ZeroTier and Carahsoft: what is signed is a route to market
7 min read
On 6 August 2026 ZeroTier and Carahsoft announced, in a joint release published in Carahsoft’s newsroom, a partnership to bring post-quantum-secure, software-defined networking to the US public sector. The headline reads broadly: “ZeroTier and Carahsoft Partner to Bring Post-Quantum Secure, Software-Defined Networking to the Public Sector.” The sentence that actually describes what was signed says something narrower: the object of the deal is distribution. We state the distinction that carries this piece straight away: a sales channel is not an authorisation to deploy. These are two different things, with two different sets of responsibility, and the announcement covers only the first.
A small company selling to a large government needs both, and a press release tends to make them sound like one. The channel gets you bought; the authorisation gets you deployed where a regulatory requirement demands it. This deal delivers the first; the second is not the subject of the announcement, and should not be inferred. We measured the same pattern from the other side — who answers for security when the authorisation belongs to someone else — in Palantir and KODE Labs; the European timetable for the cryptographic transition is in this note.
What the deal actually says
The sentence that matters, verbatim: “Under the agreement, Carahsoft will expand access to ZeroTier solutions across the Public Sector through its distribution network, making the company’s software-defined, end-to-end quantum-secure networking platform, ZeroTier Quantum, available to the Public Sector through Carahsoft’s reseller partners and the NASA Solutions for Enterprise-Wide Procurement (SEWP) V contract.” A reseller network plus availability on a contract vehicle: that is distribution, not a security authorisation, not a certification, not a direct contract with a government body. Andrew Gault, ZeroTier’s CEO, uses the same register: “Through Carahsoft’s strength and reach, agencies can more easily access ZeroTier’s platforms through established procurement channels to rapidly accelerate their deployments” — procurement channels, not an authorisation.
What SEWP is, from NASA’s own site, verbatim: “The NASA SEWP (Solutions for Enterprise-Wide Procurement) GWAC (Government-Wide Acquisition Contract) provides the latest in Information Technology, Communication and Audio Visual (ITC/AV) products and services for all Federal Agencies and their approved contractors.” A GWAC is a vehicle through which agencies buy: being listed on SEWP means being purchasable, not approved. One detail, read with caution on the same page: a notice states that “NASA is in the process of making awards for the Solutions for Enterprise-Wide Procurement (SEWP) VI contracts.” The vehicle named is the V generation, while awards for VI are under way: we draw no conclusion about the remaining life of the V contract, which we have not verified.
What ZeroTier Quantum actually does
Robert Stevenson, ZeroTier’s CCO, frames the urgency: “The White House and international security agencies are clear: the threat of quantum computing cracking modern encryption isn’t a future problem; It’s a today problem.” The release, verbatim: “ZeroTier Quantum redefines secure networking by embedding post-quantum cryptographic resilience directly into the transport layer. Leveraging the ZeroTier Transport Protocol (ZTP) and a memory-safe Rust architecture, the platform implements hybrid ML-KEM-1024 and ECDH P-384 cryptography to neutralize ‘harvest now, decrypt later’ and ‘trust now, forge later’ threats.”
Put plainly: “hybrid” means the platform combines two algorithms — one post-quantum, ML-KEM, the key-encapsulation mechanism NIST standardised as FIPS 203, “Module-Lattice-Based Key-Encapsulation Mechanism Standard” — and one classical elliptic-curve algorithm, ECDH P-384. The reason is a hedge: if either fails, security still holds on the other. “Harvest now, decrypt later” is the threat this architecture neutralises: an adversary records encrypted traffic today, to decrypt it tomorrow once a sufficiently powerful quantum computer exists. The release adds, verbatim: “By meeting rigorous NIST and NSA CNSA 2.0 standards, ZeroTier Quantum delivers high-performance, infrastructure-agnostic connectivity that functions seamlessly across public cloud, sovereign and air-gapped environments, helping Government agencies maintain data sovereignty and operational continuity without sacrificing agility.”
The claim we could not verify
The sentence “By meeting rigorous NIST and NSA CNSA 2.0 standards” is a company self-declaration, contained in its own press release. It is not a certification: no third party is named as having verified it. We could not check it against a primary NSA source: nsa.gov and media.defense.gov block automated access, and that is a limit of our own checking, not a judgement on the platform. We are not writing that the claim is false. Nor are we writing that it is certified. We are writing that it is a first-party statement, and that the right question to put to anyone selling a product with this line is who verified it, against which scheme, and on what date.
Three partnerships in two days
In the same Carahsoft newsroom, three announcements built on the same headline template appear within two days. On 6 August: “ZeroTier and Carahsoft Partner to Bring Post-Quantum Secure, Software-Defined Networking to the Public Sector,” and, the same day, “PSJ Consulting and Carahsoft Partner to Bring Mission-Focused Consulting, Data, Compliance and Project Delivery Modernization Solutions to the Public Sector.” On 5 August: “Service IT Direct and Carahsoft Partner to Bring Advanced Third-Party Maintenance Solutions to the Public Sector.” Three different companies, same template, within 48 hours. Not a flaw in Carahsoft, which does exactly its own job and states so openly: it is evidence, taken from the source, that in this market “partnership” is often the word used to announce entry into a distribution catalogue.
How we check it
When a supplier brings us a partnership as a credential, we ask for the contract type and read it: distribution, resale, integration and co-development are different commitments, with different liabilities. We always separate the purchasing channel from the authorisation to deploy: being purchasable on a federal vehicle does not mean being authorised to handle classified data, nor does it satisfy a NIS2 requirement. And for every claim of compliance with a cryptographic standard, we ask for the name of the body that verified it and the date, and we file the answer — or its absence.
See the service · Talk to an engineer
The other side of the ledger, in fairness
ZeroTier publishes what it implements, with verifiable algorithm and standard names — ML-KEM-1024, ECDH P-384, FIPS 203 — and Carahsoft openly states that it is a distributor, not an accreditation authority. Neither party is hiding anything. The problem is not the announcement: it is the hurried reading buyers give it, and the mental shortcut by which “partner of” becomes “approved by.”
What it means for a European buyer
- Always ask for the type of contract signed: distribution, resale, integration and co-development are not the same thing.
- Separate the channel from the authorisation: being purchasable on a catalogue does not make you deployable where a regulatory requirement demands a formal assessment.
- Ask who verified a declared cryptographic compliance claim, and against which scheme: a self-declaration is legitimate, but it must be named as one.
- Check that the contract vehicle named in an offer is still the one actually in force, and not a generation being phased out.
- Remember the specifically European point: a US purchasing vehicle has no effect in Europe, where different supplier-qualification rules apply.
The two axes, applied
Checking what a supplier has actually signed is not a review done once and filed away. On the first axis — comply — it becomes a control running on the client’s contracts and systems, with a register of critical dependencies: for every supplier, what agreement, with whom, what it covers, which compliance claims are declared and by whom verified, with the date — ready to show an inspector or a board.
On the second axis — decide — the same system unifies contracts, suppliers, archives, management software and documents into a single operational model, on which AI agents execute decisions with a human operator in command, for large enterprises, defence, the public sector and healthcare. Applied here: when news breaks about a supplier, the answer to “where do we have it in-house, under which contract, and with which alternative” arrives in hours. Always in two modes: on-premises on self-contained machines with no deep integration into the client’s network, or a dedicated cloud with a dedicated VPN and a data centre in Italy — always with shared management.
Do you need to work out whether a partnership you have just been shown is a channel or an authorisation? Let’s talk: the first session is at no cost.