Article content
In briefShow moreShow lessNSM recommends migrating to post-quantum cryptography by 2030.
- NSM recommends migrating to post-quantum cryptography by 2030.
- QKD only establishes keys and still requires authentication and symmetric encryption.
- The position is authoritative Norwegian security advice, not a generally binding national ban.
What NSM published
In a position paper published on 8 June 2026, NSM describes quantum computers as a future threat to existing cryptographic systems. A sufficiently capable quantum computer could use Shor’s algorithm against specific asymmetric algorithms, especially those used for key exchange and digital signatures. NSM also highlights “harvest now, decrypt later”: data intercepted today may be decrypted in the future.
The recommended direction
NSM urges every organisation to address the quantum threat by 2030. Its recommendation is post-quantum cryptography: algorithms offering comparable functions to current systems while being designed to withstand quantum attacks. The paper notes that migration may often resemble a software update, but organisations must begin immediately if they are to meet the target.
Why QKD is discouraged
QKD sends quantum states, usually photons, between parties to establish a secret key. It does not encrypt messages by itself; the key must later be used with conventional symmetric cryptography. QKD also depends on an authenticated classical channel. Authentication requires either pre-shared secrets or post-quantum asymmetric cryptography, so QKD does not remove the need for other cryptographic mechanisms.
Operational limitations
NSM identifies specialised hardware, integration complexity, cost, implementation attacks and incomplete standardisation. QKD is also distance-limited: commercial systems have ranges of roughly one hundred kilometres, while quantum repeaters remain experimental. Trusted nodes can extend connections, but they require confidence that those nodes protect the secret material correctly.
What organisations should do
Build a cryptographic inventory covering algorithms, certificates, protocols, hardware, suppliers and data with long confidentiality lifetimes. Prioritise systems where compromise today could harm people, critical services or classified information later. Test hybrid configurations, upgrade paths and rollback plans, and require demonstrable crypto-agility in new procurements.
Norwegian precision
The paper is authoritative Norwegian security advice, but it does not create a general statutory ban on QKD. Contractual terms, sector-specific rules and classified-information requirements may impose stricter constraints. Organisations should connect the advice to their own risk assessments, NSM’s other cryptographic recommendations and applicable sector or security-authority requirements.
Sources
Norwegian National Security Authority: “Position paper on quantum key distribution,” 8 June 2026.
Norwegian National Security Authority: “Quantum key distribution – report U-26-35,” 8 June 2026.
For discussion
Which systems protect information long enough that “harvest now, decrypt later” should determine migration priorities?


