NSA Rewrites Its QKD Guidance: Same Verdict, a New Certification Argument
Table of Contents
October 1, 2026 – OThe National Security Agency (NSA) published a rewritten statement on quantum key distribution (QKD). The agency repeated the conclusion of its 2020 guidance: it does not recommend QKD or other quantum cryptography for protecting data in National Security Systems (NSS) unless several technical limitations are overcome.
The statement is one of three articles in a new Post-Quantum Cryptography Resource Hub that NSA launched the same day for Department of War, NSS and Defense Industrial Base organizations. The other two articles introduce post-quantum cryptography (PQC). The QKD article dates NSA’s position to June 2026 and does not explain the date.
NSA first shared its QKD guidance publicly on October 26, 2020, saying it was responding to requests from mission customers for guidance that had previously stayed within government channels. The 2020 page is still online with its original text.
The 2026 article keeps the five limitations NSA listed in 2020. According to NSA, QKD supplies keys without authenticating their source and requires dedicated fiber or free-space equipment. QKD networks often depend on trusted relays, the practical security of a system depends on its hardware and engineering, and the sensitivity that reveals an eavesdropper also makes denial-of-service attacks easier.
The rewrite adds two passages. NSA says changing environmental conditions and physical degradation can lower the operational security established when a QKD system was certified. It also says the strongest uses of quantum cryptography remain theoretical and belong in “a broader, fully-quantum network that may link quantum computers and quantum sensors.”
Several passages from 2020 are missing. The rewrite omits the statement that NSA “does not anticipate certifying or approving any QKD or QC security products” for NSS customers unless the limitations are overcome. It also drops the attribution of physics-guaranteed security claims to vendors and the media, and the statement that QKD cannot be implemented in software or as a service on a network.
The reference list grew from five papers to ten. NSA added a 2016 review of practical challenges in QKD, a 2023 study of implementation attacks commissioned by Germany’s Federal Office for Information Security (BSI), a 2024 paper on preparing a commercial QKD system for certification, and arXiv preprints from August 2025 and March 2026.
NSA’s CNSA 2.0 FAQ, last revised in December 2024, already answers no when asked whether a QKD system can protect an NSS from a quantum computer. The FAQ says NSS owners “should not use or research QKD at this time without consulting NSA directly.”
In the press release announcing the hub, NSA restated dates set by Committee on National Security Systems Policy 15 (CNSSP 15). All new commercial NSS must be capable of supporting quantum-resistant algorithms starting in 2027, the agency said. Legacy systems that cannot support them are to be phased out by 2030.
Allied agencies have published similar positions. The UK’s National Cyber Security Centre (NCSC) said in an August 2025 white paper that it “will not support the use of QKD for government or military applications.” In a January 2024 position paper, the cybersecurity and communications-security agencies of France, Germany, the Netherlands and Sweden concluded that QKD suits only niche use cases and is not yet mature enough from a security standpoint. The four agencies also concluded that migration to post-quantum cryptography should come first.
The European Commission is building EuroQCI, a quantum communication infrastructure that all 27 EU member states have joined, with QKD as its first planned service.
My Analysis
Since NSA published its first QKD page in October 2020, BSI has certified a Common Criteria protection profile for QKD. Toshiba Europe has run a twin-field link across 254 kilometers of commercial telecom fiber in Germany, and a team in China has demonstrated device-independent QKD over 100 kilometers of fiber. NSA’s October rewrite still does not recommend QKD for national security systems, in the same terms it used before any of that happened.
NSA aimed one of its two additions at the certification work. The agency now argues that the security a QKD system has on the day it is certified can erode as conditions change and components age. Anyone selling or buying QKD for US national security systems gets the same no as in 2020, plus a new NSA argument that security established at certification can erode afterwards.
I agree with that verdict for what goes into national security systems today. Where I differ is on whether the US should build QKD at all, a question NSA’s guidance does not address.
NSA’s Five QKD Objections and What Changed Since 2020
Authentication Still Requires Classical Cryptography
QKD distributes keys. It cannot tell the receiver who sent the photons, so every QKD link also needs a classical mechanism to authenticate the two ends: post-quantum signatures, or symmetric keys placed in advance. The NCSC’s 2025 paper sets out the same two options and limits the pre-shared-key route to controlled environments, because distributing and managing those keys does not scale.
NSA has already said what it accepts instead. In the CNSA 2.0 FAQ, the agency says it considers standards-compliant pre-shared symmetric keys a better near-term post-quantum measure for Commercial Solutions for Classified deployments than unvalidated post-quantum algorithms. It also treats hybrids that mix a symmetric key into a standard exchange, citing RFC 8784 for IKEv2 and RFC 8773 for TLS 1.3, as an option for specialized applications. On the few fixed links where QKD is practical, an operator that authenticates with pre-placed keys could use the same keys inside standard protocols, an option NSA’s FAQ allows, with no QKD hardware involved.
QKD’s defenders have a real counterargument, which Michele Mosca, Douglas Stebila and Berkant Ustaoglu formalized in 2013. With QKD, the authentication key only has to stay secret while the exchange runs, and the keys QKD produces stay secure even if that authentication key is exposed years later. A pre-shared key used as the quantum-safe ingredient of a protocol has to stay secret for as long as the data it protects. For data that must stay confidential for decades, the data a harvest-now, decrypt-later adversary collects, that property is the strongest argument for QKD that I know of. NSA’s other four objections concern whether deployed systems deliver it in practice.
QKD Hardware on Commercial Telecom Fiber
In 2020 NSA wrote that QKD could not be implemented in software or as a service on a network and could not easily be integrated into existing network equipment. The 2026 text keeps the hardware dependence and drops the absolute wording.
In April 2025, Toshiba Europe reported in Nature a twin-field QKD link over 254 kilometers of commercial telecom fiber between Frankfurt and Kehl, with detectors that need no cryogenic cooling. The link delivered 110 bits of key per second, enough for a fresh 256-bit AES key roughly every 2.3 seconds on one link. The phase-stabilized lasers, single-photon detectors and relay receiver in that experiment are still QKD-specific hardware, which is the substance of NSA’s objection. The equipment now works on deployed commercial fiber. It still needs a dedicated device at each end, and those devices cannot be patched the way a software library can.
Trusted Relays on National Networks
NSA’s third objection concerns the trusted relays that QKD networks use to cover long distances. At each relay the key exists in plaintext, so the site has to be physically guarded, which adds facility costs and insider risk.
Researchers have weakened the objection for single links with two newer protocol families. In measurement-device-independent and twin-field QKD, the node in the middle performs a measurement but learns nothing about the key, so it does not need to be trusted. Toshiba’s relay at Kirchfeld worked that way. In 2023 a team at the University of Science and Technology of China (USTC) ran twin-field QKD over 1,002 kilometers of spooled ultra-low-loss fiber, at an asymptotic key rate, which assumes unlimited data, that the Chinese Academy of Sciences put at 0.0034 bits per second.
National networks still chain trusted nodes. China’s national QKD network depends on trusted relay sites on its long-haul links. Quantum repeaters, which would make those sites unnecessary, are still laboratory work. For any QKD network longer than one twin-field span, NSA’s point about facility costs and insider risk still applies.
Validation, Certification and the Drift Argument
Standards bodies and certification authorities spent much of the time since 2020 on validation, and NSA changed its argument on that point in the 2026 text. In 2020 NSA called QKD’s security highly implementation-dependent and said the tolerance for error in cryptographic security was many orders of magnitude smaller than in most engineering, which made QKD very difficult to validate.
In April 2023, ETSI’s QKD industry specification group published the first Common Criteria protection profile for QKD, covering a pair of prepare-and-measure modules. A protection profile sets the security requirements a class of product must meet in a Common Criteria evaluation. BSI certified a revised version in 2024, at evaluation assurance level 4 augmented with ALC_DVS.2 and AVA_VAN.5. AVA_VAN.5 is the Common Criteria’s most demanding vulnerability analysis and assumes an attacker with high attack potential.
BSI’s commissioned study sets out every QKD-specific implementation attack known at the time in one structure and names the work still needed before the implementation security of QKD systems can be assured, including more practical experience with attacks and more research on countermeasures. Vadim Makarov and colleagues took a commercial system built by the Russian company QRate through the preparation for certification. They searched it for known and new loopholes and amended its design against the highest-risk ones.
NSA answers that body of work with one sentence: changing environmental conditions and physical degradation can lower the operational security established at certification. NSA has extended its 2020 objection in time: if security depends on the implementation, it also depends on how that implementation behaves months after the evaluation. The article gives no reference for that sentence. Its footnote is attached to the next sentence, about attacks on commercial systems.
NSA did not cite a 2014 experiment by Audun Nystad Bugge of the Norwegian University of Science and Technology and colleagues, who showed that an attacker can use high-power laser light to permanently change the properties of components in a QKD system. After about 1.5 watts of illumination, the avalanche photodiode detectors they tested switched permanently into linear mode, where they provide no QKD security. That experiment covers deliberate damage. For environmental change and ordinary aging, NSA cites no evidence.
QKD security is more sensitive to component drift than the security of classical cryptographic hardware. A certificate for a hardware security module covers the software, firmware and physical protections around algorithms whose mathematical security does not depend on the module’s analog behavior. A QKD security proof takes measured physical parameters as inputs, such as detector efficiencies and source intensities, and assumes they stay within bounds for the life of the link. If they drift, the proof stops describing the system.
Researchers keep finding new attacks. The March 2026 preprint NSA added, by William Tighe and colleagues at the University of Leeds and Quantum Village, simulates an attack that intercepts part of the quantum signal while keeping errors under the 11 percent threshold of BB84, the original QKD protocol. It then exploits the parity information the two parties exchange during Cascade, a widely used error-correction step, to shrink the set of candidate keys before privacy amplification. The authors argue that privacy amplification cannot restore what the attack removes, since it only compresses the entropy that remains. The work is a simulation in a preprint, it demonstrates no attack on a deployed system, and it targets classical post-processing, a part of the system a certification also has to cover.
The August 2025 preprint on NSA’s list is a defense paper. It models Trojan-horse attacks, in which an attacker shines light into the transmitter and reads the reflection, against a side-channel-secure QKD protocol, and finds the attacker gains almost no key information once the reflected intensity is below $$10^{-6}$$. NSA attaches all ten references, as examples, to its sentence about attacks on commercial systems. Several of them, including this one, the 2024 certification paper and the 2016 review, document defenses and practical engineering.
Device-independent QKD is the design meant to remove the dependence on device models. It derives security from the observed violation of a Bell inequality, a statistical test that only entangled devices can pass, so drifting hardware lowers the measured violation and the key rate instead of silently breaking the proof. Its remaining assumptions include an authenticated classical channel and laboratories that leak nothing. In February 2026, a USTC team reported in Science device-independent QKD between two single-atom nodes, with a positive asymptotic key rate over 100 kilometers of fiber. The finite-key result, which accounts for the finite amount of data collected, came at 11 kilometers and took 624 hours to collect 1.2 million entangled pairs. I covered the result when it appeared. Device-independent QKD is the design that answers NSA’s drift argument, and at those rates it is a laboratory result.
Denial of Service
NSA’s denial-of-service objection is unchanged from 2020 and follows from the physics of QKD. A QKD link detects an eavesdropper through the errors that interception causes, and it responds by discarding key. Anyone with access to the fiber can cause those errors on purpose and stop key generation on that link. An operator can fail over to a classical or post-quantum key exchange, which returns the link to the cryptography it would have used without QKD.
NSA’s New Sentence on Quantum Networks
In its second addition, NSA distinguishes QKD from other forms of quantum communication. The article places the strongest uses of quantum cryptography in a future all-quantum network linking quantum computers and quantum sensors, and calls those uses theoretical.
The NCSC drew the same line in August 2025. Its paper sorted quantum networking into three classes: quantum technologies that replace classical security functions, with QKD as the example; classical networks extended with quantum components such as sensors; and inherently quantum networks that distribute entangled states between quantum devices. The NCSC said the second and third classes have the most interesting applications, from more precise sensor networks to scaling up quantum computers, and that the technology behind QKD could play some part in them. The same paper reported a growing consensus among the NCSC’s international partner agencies on the future direction of quantum communications.
NSA and the NCSC now direct their skepticism at QKD as a key-distribution product. Neither agency has applied its objections to networks that link quantum computers or quantum sensors through entanglement, and NSA now names those networks as the place where quantum communication has its strongest case.
What NSA Dropped From Its 2020 Text
In 2020 NSA said it did not expect to certify or approve any QKD or quantum cryptography product for NSS customers unless the limitations were overcome. The 2026 article has no such sentence, but I would not read the omission as an opening for QKD products in national security systems: the 2020 page is still online, certification sentence included.
The CNSA 2.0 FAQ answers no on using QKD to protect an NSS, and it says a commercial product that does not use CNSA 2.0 algorithms may not protect an NSS unless NSA has given specific written guidance. QKD is not a CNSA 2.0 algorithm, and the FAQ tells NSS owners to consult NSA before using it. A certificate alone therefore cannot put a QKD product into an NSS. The hub article is an explainer, and NSA has withdrawn neither the 2020 page nor the FAQ.
NSA also softened its tone. The 2026 text still dismisses claims of guaranteed security based on the laws of physics, and it no longer names vendors and the media as the source of those claims.
What the Rewrite Means for QKD Buyers and Vendors
For national security systems, CNSSP 15 sets the dates that count, and the CNSA 2.0 FAQ states them more precisely than the press release. From January 1, 2027, less than three months away, new NSS acquisitions must be CNSA 2.0 compliant unless otherwise noted, a procurement gate I have written about separately. CNSA 2.0 specifies ML-KEM-1024 for key establishment and contains no QKD option, so QKD counts for nothing at the gate. An NSS owner who wants QKD on top of CNSA 2.0 has to consult NSA first.
Outside national security systems, NSA’s text sets no requirement, and allied agencies say the same. The NCSC advises organizations in other sectors not to rely on QKD alone and says a QKD system should not count as evidence of data-in-transit security under its Cyber Assessment Framework. The four-agency European paper puts PQC first, and Czechia’s NÚKIB later issued a letter of support for it.
Inside Europe, the Commission’s EuroQCI program funds QKD infrastructure across all 27 member states and presents it as a contribution to digital sovereignty and industrial competitiveness. Four member-state security agencies advise putting PQC first. I have written before about why governments split on QKD, and in Europe the division is between the Commission’s industrial program and the member-state security agencies more than between the US and Europe. NSA’s rewrite changes nothing for EuroQCI, whose case includes goals other than security.
For QKD vendors, the US national security market stays closed, and in my reading NSA’s drift argument means a certificate alone will not open it. Their customers are in Europe and Asia, and in deployments that add QKD on top of PQC on a few high-value links, the role the NCSC already describes for sectors outside government.
Where I Differ From NSA on QKD Investment
I would not let a critical system depend on QKD today. It still needs classical authentication, its long links still pass through relay sites where the key exists in plaintext, and the device-independent design that answers NSA’s drift argument needed 624 hours of data for a finite-key result over 11 kilometers. On what goes into national security systems now, I agree with NSA.
Implementation trouble at this stage is common in security hardware, and smart cards show where it can lead. In 1996, Paul Kocher showed that the time a device takes to compute RSA or Diffie-Hellman operations can leak the private key. In 1999, he and his colleagues Joshua Jaffe and Benjamin Jun showed that a smart card’s power consumption can leak its keys as well. The algorithms were sound and the chips leaked. Chip makers and evaluators answered with countermeasures and test methods, and the security IC protection profile that BSI certified in 2014 requires evaluation assurance level 4 augmented with AVA_VAN.5 and ALC_DVS.2. The ETSI profile for QKD asks for the same assurance package. That package has been the evaluation target for high-security chips since at least 2014, and QKD has only now reached the point where a certification target exists.
NSA’s guidance answers a procurement question for national security systems. It does not tell a country what to build for the next twenty years, and the UK shows that the two questions can get different answers. The same NCSC paper that refuses QKD for government and military use restates the target in the UK’s National Quantum Strategy of deploying the world’s most advanced quantum network at scale by 2035.
US policy targets the later stage of quantum networking and skips the earlier one. Executive Order 14413, signed in June alongside the PQC order, requires five-year plans for quantum sensing and networking from Commerce, Energy, NSF and NASA, covering network-enhanced timing, distributed quantum computing and space applications. Key distribution appears nowhere in the order, and the US has no national QKD infrastructure program. China runs a carrier-grade, trusted-relay QKD network with 145 backbone nodes and more than 10,000 kilometers of fiber links, and China Telecom announced commercial services in 2025 that layer QKD over post-quantum cryptography.
The case for building one depends on what happens if a post-quantum algorithm fails. Hardness assumptions are believed, not proven, and they have fallen fast before. SIKE advanced to NIST’s fourth round in July 2022, and weeks later Wouter Castryck and Thomas Decru broke its level-1 parameters on a single core, in about an hour in their first version and about ten minutes in the revised paper. NIST selected HQC in March 2025 as a backup to ML-KEM built on different mathematics, in case cryptanalysts find a weakness in ML-KEM. On October 1, 2026, BSI advised against using Classic McEliece in new developments, after three research groups estimated key recovery below its claimed security levels, although nobody can run those attacks on existing hardware. BSI had recommended the scheme, in hybrid use, since 2020. NIST’s primary standards remain unbroken, and none of these events touched them.
In each case the fallback was another mathematical assumption. QKD offers a different kind of hedge. Its keys depend on physics, on the authentication used during the exchange and on the physical security of its endpoints and relays, so a QKD network authenticated with pre-placed symmetric keys would keep producing keys if every public-key algorithm failed at once.
In that scenario China would have an operating national QKD network built on trusted relays, and the US would not. A state that controls its own relay sites can accept trusted-node security for government traffic. China’s first long-haul backbone ran 2,032 kilometers through 32 trusted nodes and was built between 2013 and 2017 for under RMB 600 million, the equivalent of less than $100 million. If one post-quantum standard fell, the US would move to a backup algorithm such as HQC. If every public-key algorithm failed, China could still run a key-distribution channel for its most sensitive links, as long as its relay sites and authentication keys stayed secure. The US fallback in that case would be symmetric keys distributed in advance, the option NSA’s FAQ already describes for Commercial Solutions for Classified. That fallback works for a small number of critical government links. It does not scale to banks, grid operators and telecom carriers, and a QKD network started after the failure would arrive years late.
Skipping QKD also costs the US operating experience. The NCSC expects the skills behind today’s quantum communication systems to be relevant to the future quantum networks it finds more interesting than QKD, and NSA’s rewrite names those networks as quantum communication’s strongest use. Chinese teams have run trusted relays, satellite links and metropolitan networks for close to a decade. EO 14413 directs plans for the networks NSA considers most promising, and none of its provisions involve operating a QKD network.
My recommendation for the US is to hold both positions, as the UK does. Keep QKD out of national security systems until NSA’s objections are answered, and fund an operational QKD segment linking a handful of civilian government and critical-infrastructure sites, run as an extra layer over PQC and never in place of it. Funding for that segment should not come out of PQC migration, which protects every system that runs software while QKD protects a few links. Reports on the sensing and networking plans EO 14413 requires are due to the President within 120 days of the order, by October 20, and those plans are the natural place to add it. I made the sovereignty case for this kind of hedge in Quantum Sovereignty.
NSA’s firmest statement on QKD remains the CNSA 2.0 FAQ’s answer for national security systems. The October rewrite adds the drift argument, which in my reading means a certificate alone would not reverse that answer. I agree with both for what goes into those systems today. The same rewrite names networks of quantum computers and sensors as quantum communication’s strongest use, and the US will build those networks with less operating experience than China has unless it starts running quantum links now.