The Security Layer Europe's Quantum Experts Are Searching For

In a closed EU Quantum Communication Roadmap consultation, one particular message emerged loud and clear: in the path towards securing the post-quantum future, the market didn’t see the unique value of QKD. It was full of people building Europe's post-quantum security strategy - the researchers, the architects, the policy officers, and the standards specialists. And amongst this expert group, the most widely shared concern of QKD was this:
"The core challenge isn't engineering. It's proving the unique value proposition over mainstream encryption alternatives."
Let’s back track about what happened here. The roadmap consultation was intended to be a broader quantum communication policy session, but QKD - Quantum Key Distribution technology became a flashpoint. It was raised by the hosts almost from the get-go for its near-term deliverability for solving quantum communication problems. But the attendees weren’t having it. They wanted a solution that closes post-quantum security gaps - and the consensus was that this, albeit a mature candidate, wasn’t in fact easy to deploy, wasn’t practical, and, undercutting it all, it wasn’t closing any market gaps.
QKD’s Proposition Problem
QKD is used to secure the distribution of encryption keys via quantum characteristics. The technology, which the European Commission is actively backing, particularly through its PETRUS coordination project, uses the quantum states of individual photons to generate shared encryption keys. Key material is encoded into individual photons and transmitted between two parties, so that any measurement of the quantum state inevitably disturbs it; therefore, any attempt to intercept the exchange leaves a detectable trace. For those concerned about protecting data, the security of the key exchange rests not on computational hardness but on physics - in principle, an eavesdropper cannot intercept it without being noticed.
However, for the experts in attendance, QKD has a value proposition problem, and it came from several directions:
It's expensive. Dedicated QKD systems and dark fiber pricing were flagged directly as adoption blockers. Dark fiber is scarce and costly to rent and anyone investing in dedicated quantum infrastructure runs the risk of locking themselves into an operating model that isn’t commercially sustainable.
Slow Deployment. Large-scale, operational QKD infrastructure isn't expected before 2030. While certification gaps also contribute to slow deployment timelines, the deeper issue is that the technology simply isn't ready to run at the scale required by large networks. Photons degrade as they travel through fiber, and QKD can’t be amplified via optical amplifiers. Extending it over long distances becomes extremely challenging. In practice, QKD is limited to roughly 100km before the signal is too weak to trust. No commercial quantum repeater exists yet to solve that distance problem outright. For an industry that needs infrastructure it can deploy and rely on now, a solution years from operational readiness is a hard sell.
The integration gap. QKD demands infrastructure that most networks don't have. Whether that’s dedicated dark fiber or specialized hardware. There is no alignment between EuroQCI and defense networks, there are no unified control planes, or network-level SLAs. These were all mentioned as barriers that were bound to inhibit any rollout.
And the part that appeared to matter most: The UVP gap. Multiple independent commenters, across different sections of the agenda, landed on the same diagnosis: the challenge is market justification. "Classical networks and PQC already provide strong security" was cited in so many different ways as a demand-killer. There was no clear answer to "why this matters when encryption already exists?" In the absence of a unique raison d’etre, even the most sophisticated quantum infrastructure risks remaining a funded research programme rather than a deployed product.
A Different Layer, Not a Better Key
The security stack has been built around the assumption that encryption is the line of defense for data-in-transit. If someone intercepts your traffic, your encryption protects you. But that assumption was designed for a world where breaking encryption was computationally intractable in any workable timeframe.
Quantum computing breaks that assumption. Not today, but on a known timeline. State-level actors are tapping fiber right now: street cabinets, communication tunnels, subsea cables. They capture the encrypted traffic, store it, and wait. This isn't a future risk. It's a documented, ongoing activity. Gartner puts the probability of conventional asymmetric cryptography as unsafe to use by 2029 in the face of quantum advances.
PQC and QKD deliver better keys: PQC through quantum-resistant algorithms, QKD through the physics of quantum measurement. This is important work, but both of them address the decryption problem. Neither addresses the recording problem.
Better keys do protect the payload - indirectly. An attacker holding a recording needs either the key or a way through the AES layer that protects it, and today both are “hard problems”. But "hard" is a statement about today's compute, not tomorrow's. The data still crosses the fibre as a signal that can be tapped, copied and stored - and a stored recording gives the attacker unlimited time for those assumptions to fail. The question the room wanted answers to wasn't: how do we generate better keys? It was: how do we stop the recording in the first place?
How to Stop a Recording
To stop a recording, Photonic Layer Security is needed. The physics-based solution spreads the signal across a broad optical spectrum and continuously rotates the keys, pushing the transmitted signal below the threshold of any known interception method. An adversary who taps the fiber captures noise. Not ciphertext. Not a key exchange in progress. This means nothing to store and nothing to eventually decrypt.
That's what makes PLS additive rather than competitive. Organizations running PQC keep running PQC. Organizations building toward QKD keep building toward it. PLS solutions like CyberRidge’s Carmel, close the one gap neither addresses: the physical interceptability of the signal itself.
Blocking Interception Without the Overhead
A quiet overachiever, the Carmel, protects against interception but at a fraction of the overhead. There's no dedicated dark fiber to lease, no attenuation issues to overcome, no elaborate architecture to guard and maintain. Carmel runs on the carrier fiber already in the ground, integrates in weeks rather than months, and costs a fraction of a QKD solution to deploy. It provides the physical-layer security guarantee the room wanted, just without the need to rebuild the entire network to get it.
The Threat Isn't Waiting
QKD’s interoperability is years away. Cryptographically relevant quantum computing, per Gartner: as early as 2029. And adversaries? They’re actively harvesting fiber traffic today.
Every month spent waiting for QKD's operational runway to close is a month of active exposure, where data recorded today is decrypted the moment quantum capability arrives. These timing gaps don’t just represent a planning inconvenience. It's an exposure window.
CyberRidge enables network security specialists to close that window directly, today, on the fiber they already have.