EU Funds QKD Certification Push With QUARTERNEXT
Table of Contents
July 6, 2026 — A six-member European consortium called QUARTERNEXT launched with a four-year mandate and an EU budget line behind it. Its mission: take continuous-variable quantum key distribution (CV-QKD) from laboratory demonstrations to certified, industrial-grade hardware fit for deployment across Europe’s critical infrastructure.
The bottom line for security leaders: this project will not change what you should be doing right now (migrating to post-quantum cryptography remains the priority), but it will change the medium-term planning picture. If QUARTERNEXT delivers certified QKD products through Europe’s Nostradamus certification infrastructure, enterprise CISOs in EU-regulated sectors may face QKD as a compliance and procurement fact within five to seven years, regardless of their personal assessment of the technology.
The News
Funded under the Digital Europe Programme’s IRIS² QCI call (DIGITAL-IRIS2-2025-QCI-01), QUARTERNEXT brings together six organizations across three countries. Luxquanta, a Barcelona-based CV-QKD hardware developer, coordinates the consortium. The remaining partners are Quside (quantum random number generators, Spain), Chilas (tunable narrow-linewidth photonic laser sources, Netherlands), fragmentiX (quantum-age secret-sharing appliances, Austria), Telefónica (telecommunications operator, Spain), and the Austrian Institute of Technology (AIT) (Austria’s largest research and technology organization).
The project’s 48-month roadmap targets four deliverables. First, compact CV-QKD transmitter and receiver units integrating narrow-linewidth lasers and high-performance quantum random number generators. Second, a software-defined key management system for scalable distribution across complex networks. Third, a secret-sharing appliance with higher data rates and standardized QKD key-delivery interfaces. Fourth, coexistence frameworks allowing quantum and classical data channels to share existing optical fiber without performance loss, an engineering prerequisite for any real-world telecom deployment.
QUARTERNEXT builds directly on QUARTER, a three-year predecessor initiative that validated QKD integration across operational environments in finance, healthcare, cloud infrastructure, and data centers. The successor project advances from validation to the harder step: formal security certification.
The certification pathway runs through Nostradamus, the EU’s designated testing and evaluation infrastructure for quantum-safe systems. Launched in January 2024 with a $17.4 million budget, Nostradamus is led by Deutsche Telekom, Thales, and AIT, with its laboratory transferring to the European Commission’s Joint Research Centre in Ispra, Italy, with operational activities beginning in 2026. QUARTERNEXT will feed its hardware and software prototypes directly into this facility as primary test vehicles.
Beyond the laboratory, the consortium plans field trials in Telefónica’s TEFQCI production quantum communication infrastructure, testing multi-vendor interoperability under live telecom network conditions. AIT will conduct security testing and vulnerability assessments of the QKD layer, a practical acknowledgment that the gap between protocol-theoretic security and deployed-device security is exactly where previous QKD implementations have failed (the detector-blinding attacks against commercial systems being the most prominent example, as I detailed in my analysis of device-independent QKD).
The project also carries an explicit sovereignty mandate. QUARTERNEXT will align its manufacturing and design with PIXEurope, the EU’s approximately €400 million Pilot Line for photonic integrated circuits under the Chips Joint Undertaking. The stated goal is a domestic European supply chain for quantum communication components.
My Analysis
The most interesting thing about QUARTERNEXT has nothing to do with the physics.
Europe’s cybersecurity agencies have spent the last two years telling organizations that QKD is immature, niche, and subordinate to PQC migration. In January 2024, ANSSI, BSI, the Dutch NLNCSA, and the Swedish Armed Forces published a joint position paper whose conclusions were blunt: QKD requires specialized infrastructure, suffers functional limitations, applies only to certain niche use cases, and is “not yet sufficiently mature from a security perspective.” Their recommendation: prioritize post-quantum cryptography. The Czech Republic’s NUKIB subsequently endorsed this position.
Twelve months later, the European Commission funded a consortium to certify the same technology those agencies called immature. That is the story.
Two Logics, One Continent
As I analyzed in my earlier piece on why countries differ on QKD, this split looks incoherent only if you assume everyone is optimizing for the same objective. They are not. National cybersecurity agencies responsible for securing millions of existing endpoints prefer a software fix that ships through patch cycles. They trust mathematics they have spent careers analyzing. The Commission, optimizing for strategic autonomy and industrial policy, prefers a security technology whose supply chain Europe can own end to end, and whose buildout doubles as investment in a domestic photonics sector.
Both logics are rational. The tension between them is a feature of how the EU operates, where technical agencies issue guidance while the Commission pursues industrial strategy, and these two tracks do not require each other’s permission. A CISO reading the ANSSI position paper and then discovering that the same EU is funding QKD certification may feel confused. That confusion resolves once you separate the technical assessment (QKD has real limitations today) from the strategic bet (QKD may be required infrastructure tomorrow, and Europe intends to be the one building it).
I argued in Quantum Ready that the apparent contradiction, skeptical agencies inside an investing union, is simply both logics operating simultaneously. The hedge is defensible: you harden the mathematics now with PQC and develop the physics in parallel. The mistake would be betting everything on either.
Why CV-QKD Specifically
QUARTERNEXT’s focus on continuous-variable QKD, rather than the more established discrete-variable (DV-QKD) approach, is a calculated engineering bet. CV-QKD encodes quantum states in the amplitude and phase of light and uses standard telecom photodetectors (homodyne or heterodyne receivers) rather than the exotic single-photon detectors that DV-QKD requires. The result is hardware that integrates more easily with existing fiber infrastructure and standard telecommunications equipment.
The trade-off is performance. CV-QKD systems have historically achieved lower key rates and shorter maximum distances than their discrete-variable counterparts, though the gap has narrowed. When a European team demonstrated CV-QKD over 120 km of shared fiber in October 2025, the distance was a record for co-propagation with classical data traffic, and the system used components compatible with standard fiber networks. I covered that result and its implications for next-generation QKD protocols when it was published.
For QUARTERNEXT’s ambitions, the CV-QKD choice makes sense. Industrial certification demands hardware built from components with established manufacturing processes. The telecom-compatible component base of CV-QKD fits that requirement better than DV-QKD’s single-photon detector supply chain, much of which originates outside Europe.
The Certification Threshold
The most consequential deliverable in the QUARTERNEXT roadmap is the Nostradamus pipeline. Today, one of the strongest arguments against QKD adoption in enterprise environments is the absence of formal security certification. The NSA has stated it does “not anticipate certifying or approving any QKD” products for national security use. The UK’s NCSC declined to support QKD for government or military applications.
Europe is building a different answer. ETSI’s Industry Specification Group on QKD published the first Common Criteria protection profile for QKD equipment in 2023. Nostradamus is constructing the test laboratory to evaluate products against such profiles. QUARTERNEXT is building the hardware to be evaluated. These are three distinct organizations on a single, coordinated track.
If that track produces certified products, the practical calculus changes for EU-regulated enterprises. Certification does not make QKD suitable for every use case; the distance limitations, the authentication dependency on classical cryptography, the availability concerns when an adversary can disrupt the quantum channel, these remain as I detailed in my QKD overview for cybersecurity professionals. But certification does move QKD from “interesting technology without a trust anchor” to “procurable product with a documented security posture,” and that is the threshold where enterprise procurement teams begin to take it seriously.
What This Means For You
Three considerations for security leaders tracking this development.
First, your immediate priorities remain unchanged. PQC migration is the action item. The regulatory deadlines are already set by regulators, insurers, investors, and clients, and those deadlines concern post-quantum cryptography, not QKD. QUARTERNEXT operates on a 48-month research timeline. Your CNSA 2.0 compliance window does not wait for it.
Second, if you operate in EU-regulated sectors (financial services, telecommunications, energy, healthcare), put QUARTERNEXT and EuroQCI on your watching brief. The trajectory from QUARTER’s validation work through QUARTERNEXT’s certification push through EuroQCI’s deployment mandate is a procurement pathway with policy momentum behind it. When certified QKD products emerge from Nostradamus, expect EU procurement frameworks to follow. The question for your organization is whether QKD will arrive as a compliance requirement you anticipated or as one you did not.
Third, apply the same evidence-based scrutiny to QKD that I apply to every technology claim on this site. In Quantum Ready, I offered five questions that sort every QKD proposal. The first asks what authenticates the quantum channel, and whether that authentication mechanism is trustworthy enough to render the QKD link redundant. The second demands a map of every node on the end-to-end path where keys exist outside quantum protection. The third requires the demonstrated, sustained key rate at your distance on your fiber, with certification status attached. The fourth concerns availability when the channel is disrupted. The fifth, and the one that ends most meetings, asks what specific risk this retires that hybrid post-quantum key establishment leaves open, and at what marginal cost. A proposal with crisp answers to all five deserves a pilot. A proposal that answers any of them with the phrase “laws of physics” deserves the thirty minutes it has already consumed.
The Broader QKD Picture
QUARTERNEXT does not exist in isolation. It sits within a global QKD deployment picture where the divergence between regional approaches keeps widening. China’s operational quantum communication network spans over 4,600 km and serves more than 150 institutional users. The NSA and NCSC have declined to certify QKD. Singapore has published a financial-sector QKD sandbox report. Japan, South Korea, and India all maintain national programs of varying scale.
I have been covering this divergence for some time. People dismissing QKD outright are making the same mistake as people selling it as a finished product. The physics answers a question most enterprises are not currently asking, but somewhere, with sovereign budgets and fixed sites and fifty-year secrets, someone is asking it. QUARTERNEXT is Europe’s bet that the circle of organizations asking that question will grow, and that Europe intends to supply the certified answer.
For everyone else, the right posture remains a watching brief with named triggers: certified products under the emerging protection profiles, trusted-node-free distances at enterprise-relevant key rates, device-independent systems leaving the laboratory, and EuroQCI obligations appearing in procurement requirements. The trajectory is real. Act on PQC now. Watch QKD.