The post-quantum transition is being planned as an algorithm substitution problem. At the tactical edge it is a payload problem. The NIST-standardized signature schemes are one to two orders of magnitude larger than the elliptic curve primitives they replace, and CNSA 2.0 requires national security systems to use the largest parameter sets available. On constrained, lossy, duty-cycle-limited links the binding constraint is not processor cycles and not standards availability. It is whether the authentication exchange can physically complete inside the connectivity window the mission provides.
That constraint is calculable before deployment. This paper proposes the cryptographic link budget as the instrument for calculating it. It argues that authentication rather than key establishment is the dominant cost, demonstrates that handshake failure on lossy links degrades geometrically rather than linearly, and identifies the resulting structural collision between post-quantum migration and zero trust re-verification cadence. The governance consequence is direct. FIPS validation certifies that an algorithm is implemented correctly. It says nothing about whether a link can carry it, and no current federal instrument requires anyone to prove that it can.
The Framing Error
Federal post-quantum guidance is built on a substitution model. Inventory what uses RSA and elliptic curve cryptography, replace it with ML-KEM and ML-DSA, and establish enough crypto-agility that the next substitution costs less than this one. For enterprise environments that model is sound. It also carries an unstated assumption: that transport is effectively free, that a handshake growing from two kilobytes to forty kilobytes is a performance consideration rather than a feasibility question, and that the correct measurement of post-quantum impact is added latency on a link with bandwidth to spare.
Laboratory benchmarking reinforces the assumption. A pilot that measures handshake latency delta on a gigabit path is measuring computational overhead, which is real, but which is not the constraint that matters where the joint force operates. At the tactical edge the question is not how much slower the handshake became. It is whether the handshake fits. That is a different class of question, it has a numerical answer, and almost no one is producing the number.
The Arithmetic
The size difference between classical and post-quantum artifacts is not incremental. The following are standardized parameter sizes in bytes.
The operational significance is not the raw expansion, but the parameter selection requirement layered on top of it. CNSA 2.0 directs national security systems to ML-KEM-1024 and ML-DSA-87, the Category 5 parameter sets. The relief available to a commercial enterprise, which can rationally select ML-DSA-44 and accept a smaller signature, is not available to the mission systems running on the worst links in the inventory.
That is the central inversion of the tactical post-quantum problem. The environments with the least bandwidth, the highest loss, the tightest duty cycles, and the shortest connectivity windows are the environments mandated to carry the largest cryptographic artifacts. Crypto-agility does not resolve an inversion of that shape, because agility governs which algorithm is selected, not how many bytes the selected algorithm requires.
Authentication Dominates, Not Key Establishment
Most post-quantum readiness discussion concentrates on key establishment, because hybrid key exchange is the visible near-term deployment activity and because ML-KEM support is the feature vendors advertise. That concentration is misdirected. Hybrid key establishment is expensive but bounded. A hybrid X25519 and ML-KEM-768 exchange adds roughly 1.2 kilobytes to the client hello and roughly 1.1 kilobytes to the server response. The cost is fixed, symmetric, and paid once per session. It is a bandwidth tax, not a structural obstacle.
Authentication behaves differently because it scales with certificate chain depth and doubles under mutual authentication. A three-certificate chain using ML-DSA-87 carries roughly seven kilobytes per certificate once subject public key and issuer signature are counted, producing a chain in the range of twenty to twenty-five kilobytes before X.509 structural overhead. Mutual authentication, the default posture for machine-to-machine traffic under zero trust, requires the same exchange in both directions. A handshake that consumed under two kilobytes classically can approach forty to fifty kilobytes post-quantum, and much of that growth is authentication. Organizations tracking readiness by ML-KEM support are therefore measuring the smaller half of the problem, and vendors advertising post-quantum key exchange are answering the easier question.
Loss Amplification and Non-Linear Failure
Payload expansion becomes a feasibility question rather than a performance question because fragmented handshakes fail geometrically on lossy links. If a handshake requires N fragments and each has an independent loss probability p, the probability of first-attempt completion is (1-p) raised to the Nth power.
A five percent loss rate is unremarkable on a tactical wireless link. At that rate a mutually authenticated post-quantum handshake completes on first attempt roughly one time in six. Retransmission recovers most of those failures, but recovery is priced in round trips, and round-trip cost on these links is severe. Geostationary satellite paths carry five hundred to six hundred milliseconds as a matter of physics, and beyond-line-of-sight high frequency links run four hundred to one thousand milliseconds with substantial jitter. A handshake requiring four recovery cycles has consumed multiple seconds before the first byte of mission data moves, and in a DDIL environment the connectivity window may close before the recovered handshake completes.
The failure mode compounds where middle-boxes are involved. Performance enhancing proxies, protocol accelerators, deep packet inspection appliances, and tactical gateway encryptors were tuned around handshake profiles that fit inside a single maximum transmission unit. Oversized client hellos and fragmented certificate messages are precisely the traffic these devices handle least gracefully, and the characteristic failure is silent. The session does not report a cryptographic error. It simply fails to establish, and the operator sees a network problem.
The Constrained Link Inventory
Abstract discussion of bandwidth obscures how narrow the relevant links are. The following places a twenty-two kilobyte one-way authentication payload against representative transports.
For the lower half of that table the conclusion is not that post-quantum authentication is slow. It is that asymmetric authentication as currently standardized cannot transit the link in any operationally meaningful sense, and no compression or tuning changes that outcome by the required order of magnitude.
The Identity Population Multiplier
Per-session cost is half the calculation. The other half is session churn multiplied by identity population, and both are rising for reasons unrelated to cryptography. Non-human identity now dominates credential populations, workload identity frameworks issue short-lived credentials that rotate hourly or faster by design, and agentic systems multiply that population further because each autonomous actor requires its own verifiable identity rather than inheriting a human session. Sensor and effector populations at the tactical edge add thousands of endpoints whose individual traffic volume is trivial and whose aggregate authentication volume is not.
The metric that captures this is rekey overhead expressed as a percentage of available goodput. On a 2,400 bit per second link where authentication consumes seventy-three seconds, a five minute session lifetime means cryptographic establishment has consumed roughly a quarter of the link before any mission data moves. That is the number to place in front of a program office, because it converts a cryptographic argument into a capacity argument, and capacity arguments get funded.
The Collision with Zero Trust
Zero trust architecture presumes that re-verification is cheap. Continuous authentication, short credential lifetimes, per-request authorization, and fine-grained segmentation all rest on the assumption that establishing trust again costs little enough to do constantly. Post-quantum authentication invalidates that assumption exactly where connectivity is worst. Faced with the arithmetic above, the rational engineering response at the tactical edge is to extend session lifetimes, cache authorization decisions longer, coarsen segmentation granularity to reduce trust boundary crossings, and terminate cryptography at a gateway rather than at the endpoint. Every one of those responses is a retreat from a stated zero trust tenet.
This is the collision no current policy instrument acknowledges. Two mandated modernization programs are in direct structural tension on constrained links, and the tension will be resolved locally by engineers under operational pressure rather than deliberately by architects under governance. The predictable outcome is an undeclared risk acceptance: session lifetimes quietly extended, mutual authentication quietly disabled on the links that cannot carry it, and neither decision documented as a control deviation because no framework asked the question. Naming the tension in advance converts a hidden deviation into a governed trade.
The Cryptographic Link Budget
Radio frequency engineering solved an analogous problem generations ago. Before a link is fielded, a link budget establishes whether the signal closes the path with adequate margin. The calculation is unglamorous, entirely arithmetic, and non-negotiable, because a link that does not close does not work regardless of how sound the equipment is in isolation. Cryptographic deployment at the tactical edge needs the same instrument, taking the following inputs.
Usable payload per frame, effective goodput, per-fragment loss rate, and round trip latency for the transport
Duty cycle ceiling and connectivity window duration under representative DDIL conditions
Certificate chain depth, mutual authentication requirement, and mandated parameter set
Session churn rate, identity population, and credential lifetime policy
Mission time-to-trust requirement, derived from the operational thread rather than an IT service level
It produces total handshake bytes and resulting fragment count, first-attempt completion probability, expected time to trust including retransmission, rekey overhead as a percentage of available goodput at the specified churn rate, and margin against the mission time-to-trust requirement. Those outputs classify each link into one of four tiers, and the tier determines which architectural remedies are legitimate.
The value of the classification is that it makes the constraint architectural rather than anecdotal. A program can no longer assert that its tactical links are post-quantum ready because a laboratory pilot succeeded. It must state which tier each transport class occupies and what remedy that tier requires.
The Mitigation Ladder, Honestly Assessed
Several mitigations exist. None is free, and each converts a bandwidth problem into a different problem that must be owned elsewhere in the architecture.
Certificate compression reduces chain size modestly. Certificates are high-entropy structures, so the gains are useful at Tier 2 and irrelevant at Tier 3.
Raw public keys and cached certificate information eliminate repeated chain transmission between endpoints that have met before. The gains are substantial and the cost is provisioning discipline and bilateral support.
Intermediate suppression, Merkle tree certificate proposals, and authentication by key encapsulation rather than signature are promising standards-track and research directions with attractive size properties. Track them. Do not carry them as dependencies in a near-term roadmap.
Compact-signature alternatives derived from FALCON offer signatures near six hundred bytes at the smaller parameter set. Publication status must be verified, and CNSA 2.0 does not currently list the scheme, which makes it unavailable for national security systems regardless of technical merit.
Pre-placed symmetric keying remains adequate against quantum adversaries at appropriate key lengths and is the only approach that functions at Tier 4. The cost is key distribution logistics, compromise blast radius, and revocation without connectivity, which is where sharded custody and threshold distribution become architecturally relevant rather than academic.
Terminating cryptography at an enclave gateway works and relocates trust. It creates a plaintext aggregation point and moves the boundary away from the endpoint, which is a governance decision requiring explicit acceptance rather than an engineering convenience.
The pattern is consistent. Every remedy trades bandwidth for key management burden, provisioning rigor, or trust locality. The purpose of stating the trade in design is to ensure that someone accountable makes it, rather than having it made implicitly by a field engineer restoring a link under operational pressure.
Governance and Acquisition Implications
Four changes follow directly, and none requires new technology.
Test conditions must reflect the transport rather than the laboratory. A pilot conducted on a wired local network proves algorithm interoperability and nothing else. Meaningful validation requires representative maximum transmission unit constraints, injected packet loss, duty cycle enforcement, and deliberate interruption of the connectivity window mid-handshake, because the failure modes that matter appear only under impairment.
Maturity must be reported per transport class. A cryptographic maturity assessment producing a single enterprise score conceals the problem, because an organization at an advanced level across enterprise links may sit at the earliest level across tactical links while the aggregate reports progress the mission does not have. Readiness levels should carry the transport tier they apply to.
Acquisition language should demand testable link behavior. Vendor post-quantum claims are currently unfalsifiable because nothing in the solicitation requires the relevant disclosures. Contracts should require declared handshake byte counts under mandated parameter sets, minimum viable maximum transmission unit, documented behavior under fragmentation and loss, support for credential caching and raw public key modes, and proven operation from pre-placed keys without connectivity to a certificate authority. Algorithm validation certifies correct implementation of a primitive and carries no information about payload behavior on a constrained path, so it should not be accepted as a substitute for any of these.
Cryptographic inventory should record transport, not only algorithm. An inventory that lists algorithms without the transport class each dependency traverses cannot support migration triage, because it cannot distinguish a dependency replaceable by software update from one whose replacement is physically infeasible on its link. Adding a transport class field converts a compliance artifact into a planning instrument.
Closing Assessment
The tactical edge will not fail the post-quantum transition loudly. There will be no announcement that a mandated algorithm could not be fielded. Failure will arrive quietly, as extended session lifetimes adopted to keep links stable, mutual authentication disabled on paths that could not carry it, cryptography terminated at gateways for reasons documented as performance tuning, and pilots declared successful because they were conducted where bandwidth was never the constraint. Each decision will be locally reasonable. Their aggregate is a security architecture that reports compliance it does not have.
The instrument that prevents this is arithmetic performed before deployment rather than discovered during it. A cryptographic link budget is not a sophisticated construct. It is a small set of inputs, a handful of calculations, and a four-tier classification that tells an architect which remedies are available on which links. It forces the constraint into the open while it can still be designed around, and it produces the numbers that fund the work. The algorithms exist and are standardized. The open question is whether the links can carry them, and no one currently must compute the answer. Requiring it is the next useful step.






