France Puts Dates on the Post-Quantum Cryptography Transition
France’s ANSSI has turned post-quantum cryptography from a distant research topic into a procurement and product-roadmap decision.
France’s national cybersecurity agency, ANSSI, said that products without post-quantum cryptography would no longer be eligible to enter its security-qualification process from 2027. It also advised organisations to purchase only quantum-safe products by 2030.
ANSSI qualification is particularly important for products used by government and critical operators. The timeline therefore sends a broader market signal: vendors that cannot explain their post-quantum migration path may find themselves excluded from long-lived or sensitive procurements.
The risk arrives before a useful quantum computer
Cryptographically relevant quantum computers do not yet exist at the required scale. Migration still needs to begin now for two reasons.
First, some systems and devices bought today will still be operating in the 2030s. Second, an adversary can collect encrypted traffic now and attempt to decrypt it later. Data with a long confidentiality life—state information, health records, intellectual property or critical-infrastructure designs—may already be exposed to this “harvest now, decrypt later” strategy.
Start with cryptographic discovery
Most organisations cannot answer where public-key cryptography is used, which algorithms protect each data flow or how long the relevant information must remain secret. That inventory is the first deliverable.
Map:
- internet and private PKI certificates;
- VPN, remote-access and site-to-site encryption;
- code, firmware and document signing;
- key-management systems and hardware security modules;
- embedded devices and operational technology;
- third-party protocols, libraries and managed services;
- archived encrypted data and long-retention backups.
Record ownership, algorithm, key size, protocol, data lifetime and replacement constraint. Prioritise systems where sensitive data has a long life or where hardware replacement takes years.
Buy crypto-agility, not a label
“Quantum-safe” can become an unhelpful marketing claim. Procurement should ask which standardised algorithms are supported, whether classical and post-quantum methods can operate in a hybrid configuration, how keys and certificates will be rotated, and whether algorithms can be changed without replacing the product.
Vendors should provide performance data, interoperability evidence, implementation assurance and a supported migration schedule. A mathematically strong algorithm can still be undermined by poor randomness, side channels or unsafe protocol integration.
ANSSI’s approach emphasises defence in depth and a staged transition rather than an overnight replacement. Hybrid mechanisms can reduce the risk of relying entirely on a newer algorithm while implementations mature.
Put dates into contracts and architecture
Security and procurement teams should translate the 2027 and 2030 signals into portfolio decisions now. Products intended for French government or critical environments need an explicit qualification path. Other organisations can use the same dates as useful planning anchors.
Add post-quantum requirements to new tenders, certificate and PKI roadmaps, device-lifecycle decisions and supplier reviews. Test migration in low-risk environments before the oldest systems become the deadline’s critical path.
The transition is not one cryptographic upgrade. It is a multi-year change across protocols, devices, trust stores and contracts. France has made the starting signal hard to ignore.
Official sources
- ANSSI: post-quantum cryptography FAQ
- ANSSI: post-quantum cryptography guidance
- G7 Cybersecurity Working Group statement on PQC migration
This article is general information, not legal, procurement or cryptographic engineering advice.



