HEQA Security — From the Ground Up: Why "QKD First" is the Most Practical and Secure Transitional Path Towards Quantum Safety
Share
"If a routine software update is enough to cause massive system-wide outages (blue screens of death) across global airports, financial institutions, media, and healthcare systems, why would we choose a riskier, comprehensive overhaul of the entire software architecture when implementing a 'post-quantum security' strategy?
In fact, there is a more robust and lower-risk path: prioritize defense at the fiber optic transmission layer (physical layer), rather than blindly attempting a simultaneous software re-architecture across all end devices."
Executive Summary
The current mainstream approach for transition involves comprehensively inventorying cryptographic assets, upgrading all systems to Post-Quantum Cryptography (PQC), and subsequently (possibly) deploying Quantum Key Distribution (QKD) on a few "specific" links. While well-intentioned, this approach comes with high costs, slow timelines, and vulnerabilities introduced by integration flaws. More critically, it fails to immediately bolster the defense blind spots most coveted by attackers: the core transmission pipelines between large data centers.
PQC is indeed indispensable, and the standards issued by NIST in 2024 (FIPS 203–205) are landmark achievements. However, the migration to PQC is far from a simple "software switch." It significantly increases computational load on hardware and firmware, enlarges handshake packet sizes, and has repeatedly led to middleware crashes due to incompatibility in real-world applications.
In contrast, QKD offers a security dimension that PQC cannot provide: physically verifiable key delivery. QKD operates in an "out-of-band" mode, effectively mitigating system availability (uptime) risks during architectural changes and immediately strengthening data transmission security on core links (including data center-to-data center, data center-to-cloud, headquarters-to-data center, and backbone networks). Enterprises can adopt a "low blast-radius" strategy by prioritizing QKD deployment, then systematically rolling out PQC across the entire network.
Currently, QKD pilot projects and deployments are widespread globally (including EU testbeds and telecom operator trials, US Department of Energy-funded demonstration projects, and national-scale networks in Japan, Singapore, South Korea, and China). While national security agencies still hold differing opinions, infrastructure development programs and operators have accumulated extensive operational experience in practical applications.
Admittedly, I have a direct vested interest in this technological transition—my daily work involves building quantum-safe networks. If I believed that "a complete and immediate rollout of PQC" could enhance security more quickly, I would say so unequivocally. However, the core argument here is highly pragmatic: "QKD first, then PQC" is the optimal deployment sequence for reducing operational risks and immediately boosting defensive resilience. It enables enterprises to achieve the ultimate desired architecture—a hybrid defense deployment of PQC and QKD—with lower costs and a smoother operational process.
The Current State of "Consensus" – and Over-reliance on the Software Layer
The primary reason why agencies, led by national regulators, are prioritizing Post-Quantum Cryptography (PQC) is its theoretically excellent scalability, which does not require re-laying fiber optic infrastructure. In 2024, the National Institute of Standards and Technology (NIST) officially finalized ML-KEM (Key Establishment), ML-DSA (Lattice Signature), and SLH-DSA (Hash Signature) as FIPS 203-205 standards. For example, the UK National Cyber Security Centre (NCSC) has published a public roadmap for the full deployment of PQC (media reports indicate that large organizations are expected to complete the migration by 2035). While these strategic directions are correct, this narrative is incomplete.
The brutal reality often overlooked by industry is that so-called "pure software" solutions are practically never purely confined to the software layer.
-
Significantly inflated message and key sizes: ML-KEM-768 under FIPS 203 requires 1,184 bytes for the public key and 1,088 bytes for the ciphertext; ML-DSA-65 (equivalent to Dilithium security level) has a signature length of approximately 3.3 KB and a public key of approximately 1.9 KB. Compared to the handshake and signature sizes of current X25519 or ECDSA, these figures show an increase of "several orders of magnitude," which will have cascading domino effects on end devices and network middleboxes.
-
Real-world system outages have already occurred: During previous tests of hybrid post-quantum TLS protocols by Chrome and Cloudflare, some older routers and middleboxes crashed due to their inability to process oversized "Handshake Records," directly leading to connection interruptions. This ironclad evidence demonstrates that any verbal "software update" will inevitably run up against the physical barriers of network hardware and firmware.
-
The heavy burden of "inventory first, then advance": Official U.S. guidance (jointly issued by CISA, NIST, and NSA) requires enterprises to first establish a complete "Cryptographic Inventory" and possess "Crypto-Agility" in their architectural design. This preparatory work alone presents an extremely daunting architectural burden for enterprises even before the first PQC-protected network connection is officially enabled.
The challenges mentioned above are not intended to negate the value of PQC, but rather to strongly oppose the blind adoption of "comprehensive PQC rollout" as the first step in an enterprise's quantum security transformation.
QKD Adds Functionality That PQC Cannot
-
Physics-backed key distribution. Quantum Key Distribution (QKD) uses single photons; any eavesdropping will cause a measurable disturbance to the signal, so you know if the key exchange has been tampered with. This is information-theoretic assurance, not a gamble on perfect math.
- Out-of-band and low blast-radius. QKD systems run in parallel to the data plane on specific links, so you can harden DC↔DC, DC↔Cloud PoPs (including AWS DirectConnect, Azure ExpressRoute, and GCP Cloud Interconnect), HQ↔DC, and backbone segments without modifying every workstation, application, and firmware image on Day One.
-
Resilience under change. After the CrowdStrike incident last summer, do you really want your first “quantum-safe” step to be a mass software update across all Windows servers, routers, and applications? A Falcon sensor content update crashed ~8.5M Windows devices; airlines and hospitals were immediately impacted. Start where you can add protection without impacting uptime.
I’ve analyzed this reasoning—and the skepticism of US agencies—in detail previously; in short, PQC and QKD are complementary layers that become adversarial if we force an either/or paradigm.9
QKD’s Unique Security Domain (Beyond PQC’s Reach)
-
Physics-backed key delivery: QKD uses single photons for transmission; any eavesdropping causes measurable physical disturbances to the optical signal, allowing the system to immediately detect if key exchange has been tampered with. This mechanism provides absolute "Information-theoretic security," rather than relying on the gamble that an algorithm won't be mathematically broken in the future.
-
Out-of-band operation and low blast-radius: QKD systems are deployed on specific critical links, operating in parallel with existing data planes without interference. This means that in the initial phase of transition, enterprises can immediately enhance transmission security for data center-to-data center interconnects, data center-to-cloud endpoints (including AWS DirectConnect, Azure ExpressRoute, and GCP Cloud Interconnect), headquarters-to-data center, and core backbone networks, without modifying every workstation, application, and hardware firmware image.
-
Operational resilience in high-change environments: After the CrowdStrike system outage incident in summer 2024, should enterprises really choose to perform a massive, system-wide software update across all Windows servers, routers, and applications as their first step into "quantum security"? At that time, a mere content update for the Falcon sensor caused approximately 8.5 million Windows devices globally to crash, immediately paralyzing airlines and healthcare systems. A reasonable strategy for enterprises should be to prioritize starting at the foundational layer that "can immediately provide substantial defense without impacting system availability (uptime)."
This logic (and the reasons for official U.S. agencies' reservations) has been extensively analyzed previously; PQC and QKD should ideally form complementary, layered defense architectures. However, if we forcefully define them as an either/or adversarial sequence, it falls into the trap of extreme thinking.
What the World is Doing

This is a professional translation focusing on a comparison of global quantum security policies and a deep analysis of operational costs. The translation maintains the rigor of high-level cybersecurity whitepapers and policy analysis reports, accurately rendering specialized terminology from various governments and financial regulators (such as the Monetary Authority of Singapore), and conveying the hidden costs of a PQC-first strategy from an engineering and operational perspective:
1. United States
-
Standards and Regulations: NIST FIPS 203–205 are officially finalized—PQC is now the officially recognized security baseline. NSA's CNSA 2.0 sets the post-quantum transition timeline for National Security Systems (NSS). (It is noteworthy that the NSA has long held reservations, even negative views, on deploying QKD in national security systems.)
-
Pilot Projects & Testbeds: The US Department of Energy (DOE) and Oak Ridge National Laboratory (ORNL) successfully demonstrated QKD-protected links over commercial fiber (EPB network in Chattanooga) for utility companies, as part of a broader initiative to promote a "quantum internet." Policy Interpretation: Official policy is PQC-dominated; R&D continues to advance QKD applications in high-defense backbone networks.
2. European Union
-
Infrastructure: The EuroQCI program is building a quantum communication backbone network spanning the EU, covering terrestrial and satellite segments, thereby expanding the OPENQKD testbed operated jointly with carriers such as Deutsche Telekom and Telefónica.
-
Industry Participation: The QSAFE and Nostradamus consortia, comprising Deutsche Telekom, Thales, Austrian Institute of Technology (AIT), and Telefónica, are designing its architecture and interoperability, including test infrastructure for QKD equipment.
-
Security Agency Stance: EU national security agencies (e.g., Germany's BSI, France's ANSSI, and their Dutch and Swedish counterparts) currently classify QKD as a "niche" technology—applicable only to specific point-to-point or defense-in-depth scenarios—while urging enterprises to immediately migrate to PQC. This is precisely where the tension lies: significant policy investments are made in QKD infrastructure, yet cybersecurity authorities still insist on PQC-first.
3. United Kingdom
-
Commercial Network: BT and Toshiba operate a quantum-safe metropolitan network in London (with EY as their first client) and have industrial deployments across various research institutions.
-
Policy Direction: The National Cyber Security Centre (NCSC) is strongly advocating PQC and has published a public roadmap (as previously reported), with large organizations expected to complete migration by 2035—again, demonstrating its strategy of "PQC as baseline + localized overlay of high-defense QKD."
4. Japan
-
Operational Experience: NICT's "Tokyo QKD Network" has been operating since the 2010s, with current efforts focused on integrating QKD into NTT's All-Photon Network (IOWN) transmission technology to enable co-fiber transmission of high-capacity data and quantum keys. Additionally, Japan's CRYPTREC released an updated PQC guideline in 2024.
5. Singapore
-
Regulation-driven Adoption: The National Quantum-Safe Network (NQSN/NQSN+) is piloting QKD and quantum-safe communications for banks and critical infrastructure. The Singaporean government has pledged approximately S$300 million to develop a "National Quantum Strategy" and allocated S$100 million through the Monetary Authority of Singapore's (MAS) FSTI 3.0 program to accelerate the adoption of quantum-safe technologies (including QKD) in the financial sector.
6. South Korea
-
National Backbone: SK Broadband and ID Quantique have jointly built an approximately 800 km QKD network connecting 48 government agencies; SK Telecom is actively involved in standardization efforts to combine QKD and PQC for quantum-safe communications.
7. China
-
National Scale: Its integrated space-ground network combines the 12,000+ km "Jing-Hu Trunk" fiber backbone with satellite links, providing QKD protection across approximately 12,900 km to users. This is currently the largest deployment globally. China is the only country that explicitly mandates several critical infrastructure industries to formally commercialize (rather than merely prepare for) post-quantum security measures "today." In fact, Chinese official policy explicitly mandates the deployment of QKD, not PQC.
Software is Not "Free": The Hidden Costs of a PQC-First Approach
Let's directly confront the practical hurdles of choosing to "upgrade all systems as the first step":
-
Asset inventory is mandatory and extremely time-consuming: Any viable roadmap must begin with automated "cryptographic asset inventory" (clarifying where RSA/ECC is used, which library, what version, and who is responsible). This task will mercilessly consume significant time and project budget even before the first PQC handshake connection is officially enabled.
-
The hard reality of hardware and firmware: The significantly inflated key and handshake packet sizes will challenge the performance of IoT devices, routers, and firewalls; even resource-rich web technology stacks have experienced middleware failures during previous PQC tests. Enterprises must be prepared for cross-vendor firmware updates, protocol iterations, and interoperability testing.
-
Inherent demand for "algorithmic agility": NIST has clearly warned enterprises to maintain architectural agility, as even current PQC algorithms may be deprecated in the future. This implies endless migration projects down the line. Conversely, QKD's key security is entirely independent of whether its algorithms can be mathematically broken.
The core of this argument is not against PQC, but rather advocates for the appropriate deployment sequence: enterprises should first secure core data arteries using a physical layer technology that "does not threaten system availability (uptime) while changing engines mid-flight," and then proceed systematically with upper-layer software migration.
A Pragmatic Deployment Sequence: "QKD First, Then PQC"
Enterprises should prioritize defending the core critical points where "the attacker's potential gain is highest, and the blast radius of change is smallest":
-
Step 1: Secure Core Networks (Protect the Main Arteries)
-
Data Center-to-Data Center cross-connects
-
Headquarters-to-Data Center (HQ-to-DC)
-
Data Center-to-Cloud on-ramps
-
Backbone network links
These are the enterprise's "data arteries." QKD is deployed outside the Data Plane, immediately providing the highest standard of key exchange defense for all traffic traversing these critical links, regardless of the current update status of upper-layer applications or TLS protocol stacks.
-
-
Step 2: Quantify Key Metrics (Data-Driven Operations)
-
Track and evaluate the quantum channel's Secure Key Rates, link stability, detectable physical disturbances, and Mean Time To Recovery (MTTR).
-
Use this data to establish a baseline and concretely quantify the improved resilience of network defenses.
-
-
Step 3: Systematically Layer PQC (Gradual Reconstruction)
-
With the core network fully protected, enterprises can gradually upgrade software protocol stacks to ML-KEM, ML-DSA, or SLH-DSA standards, based on their cryptographic asset inventory.
-
This ensures that even if upper-layer software changes unexpectedly cause system crashes (go sideways), the enterprise's most valuable data-in-motion remains rigorously protected by the underlying physical defense network.
-
-
Ideal End State: PQC + QKD Hybrid Defense Architecture
-
This is the ultimate form of Defense-in-Depth that the global telecommunications industry is actively designing and standardizing (e.g., ETSI, ITU-T).
-
This deployment sequence aligns perfectly with the practical experiences of enterprises in major international cities like London, Berlin, and Madrid—deploying QKD on commercial fiber first, and then using it as a foundation for iterating and upgrading upper-layer software.

Frequently Asked Questions
-
"Our national cybersecurity authority says QKD is only for specific niche technologies."
-
Answer: Indeed, European security agencies (such as Germany's BSI, France's ANSSI, and their Dutch and Swedish counterparts) currently emphasize PQC first and position QKD as a niche application. However, these two perspectives are not contradictory in practice: the cautious approach of regulators regarding "wholesale blind replacement" can perfectly coexist with QKD's core value as a defense-in-depth layer on "a few critical links." And these critical links are precisely where I advocate enterprises should start.
-
"The architecture of Trusted Nodes compromises security."
-
Answer: In engineering practice, a "trusted relay node" is a clear architectural trade-off, not a fatal flaw—especially on controllable metropolitan or backbone routes managed by telecom operators, where machine rooms, racks, and physical lines are already hardened to the highest specifications. Using QKD with trusted nodes to secure core data arteries is an immediate and effective approach; future upgrades based on "entanglement-based" QKD are part of a long-term blueprint to reduce trust risks to near zero, but they are by no means a prerequisite for mitigating current operational risks.
-
"Isn't QKD just a science project in a research lab?"
-
Answer: Perhaps in the past, but certainly not now. Look at the EU's EuroQCI program, the OPENQKD final report, BT and Toshiba's metropolitan network in London, Japan's NICT Tokyo network, South Korea's SK Broadband's 800 km deployment, and various field demonstrations funded by the US Department of Energy. These are no longer exotic lab curiosities, but real battlegrounds where leading global operators are learning how to operate and maintain quantum-safe backbone networks at scale.
-
"How should uptime and potential risks be assessed?"
-
Answer: Unlike PQC, QKD is "deployed in parallel" with existing data paths, rather than being embedded directly (in-line). Even if QKD equipment accidentally reboots, your end systems will absolutely not experience a blue screen crash as a result. In contrast, the previous CrowdStrike software update instantly paralyzed approximately 8.5 million Windows devices globally and caused countless flight cancellations. When driving enterprise architecture modernization, smart decision-makers should prioritize the stable first step that "can both elevate security and not threaten daily operations."
-
Costs and ROI (The Board's Core Focus)
-
"PQC First" Strategy: Front-loaded Costs and Delayed Effects This strategy forces enterprises to invest vast resources upfront in asset inventory, comprehensive firmware upgrades, cross-vendor interoperability testing, and application refactoring. While these tasks are necessary, for the core, highest-value data traffic of the enterprise, the tangible reduction in risk they can bring in the short term is negligible before the overall complex software engineering "grand project" is completed.
-
"QKD First" Strategy: Precise Allocation, Immediate Results, Ensured Service Continuity This strategy advocates focusing limited Capital Expenditure (CAPEX) and Operating Expenses (OPEX) on a "very small number of extremely high-value" core data arteries. Not only can it produce quantifiable security benefits (any eavesdropping is physically detectable), but more importantly, when migrating upper-layer software later, it will absolutely not threaten existing Service Level Agreements (SLAs) or system availability.
Core Decision Summary: In the defense blueprint for elevating the enterprise's overall Cybersecurity Posture, "QKD First" represents the highest Return on Investment (ROI) and the lowest technical change risk. It builds a solid physical defense network for the enterprise, thereby laying the most stable foundation for the subsequent clean and smooth introduction of PQC.
Future Evolution (Quantum Entanglement and Architectural Integration)
The core of this technology roadmap is not an either/or choice between "QKD or PQC," but rather the combined power of "QKD + PQC," which will smoothly upgrade to an entanglement-based network architecture when the technology matures in the future.
The National Institute of Information and Communications Technology (NICT) in Japan recently demonstrated the deep integration of QKD and high-capacity optical transmission technology on NTT's Open APN (all-optical network); meanwhile, the U.S. Department of Energy's (DOE) blueprint initiative is actively pushing for the creation of a U.S. quantum internet. Both milestones clearly reveal a future trend: traditional data layers and quantum defense layers will co-travel on the same optical fiber. Early adopters of QKD will then have existing operational muscle memory, enabling a seamless architectural upgrade.
How to give a concise 15-minute briefing to a CISO
-
Identify Crown Jewels: Clearly define the enterprise's lifeline data flows (e.g., data center interconnect, data center to cloud, headquarters to data center).
-
Layer 1 Foundation First: Deploy QKD on these critical links and integrate quantum keys directly into the existing key management and encryption mechanisms within the data path.
-
Software Layer Inventory and Planning: Simultaneously initiate a cryptographic asset inventory and plan the PQC upgrade roadmap with "Crypto-agility" as a core principle.
-
Phased Software Deployment: Systematically roll out PQC in batches, by application or domain, and rigorously monitor for any performance regressions or system conflicts.
-
Converge to a Hybrid Architecture: Ultimately achieve a deep defense state where "QKD handles Layer 1 key delivery, and PQC handles upper-layer protocols."
-
Data-driven Metric Management: Continuously track key performance indicators (including key generation rate, physical disturbance events, handshake success rate, and actual impact on SLAs).
These are all the execution steps. Calm, methodical, and fully defensible in terms of compliance and architecture.
Conclusion
Everyone has their biases, and I am no exception. However, facts speak louder than words: while PQC is an indispensable standard for the future, QKD is an immediate capability that can be deployed today on the core links carrying an enterprise's highest-value data.
As a decision-maker, there's no need for a painful either/or choice between the two; what truly needs to be done is to make the correct deployment sequence.
Start by securing the main arteries (fiber optic pipes).
Author: Nir Bar Lev, CEO of HEQA Security
- https://www.cisa.gov/resources-tools/resources/quantum-readiness-migration-post-quantum-cryptography? ↩︎
-
https://csrc.nist.gov/pubs/fips/203/ipd
↩︎ -
https://digital-strategy.ec.europa.eu/en/policies/european-quantum-communication-infrastructure-euroqci?
↩︎ - https://csrc.nist.gov/pubs/fips/203/ipd ↩︎
- https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.203.ipd.pdf ↩︎
- https://quantum.lanl.gov/cryptography.shtml? ↩︎
- https://www.cisa.gov/resources-tools/resources/quantum-readiness-migration-post-quantum-cryptography? ↩︎
- https://www.reuters.com/technology/microsoft-says-about-85-million-its-devices-affected-by-crowdstrike-related-2024-07-20/? ↩︎
- https://heqa-sec.com/blog/the-peculiar-stance-of-nist-and-the-nsa-on-quantum-cryptography-and-why-theyre-wrong/ ↩︎
- https://csrc.nist.gov/pubs/fips/203/ipd ↩︎
- https://digital-strategy.ec.europa.eu/en/policies/european-quantum-communication-infrastructure-euroqci? ↩︎
- https://www.telekom.com/en/media/media-information/archive/deutsche-telekom-partners-quantum-communication-infrastructure-642332? ↩︎
- https://cyber.gouv.fr/sites/default/files/2020/05/anssi-technical_position_papers-qkd.pdf? ↩︎
- https://www.toshiba.eu/solutions/quantum/wp-content/uploads/resources/London-Quantum-Secured-Metro-Network.pdf? ↩︎
- https://www.theguardian.com/technology/2025/mar/20/uk-cybersecurity-agency-quantum-hackers? ↩︎
- https://www.itu.int/en/ITU-T/Workshops-and-Seminars/2023/0724/Documents/Kenyoshi.pdf? ↩︎
- https://nqsn.sg/? ↩︎
- https://www.idquantique.com/quantum-safe-security/nation-wide-quantum-safe-key-distribution-network-in-south-korea/? ↩︎
- https://merics.org/en/report/chinas-long-view-quantum-tech-has-us-and-eu-playing-catch ↩︎
- https://www.cisa.gov/resources-tools/resources/quantum-readiness-migration-post-quantum-cryptography? ↩︎
- https://quantum.lanl.gov/cryptography.shtml? ↩︎
- https://csrc.nist.gov/pubs/ir/8547/ipd? ↩︎
- https://www.cmorg.org.uk/sites/default/files/2025-06/CMORG%20-%20Guidance%20for%20Post-Quantum%20Cryptography%20-%20April%202025%20-%20TLP%201%
- https://www.toshiba.eu/solutions/quantum/wp-content/uploads/resources/London-Quantum-Secured-Metro-Network.pdf? ↩︎
- https://cyber.gouv.fr/sites/default/files/2020/05/anssi-technical_position_papers-qkd.pdf? ↩︎
- https://www.nict.go.jp/en/press/2025/09/16-1.html? ↩︎
- https://digital-strategy.ec.europa.eu/en/policies/european-quantum-communication-infrastructure-euroqci? ↩︎
- https://www.reuters.com/technology/microsoft-says-about-85-million-its-devices-affected-by-crowdstrike-related-2024-07-20/? ↩︎
- https://www.cisa.gov/resources-tools/resources/quantum-readiness-migration-post-quantum-cryptography? ↩︎
- https://www.nict.go.jp/en/press/2025/09/16-1.html? ↩︎
- https://www.cisa.gov/resources-tools/resources/quantum-readiness-migration-post-quantum-cryptography? ↩︎
-
-
-