Encrypted Today, Safe Tomorrow: Arista's Head Start on the Quantum Era
In this blog
Trust starts with growth
At World Wide Technology, the Associate Academy gives early-career technologists a front-row seat to the partners shaping enterprise IT. Each month, we sit down with one of WWT's prominent partners to learn how they think, what they build and where they're headed. Recently, that partner was Arista Networks. One question I asked during the session stuck with me long after it ended.
I asked whether Arista has a quantum readiness defense in place today. The answer was an immediate yes. The more I dug into what that yes actually means, the more it told me about who Arista is as a company.
Why quantum readiness matters now, not someday
Every secure connection on the internet depends on encryption, from a banking session to the management traffic on a data center switch. Most of that encryption relies on math problems that today's computers cannot solve in any reasonable amount of time. Quantum computers change that. Once they mature, the algorithms protecting most of the world's key exchanges will be breakable.
Here is the part that makes this urgent rather than theoretical. Attackers are not waiting. In a strategy known as "harvest now, decrypt later," adversaries are stealing encrypted data today and stockpiling it, betting they can unlock it once quantum computing catches up. If your data needs to stay confidential for the next decade, whether financial records, health information or intellectual property, it is already at risk even though the computer that cracks it does not exist yet.
The answer is PQC (Post-Quantum Cryptography), a new generation of encryption built on math problems that even quantum computers cannot solve efficiently. In 2024, NIST (the National Institute of Standards and Technology, the U.S. body that sets official cryptography standards) finalized the first PQC standards, and the race to adopt them began.
Skeptic's corner
But quantum computers don't exist yet, right?
That is exactly the problem. The adversaries most likely to reach this capability first are nation-state intelligence programs, the same actors collecting encrypted data at scale today. A state that quietly achieves the breakthrough has every reason to keep it secret and start reading stockpiled traffic. There will be no announcement on the day encryption breaks.
The timeline is also compressing. Estimates of the computing resources needed to break standard encryption have fallen dramatically in just the past few years, and most experts now place the arrival of a capable machine in the 2030s. Ask a simple question about any piece of data your organization encrypts. How many years from now would it still cause damage if it became public? A credit card issued this year expires before any quantum computer arrives, so that theft dies on its own. A patient's medical history or a trade secret stays damaging for decades. Now add the five to ten years a cryptographic migration typically takes, because everything sent during the transition is still being harvested under the old encryption. If that total is larger than the years until a capable machine arrives, the data being stolen today will still matter when it is decrypted. For plenty of what enterprises protect, it already does, which is why companies like Google have set internal post-quantum migration deadlines as early as 2029.
Built in, not bolted on
Arista's quantum readiness lives in EOS (Extensible Operating System), the single operating system that runs across their entire portfolio, from campus switches to the largest data center platforms. That single-OS architecture matters here. When a capability lands in EOS, it lands everywhere at once.
Briefly, here is what that readiness includes today:
- Quantum-resistant key exchange: EOS supports ML-KEM (Module-Lattice-based Key Encapsulation Mechanism), the NIST-standardized quantum-resistant method, in its TLS (Transport Layer Security) connections
- Hybrid modes: Quantum-resistant and classical algorithms paired together, so security holds even if either one is ever broken
- Quantum-safe data encryption: TunnelSec encrypts traffic at full wire speed directly in switch hardware using AES-256 (Advanced Encryption Standard with a 256-bit key)
- Fleet-wide delivery: One operating system carries every one of these capabilities across the entire product line at once
Here is what each of those pieces means:
At a high level, a secure connection does two jobs. First, two devices agree on a secret key. Second, they prove their identities to each other with digital certificates. The key agreement step is the one quantum computers threaten most, and it is the one Arista has already hardened.
EOS now supports ML-KEM, the quantum-resistant key exchange method that NIST standardized, in its TLS connections, the same protocol behind the "s" in "https." EOS offers it both in pure form and in hybrid modes that pair quantum-resistant and classical algorithms together. That hybrid approach is the careful, standards-recommended path for the transition.
The data itself gets a second layer of protection. Arista's TunnelSec technology encrypts traffic at full wire speed directly in switch hardware, using AES-256, an encryption method already considered safe against quantum attack. In practical terms, the handshake that sets up the connection is quantum-resistant, and the data flowing through the wires is quantum-safe, with no performance penalty.
"Quantum readiness wasn't a roadmap item we bolted on. It came out of how we build. Security belongs in the operating system, and once it's in EOS it reaches every platform we ship at the same time. The certificate side is the industry's next problem to solve, and we'll approach it the same way we approached key exchange — when it's ready, it ships everywhere at once."
— Miguel Balagot, Arista
A look to the future
Honesty matters when writing about security, so here is the full picture. The certificate side of the equation still runs on classical cryptography across the industry. The quantum-resistant replacement exists as a standard, but no major networking vendor has fully deployed it yet. It is the shared next frontier, and based on how Arista handled the first half, I would expect them to solve it the same way. Ship it, document it, move on.
That is the real lesson I took from our session with John Schwendeman and Miguel Balagot. Quantum readiness is not a product Arista sells. It is a result of how they build. Security is engineered into the network itself from the start, and it is delivered through one operating system that carries every advance across the entire fleet.
For customers navigating the quantum transition, that is what makes the WWT and Arista partnership matter. WWT's Advanced Technology Center, our lab environment where customers test and validate technology hands-on before they buy, gives organizations a place to see this architecture working rather than take anyone's word for it. As the next chapters of the quantum story unfold, that combination of Arista building it and WWT proving it openly is one I am glad to be learning from the inside.
Meet the author
Hi, I'm Maximus Vancaneghem, a Technical Associate in World Wide Technology's Associate Academy, on track toward the Eastern Technical Operations Center of Excellence. My background is in IT and cybersecurity, and what drew me to tech in the first place was an undying need to understand how things function and connect. That same curiosity follows me outside of work, whether I'm wrenching on motorcycles as a hobbyist mechanic or keeping up with the ever-changing tech landscape.