France to stop certifying non-quantum encryption from 2027

ANSSI will stop certifying products without quantum-safe encryption from 2027 and urges buyers to use only quantum-resistant products by 2030, citing risk that future quantum computers could unlock encrypted data.

France’s cybersecurity agency ANSSI will stop certifying security products that lack quantum-safe encryption from 2027 and advises companies to procure only quantum-resistant products by 2030. The requirement applies to products used by French government agencies and critical infrastructure operators and will affect vendors seeking ANSSI certification.

Officials said the policy responds to the possibility that future quantum computers could break the public-key algorithms that protect many online services and cryptocurrency wallets. ANSSI framed the change as a matter of governance, industrial planning, regulation and sovereignty. “It is a matter of governance, industrial planning, regulation and sovereignty,” ANSSI chief of staff Samih Souissi told the France Quantum conference.

Security experts warn of so-called “harvest now, decrypt later” attacks, in which adversaries collect encrypted data today with the expectation that stronger quantum machines will be able to decrypt it later. Quantum algorithms that, in principle, can factor large numbers and solve the mathematical problems behind common encryption schemes have not yet been demonstrated at scale.

Estimates for when quantum machines could threaten current cryptography vary. One large technology firm has set internal targets around 2029 to move systems to post-quantum algorithms. A quantum security firm has estimated a cryptographically relevant quantum computer could appear around 2030 and noted that millions of Bitcoin could be exposed if private keys are not migrated.

Parts of the crypto industry are preparing technical plans. Coinbase’s quantum advisory council has urged blockchain developers to begin planning migrations to post-quantum cryptography and to decide how networks should treat coins held in addresses whose owners do not migrate. The Stellar Development Foundation published a three-stage roadmap to move the XLM network to quantum-resistant signatures, including a protocol change that would let users add quantum-resistant signers without changing wallet addresses. The Ethereum Foundation has created a dedicated team to work on post-quantum security for its network.

Vendors that want ANSSI certification will need to show integration of quantum-resistant algorithms and update key-management practices for products such as encryption modules, authentication systems and secure communications gear. Companies outside France that supply French government bodies or critical operators may face commercial pressure to adopt quantum-safe solutions.

Boundless CEO Shiv Shankar noted that projections about timelines have tightened and that organizations need to plan and engineer migrations now, while also cautioning against immediate panic: “The risk is going up, but this was expected. There’s no cause for panic.”

ANSSI’s procurement deadline is among the earliest clear national cut-offs tied to quantum resistance. The requirement raises questions for governments, infrastructure operators and blockchain projects about migration paths, key-management changes and how to treat funds held in addresses that are not updated to quantum-resistant formats.

The material on GNcrypto is intended solely for informational use and must not be regarded as financial advice. We make every effort to keep the content accurate and current, but we cannot warrant its precision, completeness, or reliability. GNcrypto does not take responsibility for any mistakes, omissions, or financial losses resulting from reliance on this information. Any actions you take based on this content are done at your own risk. Always conduct independent research and seek guidance from a qualified specialist. For further details, please review our Terms, Privacy Policy and Disclaimers.

Articles by this author