Discrete-Modulated (DM) Continuous-Variable (CV) Quantum Key Distribution (QKD) is an experimentally attractive approach to quantum cryptography, offering high key rates over metropolitan-scale distances while relying on state-of-the-art telecom infra
Discrete-Modulated (DM) Continuous-Variable (CV) Quantum Key Distribution (QKD) is an experimentally attractive approach to quantum cryptography, offering high key rates over metropolitan-scale distances while relying on state-of-the-art telecom infrastructure. However, a fundamental gap has remained between this experimental promise and rigorous security: for more than two decades, DM CV-QKD has lacked a complete composable finite-size security proof against coherent attacks. Existing works either restrict the adversary to collective attacks, impose additional finite-dimensional assumptions, apply only to specific modulation formats, or fail to recover the known asymptotic rates. Here, we resolve this longstanding problem by establishing the first complete composable finite-size security proof for DM CV-QKD protocols against coherent attacks, incorporating imperfect detectors and both fixed- and variable-length protocol variants. Our proof introduces two central results of broader interest: an infinite-dimensional marginal-constrained entropy accumulation theorem (iMEAT) and a rigorous dimension-reduction technique that makes the infinite-dimensional security bounds numerically tractable. The resulting key rates recover the known asymptotic rates and outperform established finite-size bounds based on collective attacks, while yielding positive key rates beyond 70km for experimentally relevant block sizes and parameters. Thus, our work closes a longstanding gap and places an experimentally attractive class of CV-QKD protocols on a rigorous composable security footing and provides a pathway towards their practical deployment.