
The conversation I keep circling back to with people working in quantum security is a strange one: we're spending billions preparing for a quantum computer that can break RSA and elliptic-curve cryptography, and at the same time, the very field built to solve that exact problem — Quantum Key Distribution — is being quietly sidelined by the math-based alternative it was supposed to make irrelevant. That's worth sitting with, because it isn't a contradiction. It's a sign of where the actual value in quantum technology is migrating.
The Case Against QKD
QKD's pitch has always been elegant: use the physics of photons, not the difficulty of a math problem, to distribute an encryption key, so that any eavesdropping attempt is detectable by the laws of quantum mechanics rather than by the assumed hardness of factoring large numbers. It's a genuinely beautiful idea. But “beautiful” and “deployable at civilization scale” are different tests, and QKD has been failing the second one for years. It needs dedicated fiber or line-of-sight links, its range is limited without trusted relay nodes, it demands infrastructure investment most organizations will never justify, and — the detail that matters most to anyone doing procurement — it has never gone through a formal standardization process the way its rival has.
That rival is Post-Quantum Cryptography, and NIST has already finalized three standards for it: ML-KEM (FIPS-203), ML-DSA (FIPS-204), and SLH-DSA (FIPS-205). These are math-based algorithms designed to run on the classical hardware you already own, resistant to attack by a quantum computer, and — critically — actually deployable across the sprawling, heterogeneous, imperfect real-world systems that make up modern infrastructure. National security agencies across France, Germany, the Netherlands, the US, and the UK have converged on the same position: none of them recommend QKD as a standalone solution. PQC is the practical answer. QKD, for the narrow job of moving a secret key from one place to another, may simply lose that argument.
So Is QKD Finished? I Don't Think So
I think it means QKD was solving the wrong problem. Here's the part that I find genuinely interesting, and it's where quantum supercomputing changes the calculus in a direction most of the QKD-vs-PQC debate ignores. The physical stack that QKD depends on — ultra-stable lasers, single-photon sources and detectors, precision timing electronics, entangled photon pairs sent over fiber or free-space links — isn't actually specialized for cryptography. It's specialized for distributing a quantum state with extreme fidelity between two distant points. And that is exactly the capability that Quantum Time Transfer (QTT) and Alternative Positioning, Navigation and Timing (Alt-PNT) need.
GPS gives you position and time by broadcasting from satellites you have to trust, in an environment where the signal can be jammed, spoofed, or simply blocked — inside buildings, underground, or in contested airspace. Quantum sensors, by contrast, are increasingly being positioned as something GPS can lean on rather than something that competes with it. Defense programs are already funding quantum-enabled inertial navigation systems designed to hold position and timing accuracy independent of any satellite signal, explicitly for environments where GPS can't be trusted. Quantum Time Transfer takes the same entangled-photon machinery that QKD built for security and repurposes it to synchronize atomic clocks across distance with a precision no classical signal can match — which is the actual bottleneck in a resilient PNT architecture, not the sensor itself.
So here's the reframe I'd put in front of you: the hardware isn't obsolete. The use case is shifting. The billions being spent on photonic quantum links for “unbreakable” key distribution may end up justified — just not for the reason they were funded. The same entangled-photon infrastructure that turns out to be a commercially unconvincing way to move a secret key may turn out to be an essential way to move a synchronized instant in time, which is precisely what Alt-PNT needs to make satellite-independent navigation trustworthy. Quantum supercomputing accelerates PQC's urgency and QKD's obsolescence for encryption in the same breath that it makes quantum sensing and timing more valuable for navigation and defense resilience.
What I'd Ask You
That's not a tidy story, and it shouldn't be. It means the organizations investing in quantum-secure links today need to ask a harder question than “is this route to security worth it” — they need to ask “what is this infrastructure actually for, five years from now, when the answer might not be encryption at all.”
If quantum key distribution's core function — moving a secret — gets replaced by mathematics running on hardware you already own, is QKD's photonic infrastructure headed for the scrap heap, or does it get a second career carrying time instead of secrets? Where do you think the real value ends up — and is anyone in your organization planning for that pivot, or still funding QKD as if encryption is the endgame?
#QuantumComputing #QKD #PostQuantumCryptography #QuantumAI #AltPNT #QuantumSensing #CyberSecurity #DefenseTech