In line with the Dutch, French, German, Swedish, US and UK security agencies, the organisation gives the move to post-quantum cryptography priority over quantum key distribution and, for now, does not rely on the security of QKD solutions: QKD only distributes keys and itself needs cryptographic authentication, lacks thorough standardisation and satisfactory security proofs, is limited in distance so longer links need trusted relays that see the plaintext, and needs costly dedicated hardware that adds attack vectors. The handbook notes that the European Commission has not excluded QKD.
This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.