Skip to content

Education

QKD vs PQC: what security teams confuse

Quantum key distribution (QKD) and post-quantum cryptography (PQC) both appear in quantum security conversations — but they are not interchangeable solutions for enterprise TLS migration.

QKD versus PQC comparison diagram.
Q-Day Explained: The Quantum Threat to Encryption Watch on YouTube

Side-by-side comparison

Post-quantum cryptography (PQC)Quantum key distribution (QKD)
MechanismNew classical math (lattices, hashes)Quantum physics (photon states)
Deploys onExisting TLS, PKI, software stacksDedicated fiber/satellite links
NIST statusFIPS 203–205 finalizedOutside NIST PQC standardization
Enterprise TLS pathPrimary migration routeNiche / specialized links

NIST's PQC program standardizes algorithms software vendors integrate into OpenSSL, browsers, and HSMs. CISA guidance focuses on PQC migration for broad cyber infrastructure.

QKD detects eavesdropping on optical channels — valuable for specific high-assurance links — but does not replace PKI inventory and ML-KEM deployment across your SaaS estate.

What to tell leadership

  • PQC migration is the 2024–2035 program aligned to NIST IR 8547 and CISA's factsheet.
  • QKD may complement specialized links; it is not a substitute for finding RSA certificates on your CDN.
  • The NCCoE migration project demonstrates software-based PQC tooling enterprises can adopt today.

This quarter

  1. Clarify terminology in your risk register: PQC = algorithm migration; QKD = physical key exchange.
  2. Inventory quantum-vulnerable software crypto regardless of QKD pilots.
  3. Watch NIST featured videos for official PQC explainers.

Continue on the Q-Day hub: What is Q-Day? guide

References & further reading

Authoritative primary sources cited in this article. Summaries are our own — follow links for full context.

Last verified 2026-06-21

See your exposure with evidence

Run a live PQC inventory scan, export a CBOM, and verify signed reports independently.