Quantum-secure encryption with Zscaler - without crypto conversion
The biggest hurdle in post-quantum cryptography is rarely the technology, but the fear of the large-scale project. PQC can be provided centrally via a Zero Trust architecture - even for systems that cannot become quantum-safe themselves.
It is now undisputed that companies need to switch to quantum-secure encryption - the attack strategy "Harvest now, decrypt later" makes the issue acute. The real question is: How can you switch without touching every application, every server and every old system individually? This is where a Zero Trust platform comes into its own.
The problem with the classic approach
Anyone who introduces PQC on an application-by-application basis is faced with a mammoth project: Every software, every library, every embedded device would have to have its own quantum-safe algorithms. With legacy and IoT/OT systems, this is often simply impossible - they can no longer be updated at all. Such a restructuring takes years, during which the data is further skimmed off.
The Zero Trust Approach: PQC Central to the Data Stream
A Zero Trust platform like the Zscaler Zero Trust Exchange sits inline in data traffic. It decrypts traffic, checks it for threats, and re-encrypts it before forwarding it to its destination. This is exactly where quantum-safe encryption comes in: Zscaler conducts an inline inspection with NIST-standardized hybrid key exchange ML-KEM (FIPS 203) - and provides PQC visibility and reporting in the admin portal.
Also for legacy and IoT/OT systems
Non-upgradable devices in particular - industrial controls, sensors, older appliances - are the greatest PQC risk because they cannot be retrofitted in the traditional way. In the Zero Trust model, their data traffic is routed through the platform and encapsulated there in a quantum-secure manner. This creates protection without touching the devices themselves. We describe how this basically works for IoT/OT in the article on the Zero Trust Securing IoT/OT Environments.
Full performance despite larger keys
Post-quantum methods often use larger keys than classical cryptography. In a globally distributed cloud platform, however, the data throughput is optimized in such a way that users do not notice any difference in everyday life - except that their communication is quantum-safe.
How we do it at SourcingBlox
- Crypto Discovery: We record which encryption is running in the data stream and which systems need to be encapsulated in a quantum-secure manner.
- Prioritization according to term of protection: Long-lasting data flows that require special protection first.
- Enable inline PQC: Provide quantum-secure encryption via the Zero Trust platform - including visibility in reporting.
- Operate data sovereignty: Fully European hosted on request - ideal for regulated industries and critical infrastructures.
- Proof & Compliance: PQC reporting as evidence for audits and upcoming regulatory requirements (NIST, BSI).
PQC readiness without a major project
We will show you how quickly quantum-secure encryption becomes productive via a zero-trust architecture - data sovereign and auditable.
Make an appointment for a consultation →Frequently Asked Questions
The Zero Trust Exchange sits inline in the data stream and uses the NIST-standardized hybrid key exchange ML-KEM (FIPS 203). Traffic is re-encrypted in a quantum-secure manner; PQC visibility and reporting are available in the admin portal.
No. Quantum-safe encryption is provided centrally in the data stream. Even legacy and IoT systems that are not PQC-capable themselves are encapsulated through quantum-safe tunnels.
A quantum-resistant method for key exchange standardized by NIST in 2024. It is often combined with classical cryptography in a hybrid way to protect against future quantum attacks today.
- Zscaler – Post-Quantum Cryptography Inline Inspection (Solution Brief) & Zenith Live 2026 Announcements (ML-KEM / FIPS 203)
- NIST - FIPS 203 (ML-KEM), released in 2024
- BSI - Recommendations for Migration to Quantum-Safe Cryptography
