Quantum networking is the business of moving quantum information between machines that sit in different places, and almost everything sold under that name today does one narrow job. It delivers encryption keys over optical fibre one photon at a time. Anyone listening in changes what arrives, and gives themselves away.
The quantum internet is a larger and later idea. It is a network that hands out entanglement between any two nodes on request, the way the internet hands out packets. That would let remote quantum processors act as parts of one machine rather than as separate computers exchanging messages.
These two things are usually written about as if they were the same technology at different stages. They are not, and most of the numbers that blur them do not survive contact with their own sources. What this field publicises are peak-setting figures, taken at a machine’s best moment and repeated as though they were its working ones.
Four of the most-quoted examples are checked against their source papers below. The record fidelity on New York’s GothamQ network belongs to a setting twenty-five times slower than the record rate. Qunnect and Cisco’s local and deployed swapping rates are quoted about three hundred-fold apart, where their own loss budget accounts for roughly fifty of that. Welinq advertises a memory that holds a photon for 200 microseconds, where its founders’ published work reports about one. The 99.5 per cent transducer efficiency that circulates as a performance figure is a coefficient from a model, and the same device puts 8.7 per cent out the far end.
The distinction those numbers obscure is a simple one. Key delivery is a product you can buy and rack up this year. The quantum internet is a research programme with a small number of public testbeds, and between them sits hardware that does not exist yet.
What ships today is key delivery, not entanglement. Commercial quantum key distribution gear from Toshiba, ID Quantique, LuxQuanta and others runs on metro fibre now. It produces a string of shared random bits and nothing else.
Several of the most-quoted numbers in this field do not survive a read of the paper they come from. GothamQ’s record fidelity belongs to a setting of the machine twenty-five times slower than its record rate. Welinq advertises a memory at 200 microseconds of storage where its founders’ published work reports about one. The 99.5 per cent transducer efficiency in circulation is a coefficient from a model rather than photons out the far end. Every figure below is quoted at the setting it was actually taken at.
Long QKD links are joined by trusted nodes. That is a real compromise. At each node the key is decrypted and re-encrypted classically. The key material is exposed in plaintext. The 2,000 km Beijing to Shanghai backbone works this way, and so do most deployed QKD networks.
Entanglement over deployed city fibre is now a measured result, not a hope. Qunnect and Cisco swapped entanglement across 17.6 km of New York fibre in February 2026. The counters recorded above 0.65 swapped pairs a second on the deployed link, or roughly 2,300 an hour. The paper quotes above 1.5 a second once that figure is corrected for detector efficiency, which is a conventional correction and a correction all the same.
The missing component is the repeater. What fibre loss takes away is rate rather than reach, and the ceiling on a link with no repeater in it falls about a hundredfold for every 100 km of glass. Entanglement at a fidelity worth using runs out far sooner than key delivery at any rate does. The best node performance we have reported is 78 per cent process fidelity in a laboratory, and we have found no repeater chain in field service anywhere.
The named customers are public bodies. EuroQCI, the US Department of Energy testbeds, DARPA and the US Air Force are who the specialists sell to. How much public money stands behind that is mostly unpublished, and the private rounds beside it are small. QphoX raised eight million euros in 2024 for its transducer work, and LuxQuanta a separate eight million in a Series A in October 2025.
For a security officer with a metro fibre run between two of their own buildings, the answer on this evidence is wait. Post-quantum cryptography is standardised, needs no new fibre and no trusted node in the middle, and works to any machine on the public internet. What would reverse that advice is a threat model that genuinely rules out mathematical assumptions, or a budget that belongs to a national programme rather than to a company.
Quantum networking today is a key-delivery business
Quantum key distribution is the commercial core of the field. It has been a product for more than twenty years. ID Quantique was founded in Geneva in 2001 and is led by Gregoire Ribordy, building on Nicolas Gisin’s quantum key distribution work at the University of Geneva. The company says it serves customers in more than 60 countries.
The links are real. They are also small, and they stay inside cities. BT and Toshiba said in 2021 that they would build and trial a commercial quantum-secured metro network in London, joining sites in Docklands, the City and the M4 corridor. In December 2025 Quantum Corridor and Toshiba International reported keys running over a live metro segment of about 22 km between Illinois and Indiana. The hardware was Toshiba QKD gear sharing one fibre with Ciena transport kit.
Range is the constraint here. It shapes every product decision. Toshiba Europe and Single Quantum reported in 2024 that superconducting nanowire detectors pushed a fibre QKD link beyond 300 km. A Linkoping-led team went further in 2026 and ran QKD across a deployed 303 km link that included 33 km of multicore fibre, sharing the network with ordinary Ethernet traffic. The authors add a caveat. The key throughput at that range is low enough to make even image encryption awkward.
Vendors have responded to that by making QKD share infrastructure rather than demand its own. IonQ’s Clavis XG Multiplex, announced in June 2026, lets quantum and classical traffic run on the same metro fibre, which removes the need to dedicate dark fibre to the quantum channel.
The longest links go by satellite, and the most famous one was a trusted node
Past a few hundred kilometres of fibre the key rates collapse, and the longest links we have reported go by satellite. China’s Micius satellite launched in 2016. In 2017 it distributed entangled photon pairs to two ground stations 1,203 km apart, and the team there measured a Bell inequality violation of 2.37. That number is the standard check that the two ends really shared entanglement rather than an ordinary correlation, and anything above 2 rules the classical explanation out. The result remains the reference for entanglement sent from orbit.
The 7,600 km Beijing to Vienna call the following year was a different kind of link. Liao and colleagues report that the satellite ran decoy-state BB84, an ordinary key-exchange protocol, separately with each ground station, then combined the two keys and broadcast the result. Micius was a trusted node in orbit, not a source of shared entanglement, so it is an example of the compromise described below rather than an escape from it.
Satellite work outside China is smaller and newer. SpeQtral, spun out of the Centre for Quantum Technologies in Singapore, flew its SpeQtre CubeSat on the Transporter-15 launch in November 2025. Quantum communications experiments started in early 2026, with ground stations in Singapore and the UK. SpeQtre is often called Singapore’s first quantum satellite, and it was not. That was SpooQy-1, a CubeSat from the same centre which made entangled photon pairs in orbit in 2019, and SpeQtral’s own chief technology officer led its satellite team.
Entanglement hardware is a separate product line from the key hardware
Entanglement hardware also exists and runs, and it is separate from the key hardware. Qunnect’s GothamQ network in New York distributes polarisation-entangled photon pairs over 34 km of commercial fibre, work published in PRX Quantum and posted as arXiv 2404.08626. The sources use rubidium vapour and need no cryostat, which is why the boxes fit in a standard rack.
Three settings of one machine sit behind the GothamQ numbers, and the paper keeps them apart. At full pump and coupling power the system distributes close to 500,000 pairs a second over 34 km of fibre. At that setting the authors bound the fidelity of the entangled state only above 0.84, and put their own estimate of the true value at about 0.88. Turn the power down to around 20,000 pairs a second and the fidelity reaches approximately 0.99. The 15-day run that held better than 99.8 per cent uptime sat at a third setting again, about 200,000 pairs a second, with the fidelity bounded between 0.937 and 0.967.
Rate and quality trade against each other along one curve here, so quoting the best of each describes a machine that was never run that way. The journal version of the paper says as much. It reports the peak rate in one sentence, then gives a fidelity of about 99 per cent for rates up to 20,000 pairs a second in a separate one. The preprint abstract had put rate and fidelity together in a single clause, and it is the preprint wording that has travelled. Every fidelity figure in this work is a bound rather than a reading, because the team inferred it from correlation measurements instead of reconstructing the state in full.
Other groups have shown the same class of result with parts anyone can buy. A team including the Netherlands Organisation for Applied Scientific Research, Qunnect NL and Single Quantum distributed polarisation-entangled pairs across a campus network combining fibre and free-space optical links. The network was built entirely from commercially available components.
Sending a key and sharing entanglement are not the same job
A QKD link produces exactly one thing. It is a string of random bits that two parties hold and nobody else does. That is worth having. It is also the whole of what the link gives you, and every other security property a buyer wants has to be built on top of it with ordinary cryptography.
The UK National Cyber Security Centre is blunt about what that leaves out. Its own assessment, also summarised in our report on the NCSC guidance, says QKD addresses key establishment only and does not provide authentication. It therefore has to be bolted to other cryptographic services to be useful. The agency does not support QKD for government or military use, recommends post-quantum cryptography instead, and warns that deploying QKD should not be read as evidence that data in transit is secure. The NSA has said the same for national security systems.
Of the three arguments buyers make for QKD, only sovereignty survives
The first plank of the buyers’ case is standardisation. The ETSI industry specification group for QKD has published a key delivery interface, GS QKD 014, which lets a QKD box hand keys to ordinary applications over a standard web request. A buyer is therefore not locked into one vendor’s private protocol. Since 2024 there has also been a Common Criteria protection profile for prepare-and-measure QKD modules, which gives a procurement officer something to certify against. That is a real answer to the charge that QKD is a science project dressed up as a product, and it is the most concrete thing the vendors have to point at.
The second plank is sovereignty. A European buyer may want cryptographic hardware that depends on no foreign vendor and no algorithm chosen abroad, and QKD gear built at home answers that where an American standard does not. That argument does a lot of the work inside EuroQCI. It is an honest one.
The third plank is the one the vendors lead with. QKD’s security rests on physics rather than on a mathematical problem nobody has yet solved, so a key delivered that way stays private even if someone later finds a faster algorithm. Post-quantum cryptography cannot say that. Its hardness assumptions are unproven, and the process that produced the standards has broken candidates before now.
Two of those breaks came in the same year, and both were classical attacks on schemes NIST was still considering. Castryck and Decru took SIKE apart in 2022 with a classical attack that broke the headline parameter set in about ten minutes on one core. Ward Beullens broke Rainbow, a finalist signature scheme, in the same year, and named the paper after the weekend it took on a laptop. Both had survived years of public review inside the NIST process.
So which side does the evidence favour? The agencies, but for a narrow reason rather than a sweeping one. QKD does not authenticate. Every QKD link therefore needs classical cryptography underneath it to prove who is on the other end, which puts the mathematical assumption the buyer wanted to escape straight back into the system. It is worth being precise about what ETSI standardised and what it did not. ETSI settled an interface and a certification target for the boxes, where NIST settled the algorithms themselves, and those are answers to different questions. The NCSC paper rests on exactly that distinction.
The physics argument has a matching gap. Unconditional security is a property of the protocol on paper, not of the equipment in the rack. The NSA’s objection cites published attacks on commercial QKD systems that went after the hardware rather than the theory, and none of them needed a quantum computer. Add the trusted nodes, the special equipment and a reach that stops a few hundred kilometres short, and QKD buys a narrower guarantee at a considerably higher price. The sovereignty case survives all of that. It is an industrial policy argument, not a security one.
Distance makes the compromise sharper. Long QKD networks are built from short links joined by trusted nodes, and at each of those the key is decrypted and re-encrypted with ordinary classical cryptography. Our glossary of quantum internet terms puts it plainly, the key material sits in plaintext inside every trusted node. Most deployed QKD networks work this way, the 2,000 km Beijing to Shanghai backbone among them, as the 2021 Nature network paper describes.
Entanglement distribution is a different operation. The product is different too, in that two nodes end up holding correlated quantum states that were never copied, never measured and never converted to classical bits along the way. Nothing in the middle of the path ever holds the information. There is no trusted node to compromise.
That end-to-end quantum state is the resource. Everything else is built from it. A key is one thing you can make from it. So are teleporting a qubit into a remote processor, running a computation on a machine that never learns what it computed, and tying distant sensors into one instrument.
One thing entanglement emphatically does not do is carry a message on its own. The no-communication theorem rules it out, and as our explainer on that question sets out, even quantum teleportation needs an ordinary classical channel running alongside it to complete. Entanglement is a resource that makes classical communication do more, not a replacement for it.
Vendors have started to design for that split rather than argue about it. Q*Bird launched a key manager in June 2026 that carries keys from its own QKD hardware alongside post-quantum cryptography and ordinary public-key infrastructure. That hardware is measurement-device-independent, which means it is built so the detectors themselves never have to be trusted. The company’s own framing is that QKD and PQC solve different problems and will increasingly run together.
Computing and sensing are the demand, and the software layer is the thin part
The end state everyone is describing is a network that supplies entanglement as a service. Any node asks for a shared entangled pair with any other node, and the network works out a route and delivers. The application on top never has to know which fibres or satellites were involved.
The clearest near-term reason to want that is computing. IBM and Cisco said in November 2025 that they intend to link large-scale fault-tolerant quantum computers into a network. They describe a proof of concept inside five years, an initial demonstration in the early 2030s and what they call a quantum computing internet by the late 2030s. IBM’s own account of the work describes a quantum networking unit that turns a stationary qubit into a flying one. It also sets out three separate ranges of interconnect, one-metre couplers inside a dilution refrigerator, connectors developed with Fermilab for links across a building, and transducers with Cisco for kilometre-scale hops.
Smaller companies are selling the same shape of product already. Nu Quantum launched a rack-mounted quantum networking unit in June 2025 that combines an entangler with a real-time network orchestrator, work supported by the UK government’s Small Business Research Initiative. The firm also convened a Quantum Data Centre Alliance whose founding members include Cisco, NTT Data, OQC, QphoX, Quantinuum and QuEra.
Sensing is the second application, and it gets far less attention. IBM notes that linked processors could sharpen quantum sensing. The method is interferometry, which merges the light landing on two separate detectors so that the pair reads out as one much larger instrument. Gravitational-wave observatories work this way now. Putting the detectors on a quantum link would let them sit far further apart than one site allows, and the wider the pair is spread the finer the signal it can pick out.
The third application is the one with no classical equivalent at all. Blind quantum computing lets a client with almost no quantum hardware send a job to a remote quantum server without the server learning the input, the computation or the result. It needs the client to send prepared qubits over a quantum network, which is why it waits on the same hardware as everything else here.
None of this works without software. That layer is younger than the hardware. The Quantum Internet Alliance, with TU Delft, QuTech, the University of Innsbruck, INRIA and CNRS, published QNodeOS in Nature in March 2025 as the first operating system for quantum networks. It lets an application run across different node hardware without being rewritten for each one, which is the problem every earlier network demonstration had solved by hand and thrown away afterwards. Stephanie Wehner, who directs the alliance, won the one million euro Korber European Science Prize and has said she intends to use it to connect metropolitan quantum networks across Europe by 2030.
The software layer is thinner than the papers suggest. An Argonne review finds a persistent gap between proposed network protocols and working implementations. Much of the thinking in the field lives in simulators such as SeQUeNCe, QuISP and NetSquid rather than in running code on deployed fibre. A protocol that has only ever run in a simulator has not met a real fibre, and real fibre is where this field keeps finding its surprises.
Distance is the problem and the repeater is the unfinished answer
Photons get lost in glass, and unlike a classical signal a quantum state cannot be copied and amplified on the way. What that takes away is rate rather than reach, and the two get confused constantly. A link can be stretched almost indefinitely if you will accept fewer and fewer bits out of the far end. The question is never how far the light goes. It is how many bits a second survive at the distance you actually need.
The limit has a formal statement. The PLOB bound, named for Stefano Pirandola and his three co-authors, sets a ceiling on secret key bits per use of a channel with no repeater in it. That ceiling follows the fraction of the light which survives the glass. On standard telecom fibre losing 0.2 decibels a kilometre it falls by a factor of about a hundred for every 100 km added. Running a source at a gigahertz, that is roughly 14 megabits a second at 100 km, about 1.4 kilobits a second at 300 km, and about one bit every seven seconds at 500 km.
Those are ceilings rather than measured rates, and every deployed system sits well below them. They also bound a rate rather than a distance, which is why the 300 km links described earlier are not a contradiction. The Swedish 303 km result is a trusted-node link, two sub-links of 270 km and 33 km joined at Stockholm. Its own authors show how thin the key budget becomes by trying to encrypt an image with it.
Beating the ceiling on a single span takes a repeater or an untrusted middle station. A cleverer protocol on the same two endpoints will not do it. Stuttgart researchers put the working version of the limit at signal renewal every 50 km or so, in work teleporting quantum information between photons from two separate quantum dots.
Entanglement is the harder half of the problem, and it gives out a long way before key delivery does. A trickle of key is still key, and a receiver can wait all day to accumulate enough of it. An entangled pair has to arrive at a fidelity high enough to be worth using. That is why the deployed entanglement results in this article are 34 km and 17.6 km, while the key links run ten times further.
A quantum repeater stores an incoming state in a memory. It waits for its neighbour to be ready. It then swaps entanglement, so that two nodes which never exchanged a photon end up entangled anyway. Each part of that sentence is a hard piece of physics, and the published performance figures say so. A diamond nitrogen-vacancy node reported by Taichi Fujiwara and colleagues reached 78 per cent process fidelity with a repeat-until-success emission protocol. Process fidelity measures how closely the operation a node actually performs matches the one it was meant to perform.
The work is arXiv 2608.17470, and that protocol lifts photon collection efficiency by roughly an order of magnitude over a single attempt. The name describes the method, which is to attempt the emission over and over until a photon is collected rather than accept the poor odds of a single try.
Memories and transducers are further along than the repeater itself
Memories are further along than repeaters as products. Welinq, spun out of Sorbonne University, CNRS and PSL, has launched a rack-mounted memory for data centres. It stores and retrieves single photons at over 90 per cent efficiency for up to 200 microseconds, with no cryostat, using neutral atoms held in laser traps.
Those two figures come from the company rather than from a paper. The founding group’s published work, including a memory built into a cryptography link in 2025, reports 77 per cent efficiency and storage of about a microsecond. The product claim is therefore a long way beyond the peer-reviewed record, and it has not been tested in public. In February 2026 the company also began shipping a rack-mounted entangled photon pair source to a European institution.
Wavelength is the next obstacle. It is peculiar to superconducting machines, whose qubits live at microwave frequencies while fibre carries light, so a converter has to bridge the two without adding noise. QphoX raised eight million euros in 2024 for what it called the first quantum modem. In March 2026 it launched a commercial Quantum Transducer that IBM said it would integrate with its quantum networking unit test devices. A Fujitsu Research review of the field catalogues the competing optomechanical, electro-optic, magneto-optic and atomic-ensemble routes and the efficiency and noise trade-offs each one carries.
Error correction across links is the layer above all of that, and it is still architecture on paper. A University of Massachusetts Amherst group set out an all-photonic scheme for 1,000 km of quantum communication using repeater nodes only 9 km apart. It combines two error-correcting codes, one from Gottesman, Kitaev and Preskill and one from Andrew Steane, and needs a few thousand qubits of the first kind at each station. That is a meaningful reduction on earlier proposals and it is also several thousand qubits per hut along the route.
The deployed swap’s rate gap is six times wider than its own loss budget explains
On 18 February 2026 Qunnect and Cisco ran entanglement swapping across 17.6 km of deployed fibre between Brooklyn and Manhattan. That distance is the combined path through the hub rather than one long span. It is two legs of about 8.8 km each, with the hub in the 60 Hudson Street carrier building and both sources in the Brooklyn Navy Yard. The paper behind it reports a swapping rate above 470 pairs a second with both sources in the same building as the hub. Over the deployed fibre the same measurement gives above 1.5 pairs a second.
Neither of those is a raw count. The measured rates were above 200 and above 0.65 events a second. The paper scales both up by the 65 per cent efficiency of the avalanche photodiodes at the two spoke nodes, which are ordinary single-photon counters. That is a conventional correction, and it is still a correction rather than a measurement.
The same detectors were used in both runs, so the gap between the two figures is not a matter of cheaper equipment on the deployed link. The hub counted its photons on superconducting nanowire detectors, which only work inside a cryostat at a few kelvin. Those were in fact the better ones on the deployed run, at above 93 per cent against above 80 per cent locally.
The paper does support a loss budget, arm by arm. Optical time-domain reflectometry locates where light is lost along a fibre by timing the reflections that come back. It puts about 5 decibels of loss in each 8.8 km leg of deployed fibre, with roughly 2 more in the polarisation compensator. The authors measure the whole link at about 8.2 and 9.5 decibels for the two arms. They attribute the difference to the patch panels and connectors that join their equipment to the street fibre. On a deployed metro link the connectors cost about as much as the glass. That is a procurement fact, not a physics one.
That budget does not stretch to cover the whole fall in rate. Taken across both arms it predicts a swapping rate roughly fifty times lower, where the quoted figures are about three hundred times apart, and the paper offers nothing that closes the remainder. Each rate is also quoted at the point where the CHSH parameter crosses 2, which is the threshold above which the correlations cannot be explained by any classical arrangement. The coincidence window was chosen separately for each run. The two rates are therefore not a like-for-like measure of what the fibre took away.
The CHSH parameter stays above 2 on the deployed link, and it is the only quality measure the paper gives. Fidelity never appears as a percentage anywhere in it. The ten-thousandfold gain the companies cite is measured against earlier work between two independent sources, and it describes the local rate rather than the deployed one.
Mehdi Namazi, co-founder and chief science officer at Qunnect, put the point about the setting rather than the number. “Today, we not only broke the record for rate and scalability, we did so in New York City using some of the noisiest, most chaotic fiber on Earth,” he said.
Public budgets are paying for this, not carriers
The vendor side is narrow, and it splits along the same line the technology does. Key delivery is sold by Toshiba, ID Quantique, Q*Bird and LuxQuanta, the last a Barcelona firm whose Nova LQ product rides existing fibre beside ordinary traffic. It uses continuous-variable QKD, which encodes the key on the light’s amplitude rather than on single photons. LuxQuanta raised an eight million euro Series A in October 2025, which is a typical size at this end of the market and a rounding error beside the sums moving through the public programmes. The full roster across QKD hardware, repeaters and orchestration software sits in a separate guide to quantum networking vendors.
The one structural change of the last two years is consolidation, and IonQ has done most of it. Five of its acquisitions between December 2024 and January 2026 bear on networking, on the company’s own account in its SEC filings. It started with Qubitekk and its Bohr-IV metro network, deployed at the EPB municipal utility in Chattanooga. Lightsynq, Capella Space and Skyloom followed. No deal of comparable scale by another networking player turned up in the same window, which is weaker than it sounds, because nobody publishes the list of acquisitions that did not happen.
ID Quantique was the largest of the five. IonQ bought a controlling stake, about 86 per cent of the shares, for roughly 119 million dollars in stock. Its Form 10-Q dates the completion to 30 April 2025. A larger figure of 250 million dollars circulated before that. It came from a press report of talks in progress and was never the price paid. Two of the longest-running independent QKD specialists now sit inside one listed company.
The entanglement side of the market is startups. Their customers are public. Qunnect now runs quantum links on telecom fibre in New York, Bozeman, Berlin and Albuquerque, with DARPA funding its signal-correction work and partnerships with Montana State University and Deutsche Telekom. It also won a US Air Force contract in October 2025. Arq Quantum Technologies launched from Barcelona in 2026 to commercialise rare-earth repeater technology from Hugues de Riedmatten’s group at ICFO, work that feeds the Quantum Internet Alliance prototype network.
Europe buys the most and publishes the least
Europe’s programme is the largest single buyer. The European Commission picked Deutsche Telekom to run the EuroQCI build through the PETRUS 2 project. A second project, HarmoniQCI, sits with the AIT Austrian Institute of Technology and covers standards. National builds underneath it include a 1,500 km Romanian network, and Slovakia opened its first national quantum network in December 2025. Both of those run on ID Quantique hardware. What none of it comes with is a price, because the Commission has published no euro figure for the whole build.
In the United States the money runs through national laboratories, not through carriers. Lawrence Berkeley Lab and ESnet are building QUANT-NET, a three-node testbed that shares entanglement over 5 km of fibre between the lab and UC Berkeley. That one carries a number. The Department of Energy put 12.5 million dollars behind it over five years when it was announced in August 2021. Very few other public programmes in this field have published a figure at all.
The QUANT-NET nodes are custom ion traps built with 3-D printed parts, and the photons are shifted into the telecom band before they enter the fibre. Argonne and Northwestern run their own campus link. There an orchestrator held entanglement flowing for 12 hours together, retuning itself whenever the signal drifted.
The UK has set itself a date rather than a network. The National Quantum Strategy carries a mission to deploy the world’s most advanced quantum network at scale by 2035, and the NCSC has set out what it would take. On its own account that still needs secure network architectures, component definitions and assurance methods which do not yet exist.
The distance left to run is measured in components, not in years
The field runs in three layers. One layer is a product you can buy, one is a small number of publicly funded experiments, and one has not been built at all.
| Capability | Where it stands | Best evidence we have reported |
|---|---|---|
| Metro QKD over fibre | Deployed product | BT and Toshiba in London from 2021, Quantum Corridor and Toshiba over 21.8 km in December 2025 |
| Long-haul QKD | Deployed with trusted nodes | Beijing to Shanghai, 2,000 km, key exposed classically at each node |
| Satellite QKD | Demonstrated, state-run | Micius entanglement to two ground stations 1,203 km apart in 2017, Beijing to Vienna at 7,600 km in 2018 as a trusted node |
| Entanglement distribution on city fibre | Field testbed | GothamQ over 34 km, 500,000 pairs a second at a fidelity bounded only above 0.84, or about 0.99 fidelity at 20,000 pairs a second; the 15-day run at 99.84 per cent uptime held 200,000 pairs a second at 0.937 to 0.967 |
| Entanglement swapping on deployed fibre | First field demonstration | Qunnect and Cisco, 17.6 km, February 2026, above 0.65 swapped pairs a second measured and above 1.5 after the detector-efficiency correction |
| Quantum memory | Product launched | Published record 77 per cent efficiency and about one microsecond of storage. Welinq’s rack memory is advertised at over 90 per cent and 200 microseconds, which is a company figure with no paper behind it |
| Quantum repeater node | Laboratory result | Diamond NV node at 78 per cent process fidelity |
| Microwave to optical transduction | First commercial part | QphoX Quantum Transducer, March 2026, to be integrated with IBM test devices |
| Repeater chain over 1,000 km | Architecture on paper | UMass Amherst scheme, nodes 9 km apart, thousands of GKP qubits per station |
| Networked fault-tolerant computers | Announced intention | IBM and Cisco, proof of concept within five years of November 2025 |
The deployed column is entirely key delivery. Every long link in it leans on trusted nodes, which is the one thing the security agencies object to most. Entanglement has meanwhile moved from the laboratory bench onto city fibre in about two years, and that is fast by any measure. It has done so only over distances a cyclist could cover in an hour.
The distance left to travel is best measured in components rather than years. A working quantum internet needs repeater nodes at high fidelity and memories that hold a state long enough to synchronise a route. It also needs transducers that connect superconducting processors to fibre, and error correction that survives the link. Three of those four exist as single devices in laboratories and none exists as a chain in the field.
Nobody building it agrees on a date. The ones who have named a year have named different years. The gap between a QKD product and a quantum internet is not a matter of scaling up what already works. It is a matter of building a class of device that has never yet run outside a laboratory.
Part of the existing estate plainly does carry over. IonQ’s Clavis XG Multiplex puts quantum and classical traffic on one metro fibre, and Qunnect runs its links on Deutsche Telekom’s ordinary telecom fibre. The fibre routes, the wavelength planning and the way into a telecoms buyer are all shared, and none of that has to be built twice.
The detectors are where the sharing runs out. The New York swap shows where the seam falls. The two spoke nodes counted photons on commercial avalanche photodiodes of the kind any optics catalogue sells. The hub counted them on superconducting nanowire detectors, which only work inside a cryostat at a few kelvin. A telecom exchange already stocks the first sort and has never had to house the second, so every hub on a network like this arrives with a refrigeration plant attached. Shared infrastructure gets a buyer to the edge of the network and stops at its middle.
The deeper discontinuity is the box itself. A QKD transmitter prepares a state and sends it. A repeater has to catch one, hold it and swap it, and no quantity of installed fibre supplies that. IonQ’s 119 million dollars for a controlling stake in ID Quantique reads as a bet on distribution, an installed base and a sales channel into national programmes. It is not a verdict that the repeater problem is nearly solved. The continuity is real in the outside plant and absent in the node, which is precisely why the gap is a device rather than a scale.
Buy post-quantum cryptography this year, and budget transducers as research rather than as parts
Take a chief information security officer with a metro fibre run between two of their own buildings. That is the exact case the QKD vendors pitch. Should they buy the gear now, or deploy post-quantum cryptography and wait? On this evidence, wait.
Post-quantum cryptography is the cheaper and better-supported move. NIST published the first three standards on 13 August 2024, as FIPS 203, 204 and 205. They protect data in transit and at rest without new hardware, new fibre or a trusted node in the middle of the route. They also work between any two machines on the public internet, which a dedicated QKD fibre will never do. QKD earns a serious look only where the threat model genuinely rules out mathematical assumptions, and where the budget belongs to a national programme rather than to a company.
The honest gap in that advice is price. No QKD vendor publishes a list price. The closest public figure is an EU tender from 2019, in which the University of Latvia advertised about 190,000 euros for a QKD research testing platform. That is neither current nor a like-for-like comparison with a metro link, and no award notice naming a vendor and a final price is on the record. So the comparison is a judgement rather than a sum.
The US budget office put the cost of moving prioritised federal civilian systems to post-quantum cryptography at about 7.1 billion dollars between 2025 and 2035, in a July 2024 report to Congress. That figure leaves out national security systems, and the office itself calls it a rough order of magnitude. It is not what post-quantum cryptography costs a company. What would settle the QKD question is narrower, and it is one procurement award from 2024 or later with the hardware broken out from the integration.
The second reader is a quantum computing company weighing a budget line for transducers. That decision is easier and less comfortable. There is no shelf price for a microwave-to-optical converter because there is barely a shelf, and the QphoX part launched in March 2026 is the first commercial device of its kind. Two different numbers travel under the name of conversion efficiency, and they are more than an order of magnitude apart.
Internal efficiency describes the conversion step on its own, and the electro-optic device Sahu and colleagues published in Nature Communications in 2022 reaches 99.5 per cent of it. That figure is a coefficient from a simplified model, not a count of photons out the far side. The same experiment’s total efficiency, which includes the losses in getting the light into a fibre, is 8.7 per cent, measured in the microwave-to-optical direction at an added noise of 0.16 quanta. Run the same device harder and it reaches about 15 per cent, at 0.41 quanta.
The number that decides a budget line is smaller again, because it covers the whole path from a superconducting qubit to a photon in the fibre rather than the converter on its own. Demonstrations in that direction run from about 0.3 per cent at best down to a few parts in a million for the earliest devices. A review of the field published in 2026 puts the threshold for moving a state between distant superconducting qubits at better than half the photons surviving, with added noise well below one. Nothing has reached it. Budget for the research rather than for the part, and revisit when a maker quotes end-to-end efficiency and added noise in the same sentence.
Quantum networking vendors
The NCSC on QKD
Quantum internet terms
Can entanglement send a message
The E91 protocol
Common questions about quantum networking
What is the difference between quantum networking and the quantum internet?
Quantum networking is the general business of moving quantum information between locations, and in practice today that means quantum key distribution over fibre or satellite. The quantum internet is the end state, a network that distributes entanglement on demand between arbitrary nodes so that remote quantum processors and sensors can work as one system. The first is a product you can buy, the second is a research programme with a handful of public testbeds.
Does quantum key distribution make a network unhackable?
No, and the UK National Cyber Security Centre says so directly. QKD covers key establishment and provides no authentication, so it has to be combined with other cryptographic services, and the NCSC does not support it for government or military use, recommending post-quantum cryptography instead. The agency also warns that deploying QKD should not be treated as evidence that data in transit is secure.
What is a trusted node and why does it matter?
A trusted node is an intermediate point in a QKD network where the key is decrypted and re-encrypted using ordinary classical cryptography, which means the key material sits in plaintext inside that node. Trusted nodes are how long QKD links are built before repeaters exist, and most deployed networks including the 2,000 km Beijing to Shanghai backbone rely on them. Anyone who controls a trusted node holds the keys that pass through it.
How far can quantum information travel over fibre today?
Photon loss in glass takes away rate rather than reach, because a quantum state cannot be copied and amplified the way a classical signal can. The ceiling on a link with no repeater in it falls about a hundredfold for every 100 km. For a source running at a gigahertz that is roughly 14 megabits a second at 100 km. It falls to about 1.4 kilobits a second at 300 km, and to about one bit every seven seconds at 500 km.
Real systems run well below those ceilings. Toshiba Europe and Single Quantum reported a QKD link beyond 300 km using superconducting nanowire detectors, and the Linkoping-led 303 km result is a trusted-node link made of two shorter sub-links. Entanglement at a usable fidelity gives out far sooner, and the deployed records in this article are 34 km on the GothamQ network and 17.6 km for the Qunnect and Cisco swap.
What is a quantum repeater and why does the quantum internet need one?
A quantum repeater stores an incoming quantum state in a memory and then swaps entanglement so that two nodes which never exchanged a photon end up entangled. It is the only known way to extend entanglement beyond the loss limit of a single fibre span without a trusted node. The best node performance we have reported is 78 per cent process fidelity from a diamond nitrogen-vacancy centre in a laboratory, and we have found no repeater chain in field service anywhere.
Can entanglement be used to send messages faster than light?
No. The no-communication theorem rules it out, and quantum teleportation, which comes closest, needs an ordinary classical channel running alongside the entanglement to complete the protocol. Entanglement is a resource that makes classical communication capable of more, not a substitute for it.
Who is actually paying for quantum networks?
Mostly governments. The European Quantum Communication Infrastructure, now coordinated by Deutsche Telekom through PETRUS 2, is the umbrella for national deployments including a 1,500 km Romanian network. In the United States the Department of Energy runs testbeds such as QUANT-NET at Berkeley, while DARPA and the US Air Force fund company work directly. The private rounds behind the specialist vendors are small beside that, with LuxQuanta raising an eight million euro Series A in October 2025 and QphoX a separate eight million euros back in 2024.
When will the quantum internet exist?
Nobody building it agrees on a date, and the published targets differ by a decade. IBM and Cisco talk about a proof-of-concept network in the early 2030s and a quantum computing internet by the late 2030s. The Quantum Internet Alliance aims to connect European metropolitan networks by 2030. The UK’s own 2035 target belongs to the National Quantum Strategy, which the NCSC advises on rather than owns. The more useful measure is components, since repeater chains, link-level error correction and deployed transduction do not yet exist outside laboratories.




See today’s quantum computing news on Quantum Zeitgeist for the latest breakthroughs in qubits, hardware, algorithms, and industry deals.
