← Back to Blog
Enterprise||5 min read

AT&T Launches First PQC-Secured SD-WAN in North America

AT&T Business and Cisco debut quantum-resilient SD-WAN service. Enterprise PQC networking is now a commercial reality.

AT&T Business has announced it is the first major North American service provider to launch a Quantum Resilient SD-WAN service, powered by Cisco 8000 Series Secure Routers. This marks a significant milestone: post-quantum cryptography is no longer theoretical for enterprise networks.

What AT&T and Cisco Have Built

The new service integrates NIST-standardised post-quantum algorithms directly into SD-WAN infrastructure. Key features include:

  • ML-KEM key exchange: Quantum-resistant key encapsulation for all tunnel establishment
  • Hybrid mode: Classical and PQC algorithms run in parallel for backwards compatibility
  • Cisco 8000 Series: Purpose-built silicon with PQC acceleration
  • Managed service: AT&T handles the cryptographic complexity

Why This Matters

Until now, enterprises wanting PQC protection had to implement it themselves, typically at the application layer. This required specialist knowledge, custom development, and careful integration testing.

With AT&T's managed SD-WAN service, PQC becomes an infrastructure feature. Organisations can protect all traffic traversing their WAN without modifying applications or training staff on cryptographic implementation.

The Harvest Now, Decrypt Later Threat

The timing is critical. Adversaries are already intercepting and storing encrypted traffic, waiting for quantum computers capable of breaking today's encryption. This "harvest now, decrypt later" attack means sensitive data transmitted today could be exposed in 5 to 10 years.

For organisations handling data with long-term confidentiality requirements (financial records, healthcare data, government communications, intellectual property), the window for protection is closing.

What This Means for UK and EU Organisations

While AT&T's service is currently North American, it signals broader market movement:

  • European providers will follow: BT, Deutsche Telekom, and Orange are all working on similar offerings
  • NIS2 compliance: The directive requires "state of the art" security measures; PQC is increasingly interpreted as meeting this threshold
  • Vendor pressure: Cisco's involvement means PQC-capable hardware is entering mainstream procurement
  • Timeline acceleration: What was a 2030+ concern is now a 2026 reality

Cloudflare's 65% Milestone

AT&T's announcement follows Cloudflare reporting that over 65% of human traffic through its network is already protected by post-quantum methods. The infrastructure layer is moving faster than many application developers realise.

If your web traffic passes through Cloudflare (and statistically, much of it does), you may already have partial PQC protection without knowing it.

What You Should Do Now

  1. Assess your current state: Run a scan to understand your PQC readiness
  2. Identify sensitive data flows: Which communications have long-term confidentiality requirements?
  3. Talk to your providers: Ask your ISP, cloud providers, and CDN about their PQC roadmap
  4. Plan application-layer protection: Network-layer PQC does not protect data at rest or application tokens
  5. Budget for 2026 to 2027: PQC migration is no longer a future expense

Check Your PQC Readiness

Our free scan checks whether your site supports post-quantum key exchange and identifies gaps in your security posture.

The Bottom Line

AT&T and Cisco have made post-quantum networking a commercial product, not a research project. For enterprise security teams, this changes the conversation from "when should we start planning?" to "why have we not started yet?"

The organisations that act now will have a smooth transition. Those that wait will face rushed migrations under regulatory pressure, with fewer vendor options and higher costs.