Croatia’s €9.9M Quantum Shield Plugs In

A new kind of lock: security that shatters the moment it is observed.
Image composition · tobriefEvery encrypted message sent online today can be copied, stored and kept by a hostile intelligence service until a powerful enough quantum computer can break the mathematics protecting it. The threat has a name: "harvest now, decrypt later" (CSO Online). The technology may still be a decade away, but government files, military planning and critical infrastructure data often need to remain secret for much longer than that.
That is why the EU has been building, largely outside the public argument, a quantum communication network meant to make spying on encryption-key exchanges physically detectable. For Malta, where digital government, financial services and iGaming all depend on trusted networks, this is not a distant Brussels experiment. It is the security layer that will sit under parts of the European digital economy.
Croatia has now added its part. The €9.9 million CroQCI project demonstrated quantum-secure communication across eight locations in Zagreb (Večernji list), moving the technology beyond the laboratory into real data-centre environments and end-user applications (CroQCI). Led by CARNET, Croatia's academic network, with scientific direction from the Ruđer Bošković Institute, the pilot tested the fibre-optic infrastructure and key-management architecture needed to connect later with the EU’s wider system.
One pilot in one capital city is modest. Within a 27-country plan, it is a building block.
A tamper-evident seal made of light
Quantum key distribution, or QKD, is less mysterious than the name suggests. It uses individual particles of light to create encryption keys, then passes those keys to ordinary encryption systems that protect the actual data (ITU).
The security comes from physics. If someone intercepts the light particles to copy the key, their quantum state is disturbed in a way the sender and receiver can detect. The simplest way to think of it is as a tamper-evident seal: once it has been opened, the parties know.
This protects a specific point in the chain, the exchange of keys. It does not solve compromised devices, poor software, insider threats or metadata exposure (Fraunhofer IPMS). Quantum signals are also fragile. They cannot be amplified like normal internet traffic, so distance remains a problem without trusted relay nodes or satellite links.
The continental puzzle
The EU framework behind Croatia’s pilot is EuroQCI, launched in 2019 and involving all 27 member states and the European Space Agency (European Commission). Its purpose is to protect government data, critical infrastructure and sensitive research from future quantum-enabled decryption (HADEA).
The system has two layers. National fibre networks, like Croatia’s, form the ground segment. Satellites are meant to connect countries and routes that fibre alone cannot handle.
The Connecting Europe Facility has funded 19 cross-border projects with €193 million in total investment and €96 million in EU grants across 25 member states (HADEA). The TransEuroOGS project is building optical ground stations in Germany, Greece, Ireland and Luxembourg to receive quantum keys from satellites (FAU, HellasQCI). Another backbone project, QUANT-GPICz, aims to link Frankfurt, Berlin, Warsaw and Prague through quantum-secured fibre.
The satellite layer is the harder part to schedule. The Eagle-1 prototype was officially expected in late 2026, but reporting suggests the launch could slip to late 2027 or early 2028 (Space Intel Report).
Two shields, not one
QKD is one part of Europe’s answer to the quantum threat. The broader shield is post-quantum cryptography: new mathematical algorithms designed to withstand quantum attack. NIST finalised its first three standards in August 2024 (NIST).
France’s cybersecurity agency, ANSSI, plans to stop certifying products that lack quantum-safe encryption from 2027 (MarketScreener). That matters well beyond France. It affects software used by governments and critical operators across Europe, including small states that buy rather than build much of their digital infrastructure.
The two approaches cover different risks. Post-quantum algorithms are the software migration for the wider digital world: VPNs, certificates, messaging apps and public-sector systems. QKD adds a physics-based layer for the most sensitive links, where relying only on mathematical assumptions is considered too thin a defence (NIST, ITU).
Europe is pursuing both. The Commission has opened a public consultation, running until 24 June 2026, to shape EuroQCI activities from 2027 onward (Quantum Flagship).
Croatia’s eight quantum-linked locations in Zagreb will not protect European secrets on their own. The value comes when national pilots, cross-border fibre, certification rules and satellites work as one system. The realistic timetable is a late-2020s infrastructure build-out, with a wider quantum-safe migration around 2030.
The race is quiet, but real. Encrypted traffic captured today does not expire, and the computers that could one day read it are moving closer.
How was this article?
Help us get better
Help us get better
Details about this article
- Model:
- claude-opus-4-6
- Generated:
- 6/17/2026, 3:29:26 AM
- Pipeline run:
- eu_pipeline_20260617_015006
- Watermark:
- SynthID (Google's invisible watermark)
- Human review:
- None before publication