If you’re a large bank, an important payment rail, or a fintech platform, you likely run the systems where transactions are stored, replicated, and processed yourself. That ownership is about control, not cost. If you’re a smaller bank or credit union, you’re more likely running on a mix of leased racks, cloud paired with data center hybrids, or compute time bought from a core banking provider. Some institutions are even leaning on distributed private-cloud partners to get data-center-grade control without owning every facility.
Ownership model aside, you end up in the same spot: You’re either buying your infrastructure security through somebody or building it yourself. In both cases, you’re now responsible for proving that the cryptography protecting your systems is ready for the post-quantum standards and deadlines already taking shape across government and financial services.
Physical and network security have always been part of the job. Keeping intruders away from your hardware and out of your data centers and interconnects isn’t optional, and the risk is real. In late 2017 and early 2018, thieves broke into four Icelandic data centers and walked off with roughly 600 servers, along with the GPUs, memory, and solid-state drives inside them. Organized crime rings are now targeting data centers and AI hardware as it moves through the supply chain, with multiple incidents in the last 12 months. Your teams already treat this as table stakes. What’s new is the regulatory work landing on top of it.
Banking Deadlines Are Already on the Calendar
In June, the White House signed Executive Order 14412, setting post-quantum deadlines of December 31, 2030 for key establishment and December 31, 2031 for digital signatures across federal agencies. It also calls for those requirements to be carried into federal contracting rules and directs sector agencies to help critical infrastructure operators build their own migration plans. The U.S. Treasury Department followed closely in August by launching its Quantum-Readiness Task Force, a public-private effort focused on PQC migration, vendor readiness, crypto-agility, and operational resilience across the financial sector. International banking regulators have also followed suit.
The rest of the guidance points the same direction. NIST IR 8547 deprecates RSA-2048 and 256-bit ECC after 2030 and disallows quantum-vulnerable algorithms after 2035. The G7 Cyber Expert Group’s roadmap recommends financial institutions prioritize their most critical systems for migration in 2030–2032. The CNSA 2.0 cryptographic suite developed by NIST and the NSA, which moves networking equipment to exclusive use of quantum-resistant algorithms by 2030, is rapidly becoming the benchmark buyers and auditors measure against.
Notice that the executive order sets two dates, not one. Key establishment covers how your traffic is encrypted. Digital signatures cover how your systems prove who they are. Both are on the clock, and both will show up in audits.
The hard part isn’t agreeing that migration has to happen. It’s the time and complexity of getting there: inventorying every place RSA and ECC live, sequencing upgrades without downtime, and showing regulators real progress along the way.
3 Places Your Auditor Will Look
Every migration plan starts with a cryptographic inventory: a map of everywhere RSA and ECC are still in use. That inventory is often captured in a Cryptographic Bill of Materials (CBOM), or a Quantum Bill of Materials (QBOM) when the focus is specifically on quantum-vulnerable cryptography. It’s also the first artifact an examiner will ask to see. Inside your data centers, that map usually points to three places: East-west traffic, north-south interconnects, and device and node identity.
East-west traffic is the replication and storage sync happening between your racks, clusters, and virtual private clouds (VPCs). Because it’s “internal,” it’s often the last layer anyone thinks to put on a migration plan, and the first gap an auditor finds. North-south interconnects are the cross-DC and site-to-site backhaul connecting your own facilities, and they carry a lot of your actual transaction volume. And device and node identity, the certificates and pre-shared keys authenticating all of that traffic, is still built on RSA and ECC, the exact algorithms on NIST’s deprecation schedule.
Leave any one of the three off the plan and the inventory isn’t finished. Regulators set their deadlines with the long tail of encrypted data in mind, but for most institutions the more immediate pressure is simpler: every one of these systems has a date by which it has to be compliant, and a paper trail proving it got there.
The Risk That Isn’t About Decryption
Most post-quantum coverage focuses on someone reading your data. Identity forging is the quieter half of the problem, and in a data center it may be the more dangerous one.
RSA and ECC don’t just encrypt sessions. They also sign certificates and authenticate the devices, nodes, and services that are allowed to talk to each other. A quantum computer capable of breaking those algorithms can derive a private key from its public key, and a public key is, by design, public. That means an attacker wouldn’t need to steal anything to impersonate one of your replication nodes, a backhaul endpoint, or a management host. They could forge its identity outright, and your infrastructure would, of course, trust it.
Pre-shared keys carry a related risk today. A key lifted from a stolen server or a compromised config file can authenticate a device indefinitely, and it doesn’t take a quantum computer to use it. The server heists above aren’t only about GPU resale value. Hardware that leaves the building often leaves with its credentials still on it.
That’s why the executive order gives digital signatures their own targeted deadline, and why identity needs its own line on your migration plan, not a footnote under encryption.
How ZeroTier Quantum Secures Data Centers
ZeroTier Quantum embeds hybrid, FIPS-compliant post-quantum cryptography directly into the transport layer through the ZeroTier Transport Protocol (ZTP), aligned to CNSA 2.0 and built on ML-KEM-1024. It doesn’t just layer PQC on top of an existing tunnel, it’s the tunnel.
It’s software-defined rather than hardware-locked, and that matters for compliance as much as for cost. Vendor routers already shipping with built-in PQC tie you to that vendor’s upgrade cycle for years. A software-defined platform gives you the crypto-agility that both the Treasury and the G7 call out, so you can adopt new algorithms as standards evolve without replacing equipment. Underneath that is a hybrid key exchange combining classical and post-quantum algorithms and continuous key rotation for perfect forward secrecy (PFS).
Identity gets the same treatment. Every device on a ZeroTier network is defined by a cryptographic identity rather than a shared credential, and every connection is mutually authenticated. With ZeroTier Quantum, that identity layer moves to post-quantum protection too, so a forged certificate or replayed key can’t get a rogue node onto your network. And because authorization lives at the network controller, a server that walks out the door can be de-authorized centrally, cutting it off from every peer at once.
ZeroTier Quantum runs on your existing infrastructure, so getting to compliance doesn’t require redesigning your physical network first. It also extends to new facilities as your footprint grows, without a separate migration project each time. That shortens the part of the timeline that usually takes longest.
Site-to-Site Built for High Availability
Post-quantum protection is only half of what a data center interconnect has to deliver. The other half is staying up. Treasury’s task force names operational resilience right alongside PQC migration, and for good reason: a compliant link that drops during a replication window is still a failed link.
ZeroTier Quantum keeps data centers connected without forcing resilience and security into separate boxes. Nodes connect peer to peer, so traffic between facilities can take the most direct available path instead of hairpinning through a central concentrator that creates a single point of failure. Multipath bonding lets a connection run across multiple physical links at once, whether that’s two carriers, a private circuit plus a public uplink, or redundant paths inside the same facility. Active-backup and load-balancing policies let teams decide whether links share traffic or stand by for failover, while ZeroTier continuously monitors link quality and shifts traffic when a path degrades.
The platform works at both Layer 2 and Layer 3, supporting replication, clustering, and storage traffic that expects a flat network, not only routed IP. For institutions that need control of the control plane, ZeroTier Quantum can also be deployed in self-hosted environments inside infrastructure they own or control.
That means you don’t have to choose between the resilient connectivity your data centers depend on or the post-quantum cryptography your compliance roadmap requires. You can have both.
Quantum Security at Data-Center Speed
Data centers sell performance as the product itself: CPU, GPU, throughput, and instance size. So, when you hear “new cryptography,” you may think “probably slower,” and that objection is worth answering directly. General ZeroTier overhead runs in milliseconds, with a 50ms default failover interval built in. The platform is built for data-center-scale throughput, hundreds of gigabits per second, across your intra-DC traffic and site-to-site backhaul. Multiple concurrent tunnels are supported today, and SmartNIC hardware acceleration is a direction worth watching.
None of that is theoretical when it’s your systems on the line. A banking app can’t hang for three seconds on a deposit without your customers panicking that their money disappeared. In financial services, performance is a trust question as much as an engineering one.
Meet the Mandate, Keep the Uptime
The deadlines are set, and the work to meet them is measured in years, not quarters. Every link between your racks, clusters, and facilities, and every RSA- or ECC-based identity authenticating them, is part of the inventory regulators will expect you to have migrated. What makes ZeroTier Quantum the fit for your environment isn’t just that it meets the standard. It protects both halves of the mandate, encryption and identity. It runs as a software platform on infrastructure you already have. It delivers the multipath, high-availability (HA) site-to-site connectivity your facilities already depend on, at throughput built for data-center scale. And it doesn’t ask you to gamble on a hardware upgrade cycle or wait years for a full network redesign.
PQC Built for the Data Center
That’s where ZeroTier Quantum fits. Financial institutions need a practical path to post-quantum compliance for the traffic moving across and between their data centers, without slowing down or destabilizing the systems those environments are built to run. ZeroTier Quantum builds FIPS-compliant, CNSA 2.0 post-quantum cryptography directly into the transport layer, with post-quantum device identity, mutual authentication, multipath failover and performance built for demanding infrastructure. It gives banks a way to rapidly meet compliance deadlines without waiting for a hardware refresh or rebuilding the network from scratch.
Contact sales to learn how ZeroTier Quantum can help your data centers meet post-quantum requirements.