Why Europe Is Industrialising CV-QKD
Table of Contents
Introduction
When QUARTERNEXT launched on July 6, 2026, it put continuous-variable quantum key distribution (CV-QKD) at the centre of a new European effort to produce certifiable, industrial-grade quantum communication systems. That choice matters, but not because Europe has selected CV-QKD as the winner over discrete-variable QKD.
EuroQCI remains multi-technology by design. The PETRUS coordination action lists six parallel industrial projects: eCAUSIS develops an interoperable DV-QKD module and key management system with an explicit mandate to establish a European DV-QKD supply chain. QKISS and SEQRET are separate CV-QKD industrialisation tracks. MDI-QUEEN focuses on measurement-device-independent QKD equipment. EQUO builds QKD devices across protocols with a focus on interoperability. QUARTERNEXT, the €10 million successor to the earlier QUARTER project, adds a seventh.
What QUARTERNEXT reveals is narrower and more interesting. Europe sees CV-QKD as a strategically valuable industrial track because it aligns with coherent optical communications, photonic integration, and an effort to manufacture more of the critical stack within the European photonics base. The consortium states this sovereignty objective directly: it intends to develop EU-made components and align its work with the PIXEurope photonic-chip pilot line. For readers less familiar with the QKD modality distinctions, I covered the protocol families in detail in my next-generation QKD protocols analysis and my QKD overview for cybersecurity professionals. What follows assumes that background and focuses on the strategic question: why does Europe consider a sovereign CV-QKD supply chain valuable enough to industrialise alongside its other QKD options?
Two Ways to Distribute a Quantum Key
DV-QKD (the BB84 family and its descendants) encodes information in discrete optical states, typically phase, polarisation, or time-bin states carried by phase-randomised weak coherent pulses, and recovers them with single-photon detection. The decoy-state analysis is what allows security to be established despite the photon-number statistics of those pulses. For single-photon detection, the highest-performing option is superconducting nanowire single-photon detectors (SNSPDs), operating below 4 kelvin. Many deployed systems instead use thermoelectrically cooled InGaAs/InP single-photon avalanche diodes (SPADs) at lower performance. The protocol’s security proofs for implemented point-to-point QKD are the most mature in the field. BB84’s finite-key security against general coherent attacks has been rigorously established, and the decoy-state variant has accumulated two decades of independent scrutiny. This is what China’s national quantum communication network runs on its backbone, what most commercial QKD products implement, and what satellite-based QKD demonstrations have used.
CV-QKD takes a different path. Instead of encoding information in single-photon-level states, it encodes quantum states in the amplitude and phase of coherent light pulses, the same kind of signals used in modern coherent optical telecommunications. The receiver uses homodyne or heterodyne detection with standard InGaAs photodiodes at room temperature. No cryogenics required for the detector. The hardware draws on telecom-derived components and manufacturing processes, and CV-QKD systems can share fibre with classical data traffic. A 2025 experiment demonstrated CV-QKD coexisting with fully populated classical channels over 100 km in the finite-size regime and 120 km asymptotically, though lit-fibre coexistence is not exclusive to CV-QKD (DV decoy-state BB84 has also been demonstrated alongside classical traffic using time-interleaving techniques).
The trade-offs are real but more specific than often claimed. CV-QKD generally trades a tighter excess-noise budget and shorter practical reach for telecom-compatible coherent detection and potentially high key rates at metropolitan distances. DV-QKD, particularly when paired with low-noise single-photon detectors, currently operates at higher channel losses and dominates the longest-distance demonstrations. Luxquanta rates its second-generation NOVA LQ system for up to 100 km or 20 dB under its specified operating conditions, a 200% improvement over the first generation.
So why is CV-QKD attracting dedicated European industrialisation investment? The answer is the supply chain.
The Supply Chain Argument
Europe’s quantum communication ambitions exist within a broader strategic framework centred on technological sovereignty, a theme I explored extensively in Quantum Sovereignty. The CV-QKD investment is, in part, a supply chain decision informed by quantum physics.
DV-QKD requires single-photon detection. SNSPDs offer the highest performance but are not a universal requirement; deployed systems also use InGaAs/InP avalanche and upconversion detectors. Europe’s strategic exposure is about the depth and control of its high-performance detector supply chain rather than an inability to build DV-QKD without SNSPDs.
The SNSPD supply chain picture has shifted, however, in ways that sharpen the sovereignty question. A 2020 review by You et al. estimated the 2019 global SNSPD market at roughly $20 million and identified six commercial suppliers. That snapshot illustrates how specialised the market was, though the supplier picture has evolved since.
ID Quantique, long Europe’s flagship quantum detection company, fabricates its SNSPD wafers in Lausanne and assembles systems in Geneva. But following IonQ’s acquisition of a controlling stake announced in February 2025 and completed that May, ID Quantique now operates as an IonQ subsidiary. The manufacturing remains Swiss for now, but strategic control sits with a US-listed quantum computing company. Single Quantum in Delft remains EU-owned but is a small operation. Pixel Photonics in Münster, which raised €13.5 million in April 2026, is developing waveguide-integrated SNSPDs and represents a newer EU-headquartered entrant. Beyond Europe, Photec is Chinese, Scontel is Russian, and Photon Spot and Quantum Opus are American.
IonQ’s 2025 acquisition of ID Quantique sharpened the sovereignty optics around advanced detector supply chains. It did not create Europe’s CV-QKD strategy, which predates the transaction (EuroQCI was already funding CV-QKD industrial projects under its 2021 Digital Europe call, and QUARTER was the predecessor project). But it does illustrate why the European Commission has industrial-policy reasons to develop a QKD technology stack whose core components sit within the European photonics base.
CV-QKD’s detection hardware, homodyne receivers built from standard InGaAs photodiodes and balanced detectors, uses telecom-derived components and manufacturing processes that European industry already operates at scale. A secure CV-QKD receiver is more than an ordinary coherent telecom receiver (it requires tightly controlled balanced detection, shot-noise calibration, excess-noise estimation, and security-specific digital signal processing), but the manufacturing base is recognisably European telecom. QUARTERNEXT’s alignment with PIXEurope, the approximately €400 million Pilot Line for photonic integrated circuits under the Chips Joint Undertaking (20 institutions from 11 European countries), confirms the industrial logic.
The Certification Challenge
Choosing CV-QKD for its industrial advantages does introduce a genuine technical consideration: the security proofs are less tested than DV-QKD’s.
In DV-QKD, decoy-state BB84 has finite-key security proofs against the most general class of attacks (coherent attacks) that have been independently refined over two decades. The principal concern has shifted to implementation security, the gap between a protocol’s theoretical guarantees and a real device’s behaviour, most famously exposed by the detector-blinding attacks against commercial systems.
CV-QKD’s security proof literature is younger and more active, with different modulation schemes and receiver models requiring different analyses. For Gaussian-modulated CV-QKD, composable security against collective attacks in the finite-key regime was demonstrated by Jain et al. in Nature Communications in 2022, requiring approximately 2 × 10⁸ coherent states. For discrete-modulated CV-QKD, finite-key security against coherent attacks had already been established for particular protocols, including binary modulation in 2021 and a four-state heterodyne protocol in 2024. Pascual-García, Bäuml, Araújo, and collaborators substantially improved the finite-size rates in Physical Review A in February 2025, reducing the useful block-size regime to roughly 10⁸ rounds at metropolitan distances.
Infinite-dimensional state spaces complicate practical finite-size proofs. Some analyses use photon-number truncation or bounded-dimensional reductions, so certification must establish whether the discarded tail and all associated approximation errors are rigorously included in the security bound. A June 2026 arXiv preprint continues that line of work with a dimension-reduction treatment intended to remove earlier restrictive assumptions.
QUARTERNEXT’s certification challenge is to bind a real product (Luxquanta’s NOVA LQ uses Gaussian-modulated coherent states with a true local oscillator) to a specific composable proof model, finite-size analysis, and implementation-security profile. That is harder than citing the existence of a theoretical proof, and it is where CV-QKD’s active research programme becomes operationally significant. The Nostradamus testing and evaluation infrastructure at the JRC in Ispra will need to accommodate several QKD families; CV-QKD will be one important product category going through that pipeline, alongside DV and MDI systems.
China’s Hybrid Architecture
China is not making the clean opposite bet that a simple narrative would suggest.
The current China Quantum Communication Network (CN-QCN), described in a 2025 peer-reviewed paper in npj Quantum Information, is explicitly hybrid. Its fibre backbone spans approximately 10,103 km and supports interconnection with the earlier Beijing-Shanghai network, taking the combined fibre mileage above 12,000 km. The network incorporates 145 fibre backbone nodes and 20 metropolitan networks across 17 provinces and 80 cities.
Four high-speed decoy-state BB84 systems (three polarisation-encoded, one phase-encoded) serve the long-distance backbone, where attenuation tolerance and an established trusted-relay design matter. But the metropolitan networks include both a DV-QKD system and two Gaussian-modulated CV-QKD systems. The backbone systems use InGaAs/InP avalanche detectors and upconversion detectors, not SNSPDs, which matters for the supply chain argument: China’s backbone does not depend on the cryogenic SNSPD infrastructure that the draft’s earlier version assumed.
The comparison with Europe is therefore architectural rather than national. China has deployed DV-QKD at backbone scale and CV-QKD under metropolitan loss budgets. Europe is industrialising several modalities in parallel before converging on certification and procurement profiles. As I have written before, the global divergence on QKD reflects different strategic calculations, not different physics.
The DI-QKD Horizon
Then there is device-independent QKD, which neither Europe nor China has selected for infrastructure deployment, for the simple reason that it remains in the laboratory.
DI-QKD can certify security without trusting a detailed model of the source or measurement devices, closing many of the implementation loopholes that have affected conventional QKD. It still depends on authenticated classical communications, private randomness, trusted post-processing, and secure user locations with no unauthorised leakage. Its practical challenge is to produce sufficiently high-quality entanglement, detection performance, and event rates to obtain a finite key over useful distances.
The first successful DI-QKD experiments were reported in 2021-2022 (Oxford, Munich, USTC), achieving secure key bits over distances of metres to hundreds of metres. In February 2026, Pan Jian-Wei’s team at USTC demonstrated DI-QKD over 100 km of fibre, using single rubidium atoms in optical tweezers with quantum frequency conversion to the telecom band. The experiment produced positive asymptotic rates at up to 100 km. At 11 km, the team also estimated an extractable finite-size secure key rate from 1.2 million heralded Bell pairs gathered over 624 hours. It did not demonstrate finite-size key generation at 100 km, and its acquisition time remains far from infrastructure requirements.
On current evidence, certified operational DI-QKD deployment before the mid-2030s appears unlikely. By any standard technology readiness assessment, DI-QKD remains at early laboratory stages, roughly TRL 2-3, with no commercial products or field deployments. The DI-QKD endpoint and entanglement-distribution hardware would be substantially different from today’s CV coherent-transceiver stack, though the eventual industrial architecture remains unsettled.
If DI-QKD Matures
Much of what QUARTERNEXT and the broader EuroQCI programme are building is not QKD-modality-specific. Terrestrial fibre assets, sites, key-management interfaces (the ETSI GS QKD 004 and 014 standards for application and REST-based key delivery are the starting point), operational procedures, and portions of the testing environment could be reused. Nostradamus’s organisational capability should transfer, even though protection profiles, optical test equipment, and pass/fail criteria would be modality-specific.
The CV-QKD endpoint hardware (transmitters, homodyne receivers) is specific to the continuous-variable approach and would become a previous generation if a stronger modality matures. But that applies to DV-QKD endpoint hardware equally.
Both China and Europe must watch DI-QKD because it could eventually offer a stronger assurance tier. Whether it displaces conventional QKD or remains confined to the most demanding use cases will depend on rate, cost, reliability, and deployability. Security theory alone does not settle that question.
What This Means in Practice
For the CISO or CTO reading this, the modality debates within QKD are largely someone else’s problem right now. Your immediate action items remain the same: PQC migration is the priority, and the regulatory deadlines driving that migration are already set.
Two planning implications follow from Europe’s multi-modality industrialisation push.
First, the European testing and certification pipeline will accommodate several QKD families. CV-QKD will be one important product category, alongside DV and MDI systems. If you operate EU-regulated critical infrastructure, your procurement teams should understand the modality distinctions well enough to evaluate vendor claims. The five evaluation questions from Quantum Ready apply regardless of modality: what authenticates the quantum channel, where keys exist outside quantum protection, the certified key rate at your operating distance, the availability model, and which specific risk this retires that PQC leaves open.
Second, do not invest in QKD infrastructure that locks you to a single vendor or a single modality. The field is moving. Build for modularity. Insist on standardised key management interfaces. Ensure your architecture can swap out endpoint hardware without rebuilding the key distribution layer above it. This is crypto-agility applied to hardware, and it is the same principle I advocate for PQC migration.
Europe has not chosen one QKD modality. It is building a portfolio and trying to ensure that, whichever technologies survive certification and deployment, European industry controls more of the underlying stack. QUARTERNEXT matters because CV-QKD fits that industrial strategy well. Its coherent-optical architecture aligns with European photonics, telecom integration, and photonic-chip manufacturing. But DV-QKD remains part of EuroQCI, China already uses both modalities, and DI-QKD is better understood as a possible future assurance tier than as a guaranteed replacement.
Migrate to PQC. Treat QKD as a specialised additional control. Build for the upgrade.