Post-Quantum Cryptography Versus Quantum Key Distribution
PQC and quantum key distribution sound alike but are very different. One is new maths in software; the other is physics over special links. Here is how they compare and what security agencies recommend.
Checked against primary sources and independently reviewed on . Sources are listed at the end.
Two technologies with “quantum” in their names are often presented as answers to the quantum threat. Post-quantum cryptography (PQC) is new mathematics that runs as software on the computers we already have. Quantum key distribution (QKD) uses the physics of light to share keys over dedicated links. Vendors sometimes blur the two, and decision makers end up comparing products that solve different problems.
This article sets out what each one is, where QKD falls short in practice, and why national security agencies in the US, UK, France, Germany, the Netherlands and Sweden all point towards PQC as the main path.
Two Different Ideas
PQC replaces the public-key algorithms behind key establishment and digital signatures with new ones built on problems that quantum computers are not known to solve efficiently. It travels over any network, fits inside existing protocols such as TLS, and can be delivered through a software update. The NSA makes the same contrast: PQC works on the platforms organisations already own, and its strength comes from hard mathematics rather than from special hardware.1
QKD works differently. Two parties send individual particles of light, usually over optical fibre, and use quantum effects to agree a key. In theory, an eavesdropper disturbs the light in a way the parties can detect. The NSA notes that QKD and the related “quantum cryptography” both need special-purpose equipment and dedicated links to do this.1
The names cause confusion because “quantum” means something different in each. In PQC it describes the attacker the algorithm is designed to resist. In QKD it describes the physical mechanism the system uses.
| Question | Post-Quantum Cryptography | Quantum Key Distribution |
|---|---|---|
| What it is | New public-key algorithms based on hard maths problems | Key sharing using quantum properties of light |
| Hardware needed | Existing computers, phones and servers | Dedicated optical equipment and links |
| Runs over the internet | Yes, inside existing protocols such as TLS and SSH | No, needs dedicated fibre or free-space links |
| Authenticates the other party | Yes, through post-quantum signatures | No, needs signatures or pre-shared keys alongside it |
| Network reach | Anywhere the network reaches | Networks often need trusted relay points |
| How it is updated | Software or firmware update | Hardware change |
| Standards | NIST FIPS 203, 204 and 205 (final, August 2024) | No equivalent NIST standard |
| Agency stance | Recommended main path by NSA, NCSC, ANSSI and BSI | Not supported by NSA for national security systems, or by NCSC for government or military use |
Where QKD Falls Short
The most basic problem is authentication. QKD can produce a shared key, but it cannot by itself prove who is on the other end of the link. The UK National Cyber Security Centre (NCSC) is direct about this: QKD does not provide authentication, so it must be combined with other cryptography to give real protection.2 There are two ways to do that. One is a digital signature, and to survive a quantum attacker that signature has to be post-quantum, which brings PQC back in. The other is a set of symmetric keys shared in advance between the sites. The NCSC notes that managing those keys makes such systems hard to scale, so they are not suited to general use.2 The NSA likewise says QKD needs either asymmetric cryptography or keys placed in advance to authenticate the source.1
The NSA lists several further limits.1 QKD cannot be delivered as software or as a network service and does not slot easily into existing equipment. Because it is hardware, it is hard to patch or upgrade. Longer QKD networks often depend on trusted relay points, which add cost and create places where an insider could see keys. The equipment is also sensitive by design, so an attacker who disturbs the link can stop it working, which raises the risk of denial of service.
There is also a gap between theory and practice. The physics behind QKD may be sound, but a real system’s security depends on the engineering of its lasers, detectors and software. The NSA points to several published attacks on commercial QKD systems and concludes that QKD security is “highly implementation-dependent rather than assured by laws of physics”.1
What Security Agencies Say
The positions are unusually consistent. For US national security systems, the NSA does not support QKD or quantum cryptography, and it does not foresee certifying any such product while the limits above remain. In its view PQC costs less and is easier to maintain.1
The UK NCSC says it will not support QKD for government or military applications and calls PQC the best mitigation to the quantum threat to cryptography.2 In January 2024, France’s ANSSI, Germany’s BSI, the Netherlands’ NLNCSA and Sweden’s National Communications Security Authority, part of the Swedish Armed Forces, published a joint paper on QKD. Their verdict was that it needs dedicated infrastructure, is limited in what it can do, fits only a few specialised settings and has not yet reached an adequate level of security assurance. They advise organisations to put PQC first.3
None of this means QKD research has no value. It means that, for an organisation planning its quantum readiness in 2026, QKD is not a substitute for migrating to PQC.
Choosing Where To Spend Effort
For nearly every organisation, the practical answer is to focus on PQC. It protects traffic over the networks you already run, fits the protocols your suppliers already support, and covers signatures as well as key establishment. The core standards, FIPS 203, 204 and 205, have been final since August 2024,4 and major browsers, libraries and messaging apps already use ML-KEM, as our article on hybrid post-quantum cryptography shows.
If a supplier proposes QKD, useful questions include how the link is authenticated, whether trusted relay points are involved, how the equipment has been independently evaluated, and what happens when the link is disrupted. The answers will usually show that PQC is still needed alongside it.
Footnotes
-
NSA, “Quantum Key Distribution (QKD) and Quantum Cryptography (QC)”, nsa.gov (page undated; accessed 7 October 2026). nsa.gov ↩ ↩2 ↩3 ↩4 ↩5 ↩6
-
UK National Cyber Security Centre, “Quantum networking technologies”, 5 August 2025, updated 10 April 2026. ncsc.gov.uk ↩ ↩2 ↩3
-
ANSSI, BSI, NLNCSA and the Swedish National Communications Security Authority, “Position Paper on Quantum Key Distribution”, 25 January 2024. cyber.gouv.fr ↩
-
NIST, “NIST Releases First 3 Finalized Post-Quantum Encryption Standards”, 13 August 2024. nist.gov ↩
Knowledge Hub content is general information. It is not legal advice, a compliance certification, a guarantee of security or a substitute for an assessment of your own systems. Standards and rules change; check the sources for the latest position.