---
title: "Introducing Data-in-Transit Encryption for Calico Enterprise"
source: "https://www.tigera.io/blog/introducing-data-in-transit-encryption-for-calico-enterprise/"
description: "Calico Enterprise, the leading solution for Kubernetes networking, security and observability in hybrid and multi-clouds now includes encryption for data-in-transit."
---

[Technical Blog](https://www.tigera.io/category/technical-blog/)

# Introducing Data-in-Transit Encryption for Calico Enterprise

By [John Armstrong](https://www.tigera.io/blog/author/john-armstrong/) on Oct 29, 2020 • 3 min read

We’re excited to announce that Calico Enterprise, the leading solution for [Kubernetes networking](https://www.tigera.io/learn/guides/kubernetes-networking/), security and observability in hybrid and multi-cloud environments, now includes encryption for data-in-transit.

Calico Enterprise is known for its rich set of network security implementations to protect container workloads by restricting traffic to and from trusted sources. These include, but are not limited to, [implementing existing enterprise security controls in Kubernetes](https://www.tigera.io/tigera-products/security-controls/), managing [egress access using DNS policy](https://www.tigera.io/features/access-controls/), [extending firewalls to Kubernetes,](https://www.tigera.io/features/access-controls/) and [intrusion detection and threat defense](https://www.tigera.io/features/intrusion-detection-system/). As the Kubernetes footprint expands, however, we’ve seen demand for an even greater in-depth approach to protecting sensitive data that falls under regulatory compliance mandates.

## Why encryption is necessary

Not all threats originate from outside an organization. According to Gartner, nearly 75% of breaches happen [due to insider behavior](http://www.cebglobal.com/member/information-risk/blog/15/is-employee-behavior-your-biggest-risk-4-easy-steps-to-find-out.html?sso=gartner), from people within the organization such as employees, former employees, contractors or business associates, who have inside information concerning the organization’s security practices, data and computer systems. This level of exposure is unacceptable for organizations that have strict data protection and regulatory compliance requirements. No matter where a threat originates, encrypted data is unreadable to anyone except the legitimate keyholder, thus protecting the data should a breach occur.

![A padlock connecting two blocks of binary code, representing insider threat breaches](https://www.tigera.io/app/uploads/2020/07/Encrypt-Data-in-transit-1.png)

## Encryption requirements for compliance

Several regulatory standards impose data protection and compliance requirements on organizations and specify the use of encryption, including SOX, HIPAA, GDPR, and PCI. For example, the Payment Card Industry Data Security Standard ([PCI DSS](https://www.tigera.io/lp/kubernetes-pci-compliance/)) applies to organizations that handle branded credit cards and was created to increase controls around cardholder data to reduce credit card fraud. PCI DSS requires organizations to encrypt credit card account numbers stored in their databases and ensure that data remains secure when transferred. Validation of compliance is performed annually or quarterly.

## Encryption methods

A common solution is to encrypt traffic at the application layer using protocols like Transport Layer Security (TLS). Traffic can also be encrypted at a lower infrastructure level using IPsec. However, these approaches introduce an additional layer of complexity and performance implications. Encrypting traffic with TLS requires SSL certificates, creating operational overhead for IT organizations that are already overburdened.

![Benchmark showing performance implications of encrypted CNIs in Kubernetes, with bandwidth comparisons](/app/uploads/2020/10/Encrypted-CNI-Benchmarks_Aug2020-1-300x225.png)

## Calico’s Data-in-Transit encryption

Calico Enterprise avoids that complexity by utilizing WireGuard to implement data-in-transit encryption. WireGuard is consistent with Tigera’s “batteries-included” approach to Kubernetes networking, security and observability. WireGuard runs as a module inside the Linux kernel and provides better performance and lower CPU utilization than IPsec and OpenVPN tunneling protocols. Independent [benchmark tests of Kubernetes CNI’s](http://itnext.io/benchmark-results-of-kubernetes-network-plugins-cni-over-10gbit-s-network-updated-august-2020-6e1b757b9e49) have shown that Calico with encryption enabled is [6x faster than any other solution](https://miro.medium.com/max/700/1*eul4ltPeOmG9pwK7VR_8Gw.png) in the market.

We are pleased to announce that WireGuard encryption is now generally available with Calico Enterprise v3.3. The addition of data-in-transit encryption augments an existing rich security feature set in Calico Enterprise. And with Calico Enterprise, you’ll maintain [visibility into all traffic in your Kubernetes clusters](https://www.tigera.io/tigera-products/observability-and-troubleshooting/) even when encryption is deployed. Enabling data-in-motion encryption on Calico Enterprise is easy… all you need is a Kubernetes cluster with WireGuard installed on the host operating system. You’ll find a complete list of supported operating systems and installation instructions on the [WireGuard website](http://www.wireguard.com/install/).

————————————————-

[**Free Online Training**](https://www.tigera.io/events/)

Access Live and On-Demand Kubernetes Training

[**Calico Enterprise – Free Trial**](https://www.calicocloud.io/home)

Kubernetes Networking, Security and Observability in Hybrid and Multi-Clouds

[Products](https://www.tigera.io/tags/products/)[Announcements](https://www.tigera.io/tags/announcements/)

## Related posts

[![Meet Mylo: An AI-native way to work with Calico](https://www.tigera.io/app/uploads/2026/09/Meet-Mylo-An-AI-native-way-to-work-with-Calico.png)](https://www.tigera.io/blog/meet-mylo-an-ai-native-way-to-work-with-calico/)

#### [Meet Mylo: An AI-native way to work with Calico](https://www.tigera.io/blog/meet-mylo-an-ai-native-way-to-work-with-calico/)

By [Phil DiCorpo](https://www.tigera.io/blog/author/phil-dicorpo/)
on Sep 3, 2026

A library of Calico tools and skills — delivered through the Calico MCP Server What if your hardest network question took ten minutes instead of ten days? Anyone who has operated Kubernetes networking at scale...

[Read more](https://www.tigera.io/blog/meet-mylo-an-ai-native-way-to-work-with-calico/)

[![The Safest Place to Run an AI Agent Is On a Cluster That Doesn’t Trust It](https://www.tigera.io/app/uploads/2026/08/The-Safest-Place-to-Run-an-AI-Agent-Is-On-a-Cluster-That-Doesnt-Trust-It.png)](https://www.tigera.io/blog/the-safest-place-to-run-an-ai-agent-is-on-a-cluster-that-doesnt-trust-it/)

#### [The Safest Place to Run an AI Agent Is On a Cluster That Doesn’t Trust It](https://www.tigera.io/blog/the-safest-place-to-run-an-ai-agent-is-on-a-cluster-that-doesnt-trust-it/)

By [Alister Baroi](https://www.tigera.io/blog/author/alister-baroi/)
on Aug 27, 2026

Every organization running AI agents has already made a hosting decision. Most made it by accident. The sales team switched on the agent built into their CRM. Engineering is piloting a coding agent in a...

[Read more](https://www.tigera.io/blog/the-safest-place-to-run-an-ai-agent-is-on-a-cluster-that-doesnt-trust-it/)

[![AI Red Team Agents Automate Attacks on your AI Agents. Runtime Policies Automate their Defense.](https://www.tigera.io/app/uploads/2026/08/AI-Red-Team-Agents-Automate-Attacks-on-your-AI-Agents.-Runtime-Policies-Automate-their-Defense.png)](https://www.tigera.io/blog/ai-red-team-agents-automate-attacks-on-your-ai-agents-runtime-policies-automate-their-defense/)

#### [AI Red Team Agents Automate Attacks on your AI Agents. Runtime Policies Automate their Defense.](https://www.tigera.io/blog/ai-red-team-agents-automate-attacks-on-your-ai-agents-runtime-policies-automate-their-defense/)

By [Alister Baroi](https://www.tigera.io/blog/author/alister-baroi/)
on Aug 24, 2026

The AI red teaming market grew up fast this year. OpenAI bought Promptfoo, Cisco and Microsoft shipped automated attack suites, and a seed-stage startup publicly compromised 50 of 55 live customer service bots. These platforms...

[Read more](https://www.tigera.io/blog/ai-red-team-agents-automate-attacks-on-your-ai-agents-runtime-policies-automate-their-defense/)

<!-- plugin=object-cache-pro client=phpredis metric#hits=3170 metric#misses=33 metric#hit-ratio=99.0 metric#bytes=1571117 metric#prefetches=0 metric#store-reads=174 metric#store-writes=22 metric#store-hits=169 metric#store-misses=22 metric#sql-queries=39 metric#ms-total=501.33 metric#ms-cache=32.74 metric#ms-cache-avg=0.1679 metric#ms-cache-ratio=6.5 sample#redis-hits=45330103 sample#redis-misses=12847753 sample#redis-hit-ratio=77.9 sample#redis-ops-per-sec=93 sample#redis-evicted-keys=0 sample#redis-used-memory=106635504 sample#redis-used-memory-rss=95981568 sample#redis-memory-fragmentation-ratio=0.9 sample#redis-connected-clients=1 sample#redis-tracking-clients=0 sample#redis-rejected-connections=0 sample#redis-keys=64178 -->
