France's ANSSI will block non-PQC products from certification starting 2027
A national security agency is making post-quantum cryptography mandatory for product certification, signaling regulatory shifts ahead of quantum threats.
Certification deadline set for quantum-resistant systems
France's cybersecurity authority ANSSI will refuse to certify products lacking post-quantum cryptography (PQC) capabilities beginning in 2027. The mandate applies to all products seeking government security certification, requiring them to implement quantum-resistant cryptographic algorithms.
The decision reflects growing concern about "harvest now, decrypt later" attacks, where adversaries collect encrypted data today to decrypt once quantum computers become powerful enough. Organizations developing products for government or critical infrastructure markets in France will need to integrate PQC standards ahead of the deadline.
Europe moves toward quantum-safe standards
The French requirement follows NIST's publication of standardized post-quantum algorithms in 2024 and represents one of the first national-level enforcement mechanisms. Vendors will need to adopt algorithms like CRYSTALS-Kyber for key exchange and CRYSTALS-Dilithium for digital signatures.
The three-year lead time allows organizations to audit existing cryptographic implementations, test PQC integrations, and update product roadmaps. Security teams should prioritize systems handling long-lived sensitive data or operating in environments where encrypted traffic could be intercepted and stored.