France’s Security Qualification Gate Starts Closing to Non-PQC Products in 2027
France is beginning to turn post-quantum cryptography from a product-roadmap promise into a condition for entering its security-qualification process.
ANSSI, France’s national cybersecurity agency, says post-quantum cryptography will become mandatory for entry into qualification from 2027, at least for certain types of product. The scope matters. This is not a categorical ban on every non-PQC product, and it is not a blanket law for every organisation operating in France.
It is still a consequential market signal. ANSSI qualification is used to identify trusted security products, particularly for government, critical and otherwise sensitive environments. A supplier that cannot show how its product will adopt post-quantum mechanisms may find its route into those procurements narrowing before a useful quantum computer exists.
The first deadline lands in product qualification
ANSSI’s current FAQ separates developers of security products from organisations buying them. For developers, the agency aims to establish post-quantum requirements for entry into qualification from 2027, with the initial obligation applying to at least some product types.
For buyers outside a specifically regulated environment, ANSSI does not describe a new universal legal duty. It instead says that purchasing products without post-quantum cryptography after 2030 will no longer be reasonable. That advice should be read as a lifecycle and procurement warning: equipment bought now may still be protecting data or identities well into the 2030s.
| Date | French policy signal | Operational meaning |
|---|---|---|
| Now | Inventory cryptographic uses and prioritise long-lived protection needs | Find algorithms, protocols, certificates, keys, suppliers and replacement constraints |
| From 2027 | PQC requirements begin entering ANSSI qualification for at least certain product types | Vendors need credible implementations and evaluation evidence, not only roadmap language |
| After 2030 | ANSSI says buying products without PQC will no longer be reasonable | Procurement cycles must avoid introducing new cryptographic debt that survives into the quantum-risk window |
The risk arrives before the machine
Cryptographically relevant quantum computers do not yet exist at the scale required to break widely used public-key cryptography. That uncertainty does not remove the present risk.
Some systems bought today will remain deployed after 2030. Some information must remain confidential for a decade or longer. An adversary can collect encrypted traffic now and attempt to decrypt it later, a strategy usually described as harvest now, decrypt later. State information, healthcare data, intellectual property and critical-infrastructure designs can lose value or cause harm long after their original transmission.
The migration itself also takes time. Public-key cryptography appears in certificates, virtual private networks, code signing, firmware, identity systems, hardware security modules, embedded equipment, cloud services and third-party libraries. Replacing an algorithm in a laboratory is much easier than changing every protocol, trust store, contract and device that depends on it.
Start with cryptographic discovery
Most organisations cannot produce a complete answer to three basic questions: where public-key cryptography is used, which information it protects and how long that protection must last. The first post-quantum deliverable is therefore an inventory, not an algorithm choice.
- Map internet-facing and private PKI certificates.
- Record VPN, remote-access and site-to-site encryption.
- Identify code, firmware and document-signing dependencies.
- Locate key-management systems and hardware security modules.
- Include embedded devices, operational technology and appliances with long replacement cycles.
- Record cryptography inside third-party protocols, libraries, platforms and managed services.
- Identify archives and backups whose confidentiality must survive beyond 2030.
For each use, record the owner, algorithm, key size, protocol, data lifetime, update mechanism and replacement constraint. Priority belongs to information with a long confidentiality life and systems that cannot be changed quickly.
Buy crypto-agility, not a label
Quantum-safe can become an empty marketing phrase. A useful procurement response asks which standardised algorithms are supported, whether classical and post-quantum methods can operate together, how keys and certificates will be rotated and whether the cryptographic choice can be changed without replacing the product.
ANSSI currently emphasises hybrid mechanisms where post-quantum protection is needed. Hybridisation combines a recognised classical mechanism with a post-quantum one so that adopting the newer component does not discard established protection while implementations mature. Crypto-agility supplies the second safeguard: the ability to change parameters or algorithms when evidence, standards or implementation risks change.
Technical support in a mainstream platform can help organisations test that transition, but it does not substitute for French product qualification. For example, Windows 11 update KB5120998 added a standalone ML-KEM option for TLS key exchange. That is useful for interoperability and deployment testing. It is not evidence that a particular Windows configuration or product fulfils ANSSI qualification requirements.
The pressure now extends beyond France
On 3 September 2026, under France’s G7 presidency, ANSSI and its G7 partners issued a further call for public and private decision-makers to begin the post-quantum transition now. The European Commission and ENISA participated as guests.
The statement adds political and operational pressure, not a new European law. Its significance is the growing alignment around governance, cryptographic inventories, risk prioritisation, crypto-agility and procurement before the threat becomes an observable crisis.
Put the dates into contracts now
Security and procurement teams should translate the 2027 and 2030 signals into portfolio decisions. Products intended for French government, critical or other qualification-dependent environments need a clear route through the relevant evaluation process. Other organisations can still use the dates as planning anchors without pretending that the guidance creates a legal duty where ANSSI says none currently exists.
- Add post-quantum requirements and evidence requests to new tenders.
- Ask suppliers for supported algorithms, hybrid modes, update paths and lifecycle dates.
- Link certificate, PKI and device-renewal plans to information-retention requirements.
- Test post-quantum interoperability and performance in low-risk environments.
- Require a migration route for products expected to remain in service after 2030.
- Avoid treating one supported algorithm as proof of a complete, secure or qualified implementation.
The transition is not one cryptographic upgrade. It is a multi-year change across protocols, products, trust stores, contracts and institutional habits. France’s qualification timetable makes one part of that future concrete: some products will need more than a promise when they approach the gate in 2027.
Official sources
- ANSSI: post-quantum cryptography FAQ, current guidance accessed 7 September 2026.
- ANSSI: post-quantum cryptography guidance and initiatives, current guidance accessed 7 September 2026.
- G7 Cybersecurity Working Group statement on preparing for a post-quantum cryptography migration, published 1 June 2026. No publication time was provided.
- G7 Cybersecurity Working Group: Preparing for the Post-Quantum Era, A Call to Action, published 3 September 2026. No publication time was provided.
This article provides general information and does not constitute legal, procurement or cryptographic-engineering advice. Article updated in September 2026


