big practical difference
PQC is software. It runs on the laptops, phones and servers we already have, over the fiber and Wi-Fi we already have. NIST has been standardizing it for years (see the NIST process). QKD is hardware. It needs special photon sources and detectors, and it usually needs a dedicated fiber or a clear line of sight through the air or space. That one difference shapes almost every official opinion below.
What the NSA says
According to a 2026 summary by PostQuantum.com of the NSA's rewritten statement, the agency lists five limitations, unchanged since its first public QKD guidance on October 26, 2020:
- QKD supplies keys but does not authenticate who is on the other end.
- It requires dedicated fiber or free-space equipment.
- QKD networks often depend on trusted relays.
- Real-world security depends on hardware and engineering, not just the physics.
- The sensitivity that reveals an eavesdropper also makes denial-of-service attacks easier.
The same report says the 2026 rewrite adds that changing environmental conditions and physical wear can lower the security established when a device was certified. The NSA's position, as reported, is that it does not recommend QKD or other quantum cryptography for protecting National Security Systems unless these limits are overcome, and its CNSA 2.0 FAQ reportedly tells owners of those systems not to use or research QKD without talking to the NSA first. CNSA 2.0 itself lists no QKD option. See government deadlines for the dates.
What the UK NCSC says
The UK's National Cyber Security Centre reaches a similar view in its QKD white paper. It does not endorse QKD for government or military use, advises against relying on it alone for business critical networks, and sees quantum-safe cryptography as the best defense. Its reasons include the need for specialised hardware, and the fact that QKD protocols do not provide authentication, which leaves them open to physical man-in-the-middle attacks. It also says integrating QKD into complex classical systems needs more research, and it welcomes that research.
Why authentication matters so much
Imagine two offices using QKD. The physics can tell them nobody tapped the fiber between them. It cannot tell them the person at the other end is really their colleague. To fix that, QKD systems still need classical authentication, and that authentication itself has to be quantum-safe. So QKD does not escape the need for good cryptography. It adds a layer on top of it.
Does that make QKD a dead end?
No, and this is the optimistic part. The agencies criticize QKD as a replacement for PQC, not the science. The NSA article reportedly says the strongest uses of quantum cryptography may lie in a broader, fully quantum network that links quantum computers and quantum sensors, and it calls those uses theoretical for now. That is exactly where networking research is heading (see the quantum internet). Some governments and companies also run QKD pilots alongside PQC, treating it as an extra layer.
A simple way to think about it
| PQC | QKD | |
|---|---|---|
| Type | Software and math | Special optical hardware |
| Runs on | Today's computers and networks | Dedicated fiber or free-space links |
| Authentication | Covered by PQC signatures | Needs a separate method |
| Long distance | Anywhere the internet reaches | Trusted relays or satellites today |
| Agency stance (NSA, NCSC) | Preferred path | Not recommended for government systems |
What to do with this
If you run systems, the practical advice is to inventory your cryptography and plan a move to PQC, a habit called crypto agility. Data stolen today can be decrypted later, which is the harvest now, decrypt later risk. For crypto users, see PQC and crypto. This is education, not financial advice.
Sources and further reading
- NSA: Post-Quantum Cybersecurity Resources (QKD position)
- PostQuantum.com: NSA QKD guidance rewrite (single secondary report of the 2026 rewording)
- UK NCSC: Quantum key distribution white paper
- PQShield: NSA update to CNSA 2.0
Reported as of 2026-10-09. Quantum networking results are mostly lab or pilot demonstrations, and schedules slip. Check the primary papers and agency pages before relying on any figure. Nothing here is financial advice. QNT is an independent community memecoin and is not linked to Quantinuum Ltd or any lab, company or government.
Frequently asked questions
Does the NSA think QKD is useless?
Not exactly. As reported, it does not recommend QKD for National Security Systems unless several limits are overcome, and it sees theoretical value in future fully quantum networks.
Which is easier to deploy, PQC or QKD?
PQC. It is software on existing hardware, while QKD needs special optical equipment and often dedicated links.
Can QKD work without PQC or other cryptography?
No. QKD does not authenticate the other party, so it still needs a separate, quantum-safe authentication method.
Is this investment advice?
No. This is education only, and QNT is an independent community token not linked to any lab or agency.
Keep reading
- Quantum Key Distribution (QKD) Explained vs Post-Quantum Cryptography
QKD uses quantum physics to share encryption keys. Learn how it works, its limits, and how it differs from post-quantum cryptography. - The NIST Post-Quantum Process Explained
How NIST ran its multi-year post-quantum cryptography competition, from public call to the first standards in 2024, and what work is still continuing. - Government Post-Quantum Deadlines: NIST, NSA CNSA 2.0 and Federal Migration
The dates governments have set to move off RSA and elliptic curves: NIST 2030 and 2035, NSA CNSA 2.0 milestones, and the January 1, 2027 acquisition rule. - Post-Quantum Cryptography and Crypto: What It Means
Why large quantum computers could threaten blockchain signatures, and what post-quantum cryptography is doing about it.
All Quantum computing guides | Back to top | Search the site
Main pages: Quantum computing explained | Quantum and crypto | Companies | Quantum news | Glossary