NSA Guidance for Transition to Quantum-Resistant Cryptography
NSA transition positions: hybrids, quantum alternatives, pre-shared keys, CSfC, PKI and roots of trust – NSA Guidance for Transition to Quantum-Resistant Cryptography

NSA Guidance for Transition to Quantum-Resistant Cryptography Q-QKD: Q-QKD Do not use or research quantum key distribution for NSS without consulting NSA; quantum RNGs only within an approval

NSA does not generally consider quantum key distribution a practical security solution for NSS: it addresses only some threats, performs only key distribution, and needs significant engineering changes to NSS communications. NSS owners should not use or research QKD without consulting NSA directly. A quantum random number generator is acceptable only as any properly certified or approved RNG is, within the constraints of that approval. The DoW CIO memo of November 2025 goes further for DoW networks: no testing, piloting, use or procurement of QKD, QKD combined with other key establishment, quantum networking, non-local quantum randomness or non-FIPS random number generation for confidentiality, authentication or integrity without an exception.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • QKD Give priority to PQC and do not rely on quantum key distribution

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in NSA transition positions: hybrids, quantum alternatives, pre-shared keys, CSfC, PKI and roots of trust – NSA Guidance for Transition to Quantum-Resistant Cryptography

Query this from an agent

The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.