ANSSI Sets 2027 Deadline for Quantum-Safe Certification
Cookie policy
Quantum Security & PQC
France’s ANSSI Will Block PQC-Free Products From Certification Starting 2027
Marin Ivezic
Follow on X
Send an email
June 17, 2026<br>7 minutes read
Table of Contents
June 17, 2026 — France’s national cybersecurity agency, ANSSI (Agence Nationale de la Sécurité des Systèmes d’Information), confirmed on Tuesday that it will stop certifying security products that lack quantum-resistant encryption. The deadline is 2027.
Samih Souissi, ANSSI’s chief of staff, made the announcement at the France Quantum 2026 conference at Station F in Paris. He added that businesses should be purchasing only quantum-safe products by 2030, Reuters reported.
ANSSI certification (known as “qualification” in French regulatory terminology) is a prerequisite for use across French government agencies and critical infrastructure operators. Losing certification eligibility amounts to losing access to one of Europe’s largest government technology markets.
Souissi framed the decision as extending beyond technical cybersecurity. “It’s not only a technical issue,” he said. “It’s a matter of governance, industrial planning, regulation, and sovereignty.”
The policy reflects growing concern about Harvest Now, Decrypt Later (HNDL) attacks, in which adversaries intercept and store encrypted communications today with the intention of decrypting them once a cryptographically relevant quantum computer (CRQC) becomes available.
Industry players at the conference signaled that demand for PQC-capable products is already accelerating. Pascal Brier, chief innovation officer at Capgemini, told Reuters that banks and public services are actively assessing their exposure. “That market is becoming big. It’s going to be very substantial,” Brier said.
IBM executive Jerry Chow said at the event that the quantum threat to current cryptography could materialize by the mid-2030s. Separately, Qperfect warned that the Elliptic Curve Digital Signature Algorithm (ECDSA), widely used in blockchain systems, could be among the earliest targets for quantum attacks.
Fanny Bouton, head of quantum at French cloud provider OVHcloud, told Reuters the industry faces a compounding compliance challenge. “We face two challenges: auditing our products and securing all the data we hold in order to meet ANSSI’s requirements,” she said. As a European operator, OVHcloud must simultaneously satisfy ANSSI, the European Commission’s requirements, and U.S. NIST standards.
France has backed its quantum technology ambitions with a national strategy launched in 2021 that committed €1.8 billion in public and private funding over four years. [EDITOR: Reuters cites a “3 billion euro” figure; the original 2021 plan was €1.8 billion. The discrepancy may reflect additional commitments since 2021, including the PROQCIMA program for quantum computer development. Verify the current total before publication.]
My Analysis
ANSSI has been telegraphing this move for years. Its first position paper on the PQC transition arrived in 2022, with a follow-up in late 2023 that stated ANSSI would “stop delivering security labels for certain types of products claiming long-term security” without PQC. The agency’s own FAQ page confirmed it was targeting “PQC obligations for qualification starting in 2027.” What changed yesterday is that ANSSI’s chief of staff said it publicly at a major conference, in front of the French quantum ecosystem, with Reuters in the room. The guidance became a commitment.
I wrote three weeks ago that post-quantum deadlines are likely about to compress, with governments converting their 2025 guidance documents into binding obligations clustered around 2028 to 2030. ANSSI’s announcement is the latest confirmation of that pattern, and one of the clearest: a certification authority with direct market-access power, setting a hard date, in public, at a conference covered by international media.
Another 2027 Procurement Gate
The timing is impossible to ignore. ANSSI’s 2027 certification cutoff now runs in parallel with NSA’s CNSA 2.0 procurement gate, which requires all new National Security System acquisitions to support CNSA 2.0 algorithms starting January 1, 2027. Two of the world’s most demanding cryptographic certification authorities, serving two of the world’s largest defense and government technology markets, have independently converged on the same year for making PQC a pass-fail requirement.
The mechanisms differ. CNSA 2.0 operates through procurement eligibility, NIAP validation, and the Risk Management Framework. ANSSI operates through its qualification and certification schemes, which function as a gatekeeper for any security product deployed...