Starting in 2027, France’s cybersecurity agency, ANSSI, will stop certifying any encryption product that doesn’t support quantum-resistant algorithms. By 2030, the agency wants businesses buying quantum-safe products exclusively, full stop. If you sell into French government agencies or critical infrastructure, that certification requirement isn’t optional advice. It’s a gate you don’t pass through anymore with last decade’s crypto stack.
This is the kind of deadline that looks distant until it isn’t. Eighteen months sounds like plenty of runway for a crypto migration, right up until you try to inventory every place RSA and elliptic-curve keys are baked into your products, your VPN concentrators, your code-signing pipeline, and the firmware you shipped five years ago that nobody budgeted to update. ANSSI just turned “quantum-safe encryption” from a research topic into a procurement checkbox, and that changes the calculus for every vendor and enterprise that touches the French market, or watches what French regulators do because everyone else tends to follow eventually.

ANSSI Sets A Hard Deadline: 2027
Here’s the mechanism, and it matters because it’s blunter than most regulatory pushes. ANSSI certification, called CSPN or the more rigorous Critères Communs process, is required for products sold into French government agencies and operators of critical infrastructure. Miss the certification, lose the market. Samih Souissi, ANSSI’s chief of staff, said at the France Quantum conference that the agency will halt certification of non-quantum-safe products from 2027 and expects businesses to be buying quantum-safe products only by 2030.
That’s not a suggestion to start researching post-quantum cryptography. It’s a de facto phase-out notice for an entire generation of encryption products, issued by the one agency whose sign-off a huge swath of the European critical infrastructure market depends on. Vendors who wait for a customer to ask about quantum resistance are going to find out the hard way that the customer’s procurement office already crossed them off the list.
Why This Is A Cybersecurity Problem, Not A Crypto One
It’s tempting to file this under “future problem,” something for the cryptographers to sort out while the rest of us handle today’s fires. That’s the wrong frame. The reason ANSSI is moving now, rather than waiting for a cryptographically relevant quantum computer to actually exist, is harvest-now-decrypt-later. Adversaries with nation-state resources are already collecting encrypted traffic and storing it, betting that quantum decryption capability arrives before the data stops being valuable. Diplomatic cables, health records, intellectual property, infrastructure control-system credentials: a lot of that has a shelf life measured in decades, which means it’s already at risk from a computer that doesn’t exist yet.
That’s a cybersecurity problem in the fullest sense: it touches risk assessment, asset inventory, and incident response planning, not just algorithm selection. A security program that treats “post-quantum” as a future line item on a roadmap, rather than a live category of exposure, is going to be surprised twice. Once when a regulator like ANSSI forces the issue, and again when they realize how much of their own encrypted data has already been sitting in someone else’s archive for years.
Migration Steps You Can Start This Quarter
You don’t need to wait for a French mandate to start this work, and you shouldn’t. Crypto migrations are slow by nature, full of legacy dependencies and vendor lag, so the organizations that start early are the ones that aren’t scrambling when a customer, auditor, or regulator asks the question cold. Treat this the same way you’d treat any other long-lead security hardening project: inventory first, prioritize by exposure, then execute in phases.
- Inventory every place cryptographic keys and algorithms are in use: TLS termination points, VPN and firewall configurations, code-signing infrastructure, database-at-rest encryption, and embedded device firmware.
- Flag data with a long confidentiality shelf life, anything that still needs to be secret in ten or twenty years, as harvest-now-decrypt-later risk and prioritize it first.
- Ask every vendor in your supply chain for their post-quantum roadmap in writing, not a verbal assurance, and put a follow-up date on the calendar.
- Build crypto agility into new procurement requirements now, so future algorithm swaps don’t require ripping out entire systems.
- Fold quantum-readiness into your existing incident response and threat detection playbooks, since a future decryption event needs a response plan just like any other breach.
None of this replaces the fundamentals. A quantum-resistant TLS stack sitting behind a poorly configured firewall, weak brute-force protections on your admin interfaces, and no real threat detection on the network is still a soft target. Post-quantum migration is one more layer in a defense in depth strategy, not a replacement for the layers you already need: patching discipline, least privilege, segmentation, and logging that someone actually reviews.
The Rest Of The World Isn’t Waiting Either
France isn’t acting alone, it’s just moving first with teeth. NIST finalized its post-quantum cryptography standards in 2024, and agencies in the US, UK, Germany, and elsewhere have published migration timelines with similar mid-2030s end dates for legacy algorithm retirement. What ANSSI has done differently is attach a certification cutoff to a specific, near-term calendar date, which turns a general industry direction into an enforceable market requirement. Expect other national agencies with similar certification regimes to follow that playbook rather than reinvent it.
For security teams outside France, the practical takeaway is the same regardless of jurisdiction: quantum-safe encryption is moving from optional to mandatory faster than most roadmaps assumed, and the organizations that treat 2027 and 2030 as somebody else’s problem are going to be the ones filing emergency change requests when a customer contract or regulatory audit demands proof of compliance on a timeline that doesn’t fit a normal procurement cycle.
Sources
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
