Skip to content
Tech News
← Back to articles

France's Anssi Will Block PQC-Free Products from Certification Starting 2027

read original more articles
Why This Matters

France's ANSSI will cease certifying security products that lack quantum-resistant encryption by 2027, emphasizing the urgent need for industry-wide adoption of quantum-safe solutions. This move underscores the growing threat of quantum computing to current cryptographic standards and highlights the importance of proactive governance and regulation in safeguarding critical infrastructure. For consumers and businesses alike, this signals a pivotal shift towards more secure, future-proof cybersecurity practices in the coming years.

Key Takeaways

June 17, 2026 — France’s national cybersecurity agency, ANSSI (Agence Nationale de la Sécurité des Systèmes d’Information), confirmed on Tuesday that it will stop certifying security products that lack quantum-resistant encryption. The deadline is 2027.

Samih Souissi, ANSSI’s chief of staff, made the announcement at the France Quantum 2026 conference at Station F in Paris. He added that businesses should be purchasing only quantum-safe products by 2030, Reuters reported.

ANSSI certification (known as “qualification” in French regulatory terminology) is a prerequisite for use across French government agencies and critical infrastructure operators. Losing certification eligibility amounts to losing access to one of Europe’s largest government technology markets.

Souissi framed the decision as extending beyond technical cybersecurity. “It’s not only a technical issue,” he said. “It’s a matter of governance, industrial planning, regulation, and sovereignty.”

The policy reflects growing concern about Harvest Now, Decrypt Later (HNDL) attacks, in which adversaries intercept and store encrypted communications today with the intention of decrypting them once a cryptographically relevant quantum computer (CRQC) becomes available.

Industry players at the conference signaled that demand for PQC-capable products is already accelerating. Pascal Brier, chief innovation officer at Capgemini, told Reuters that banks and public services are actively assessing their exposure. “That market is becoming big. It’s going to be very substantial,” Brier said.

IBM executive Jerry Chow said at the event that the quantum threat to current cryptography could materialize by the mid-2030s. Separately, Qperfect warned that the Elliptic Curve Digital Signature Algorithm (ECDSA), widely used in blockchain systems, could be among the earliest targets for quantum attacks.

Fanny Bouton, head of quantum at French cloud provider OVHcloud, told Reuters the industry faces a compounding compliance challenge. “We face two challenges: auditing our products and securing all the data we hold in order to meet ANSSI’s requirements,” she said. As a European operator, OVHcloud must simultaneously satisfy ANSSI, the European Commission’s requirements, and U.S. NIST standards.

France has backed its quantum technology ambitions with a national strategy launched in 2021 that committed €1.8 billion in public and private funding over four years. [EDITOR: Reuters cites a “3 billion euro” figure; the original 2021 plan was €1.8 billion. The discrepancy may reflect additional commitments since 2021, including the PROQCIMA program for quantum computer development. Verify the current total before publication.]

My Analysis

... continue reading