Croatia Joins EU Quantum Shield

A new kind of lock: security that shatters the moment it is observed.
Cumadóireacht íomhá · tobriefEvery encrypted message moving across the internet today can, in theory, be copied and stored by a hostile intelligence service. The hope would be simple: wait until quantum computers are strong enough to break the maths protecting it. Cybersecurity people call it "harvest now, decrypt later" (CSO Online).
That moment may still be a decade away. But government files, military planning and critical infrastructure data often need to stay secret for much longer than that. So the EU has been building, largely out of public view, a quantum communications network intended to make interception of encryption keys physically detectable.
Croatia has now put down its piece of that system. The €9.9 million CroQCI project has demonstrated quantum-secure communication across eight locations in Zagreb (Večernji list), taking the technology out of the laboratory and into data-centre settings and end-user applications (CroQCI). CARNET, Croatia's academic network, is leading the work, with scientific direction from the Ruđer Bošković Institute.
On its own, a capital-city pilot is modest. Its significance lies in the wider European design: national systems that can eventually be connected into a 27-country quantum security network.
A tamper-evident seal made of light
Quantum key distribution, or QKD, sounds more forbidding than it is. It uses individual particles of light to create encryption keys, then hands those keys to ordinary encryption systems that protect the actual data (ITU).
The useful part is the physics. If someone tries to intercept and copy the light particles carrying the key, their quantum state is disturbed. The sender and receiver can see that something has happened. The closest everyday comparison is a tamper-evident seal: if it is broken, you know someone has been at it.
That does not make the whole system magically secure. QKD protects the exchange of keys, not every weakness around it. Compromised devices, poor software, insider threats and metadata exposure remain real risks (Fraunhofer IPMS). Quantum signals are fragile too. They cannot be amplified like ordinary internet traffic, which limits their range unless trusted relay nodes or satellite links are used.
The continental puzzle
Croatia's pilot matters because it sits inside EuroQCI, the EU programme launched in 2019 with all 27 member states and the European Space Agency involved (European Commission). The aim is to protect government data, critical infrastructure and sensitive research from future quantum-enabled decryption (HADEA).
The system has two parts. National fibre networks, such as Croatia's, make up the ground segment. Satellites are meant to connect places that fibre cannot sensibly bridge. The Connecting Europe Facility has backed 19 cross-border projects with €193 million in total investment and €96 million in EU grants, covering 25 member states (HADEA).
Ireland is already in the frame. The TransEuroOGS project is building optical ground stations across Germany, Greece, Ireland and Luxembourg to receive quantum keys from satellites (FAU, HellasQCI). Another backbone project, QUANT-GPICz, is intended to link Frankfurt, Berlin, Warsaw and Prague through quantum-secured fibre.
The satellite side is the part to watch. The Eagle-1 prototype was officially due in late 2026, but reporting suggests the launch could slip to late 2027 or early 2028 (Space Intel Report).
Two shields, not one
QKD is not Europe's only answer to quantum risk. The broader and more immediate layer is post-quantum cryptography: new mathematical algorithms built to resist quantum attack. NIST finalised its first three standards in August 2024 (NIST).
France is already moving the policy machinery. Its cybersecurity agency, ANSSI, plans to stop certifying products that lack quantum-safe encryption from 2027 (MarketScreener). That reaches far beyond specialist equipment. It affects software used by governments and critical operators.
The two approaches do different jobs. Post-quantum algorithms are the mass upgrade: VPNs, certificates, messaging apps and the wider digital infrastructure. QKD is a more specialised layer for the most sensitive links, where relying only on mathematical assumptions may feel like too much trust (NIST, ITU).
Europe is pursuing both. The Commission has opened a public consultation, running until 24 June 2026, on EuroQCI activities from 2027 onwards (Quantum Flagship).
Croatia's eight quantum-linked sites in Zagreb will not, by themselves, protect European secrets. Their value comes when national pilots, cross-border fibre, certification rules and satellites start working as a single interoperable system. The likely path is a late-2020s infrastructure build-out, alongside a wider move to quantum-safe encryption around 2030. The race is quiet, but it is real. Encrypted traffic captured today does not expire, and the computers that could read it are getting closer.
How was this article?
Help us get better
Help us get better
Details about this article
- Model:
- claude-opus-4-6
- Generated:
- 6/17/2026, 3:29:26 AM
- Pipeline run:
- eu_pipeline_20260617_015006
- Watermark:
- SynthID (Google's invisible watermark)
- Human review:
- None before publication