Quantum NetworkQuantum Network

Why now

Protect what you send from today.

Traffic between your sites crosses lines you do not own. What you send from today is the part you can still protect, so it stays confidential for as long as it matters.

Protect what you send from today.

01 · The deadlines

The migration dates are set. The first one falls at the end of this year.

Governments and regulators have published dates for the move to post-quantum cryptography. These four publications set the pace, and the clock is already running.

Today

Your networkIf it relies on RSA or ECC, the NIST draft already lists both for retirement.

2028

UK NCSCServices that need upgrading identified, and a migration plan in place.

End 2030

EU roadmapCritical infrastructure transitioned, no later than the end of 2030.

NIST draftRSA and ECC at 112-bit security deprecated after 2030.

2031

UK NCSCHigh-priority migrations done.

2035

UK NCSCMigration complete for all systems, services and products.

NIST draftRSA and ECC disallowed after 2035.

FINMA, July 2026: Swiss financial institutions are aware of the risk, but in most cases there is no clear roadmap for the migration.

Sources: EU roadmap, June 2025 · UK NCSC, March 2025 · NIST IR 8547 draft, Nov 2024 · FINMA, July 2026

02 · What crosses the line

Traffic you protect today stays protected for as long as it matters.

“Sensitive data often retains its value for many years.”

NIST IR 8547, initial public draft
Scope

This page is about the connection, not the devices behind it. An infected laptop stays infected, and this is not a defence against DDoS.

Between your control room and each site, traffic crosses public networks you do not control. Your firewalls sit at both ends and protect what is behind them. They do not reach the stretch in between.

That stretch is where quantum-safe encryption belongs. Protecting it now keeps today’s traffic confidential for as long as its contents stay sensitive.

Examples of what crosses it

  • Critical infraSubstation management, grid monitoring and mission critical grid information
  • IndustrialCommands, readings, alarms and remote sessions between sites
  • HealthcarePatient records and X-ray, MRT and CT images
  • DefenceLive video streams and remote control
03 · Four risks on public networks

QPN protects the connection against four risks. Only one of them depends on a quantum computer.

Protecting traffic early matters most for that one, because protection only covers traffic sent after the switch.

Protected from today01

Harvest now, decrypt later

QPN agrees keys with quantum-resistant mathematics, so traffic protected from today stays protected against later decryption by a quantum computer. Protection starts with the traffic sent after the switch.

Start early for this one.

Protected today02

Man in the middle

QPN peers authenticate each other with pre-installed keys, and packets from unknown devices are dropped immediately. That protects the public networks between your control room and your sites, where you cannot see who else is present.

Protected today03

Protocol level attacks

Everything above Layer 3, including HTTPS, TLS and MQTT, travels encrypted between QPN endpoints, so protocol level exploits are covered in transit. What a device behind the gateway does sits outside that boundary. Where only certified equipment may be used, the gateway protects those protocols without touching the equipment.

Protected today04

Eavesdropping

Traffic between QPN endpoints cannot be read in unencrypted form, and cannot be altered without breaking both the classical and the post-quantum encryption. That holds for every edge site that reports to your data centre over a public network.

04 · The equipment

The equipment you install today will likely outlive the encryption it uses.

After 2030RSA and ECC at 112-bit security deprecated in the NIST draft
YearsHow long certified equipment stays in service before it can be modernised or replaced

In regulated environments only certified devices may be used. Replacing one means downtime and a visit to every site, so the equipment stays in service for years. The protocols it speaks, MQTT and TLS, were fixed long before now.

Encryption has a shorter shelf life than that. The network you run today is largely the network you will still be running when the cryptography inside it is no longer strong enough. Nobody can name that date and we will not invent one.

Waiting does not shorten the replacement cycle. It shortens the time you have left to work with.

Next · Solution

Reviewing the design? The Solution page holds the reference architecture and the full capability list. The hardware specification is on Technology.

Upgrade to quantum-safe protection

See which gateways you need and where they go, in a few questions.

Answer a few questions about your locations and connections. You see an indicative configuration straight away: which gateways, and where they sit in your existing network.

Manage risk. Reduce your exposure.

No contact details needed to see your configuration.

Rather talk it through? Book a 30-minute call

Public internet now quantum-safeAny public networkQUANTUM GATEWAYControl sideQUANTUM GATEWAYField sideCONTROL CENTEROperators and SCADAYOUR SITEPLCs, sensors, cameras
Copyright 2026 - All rights reserved - Quantum NetworkKnowledge-base