France’s national cybersecurity agency, ANSSI, will stop certifying security products lacking quantum-resistant encryption by 2027, mandating that all government and critical infrastructure technology transition to quantum-safe standards.
Key Points
- ANSSI will require quantum-resistant encryption for all security product certifications starting in 2027.
- The agency mandates that businesses exclusively purchase quantum-safe products for critical infrastructure by 2030.
- ANSSI’s policy requires hybrid cryptographic implementations, combining classical and post-quantum algorithms, rather than standalone post-quantum solutions.
- This 2027 deadline aligns with the U.S. National Security Agency’s CNSA 2.0 procurement requirements, creating a synchronized global standard for government technology.
- The mandate aims to mitigate "Harvest Now, Decrypt Later" attacks, where adversaries store encrypted data today to decrypt it once quantum computers become viable.