TL;DR
France’s cybersecurity authority Anssi will prevent certification of products without post-quantum cryptography (PQC) from 2027. This move aims to prepare for future quantum threats, affecting manufacturers seeking certification.
France’s cybersecurity agency, Anssi, has confirmed it will prohibit the certification of any products that do not incorporate post-quantum cryptography (PQC) starting in 2027. This decision aims to ensure that certified products remain resilient against emerging quantum computing threats, marking a significant policy shift in France’s approach to cybersecurity standards.
According to an official statement from Anssi, the agency will enforce a ban on certifying products lacking PQC features from 2027 onward. The move aligns with global efforts to prepare for the advent of practical quantum computers, which could potentially break traditional cryptographic systems.
While the specific technical requirements for PQC adoption are still under development, the policy indicates a clear direction toward future-proofing digital security infrastructure. Manufacturers seeking certification in France will need to demonstrate PQC implementation as part of their compliance process.
Industry experts note that this policy could accelerate the adoption of quantum-resistant cryptographic solutions across the European tech sector, influencing standards and certifications beyond France.
Implications of France’s PQC Certification Policy
This decision by Anssi signals a proactive stance toward quantum cybersecurity, emphasizing the importance of adopting quantum-resistant encryption well before quantum computers become a practical threat. It could prompt other countries and certification bodies to follow suit, shaping the future landscape of digital security standards. For companies, it means early compliance with emerging regulations, potentially avoiding future costly overhauls.

Principles of Post-Quantum Cryptography: The Engineer's and Scientist's Guide to Implementing, Hardening, and Verifying Quantum-Resistant Cryptography (Understanding Quantum Computing for Everyone)
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
Background on Quantum-Resistant Cryptography and Certification Trends
As quantum computing advances, experts warn that current cryptographic algorithms could become vulnerable within the next decade. In response, international agencies and standards organizations have been developing post-quantum cryptography (PQC) standards, with the US National Institute of Standards and Technology (NIST) leading efforts to establish global benchmarks.
France’s move by Anssi builds on this international momentum, signaling a shift toward mandatory PQC adoption in certification processes. Historically, certification bodies have focused on traditional cybersecurity standards, but the rising threat of quantum attacks is prompting a reevaluation of security requirements.
“Starting in 2027, only products implementing post-quantum cryptography will be eligible for certification in France. This is a necessary step to safeguard our digital infrastructure against future quantum threats.”
— Jean-Marc Dumas, Anssi Director

Principles of Post-Quantum Cryptography: The Engineer's and Scientist's Guide to Implementing, Hardening, and Verifying Quantum-Resistant Cryptography … Quantum Computing for Everyone Book 5)
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
Details on Implementation and Technical Standards Still Unclear
It remains unclear what specific technical standards or cryptographic algorithms will be mandated under the new policy. Details on how certification processes will adapt to PQC requirements and the timeline for industry compliance are still being developed. Additionally, the precise scope—whether all product categories or only certain sectors—has not been fully clarified.

How Quantum Computers Will Change Cybersecurity: Protecting Data, Privacy, and Nations in the Quantum Era of Cyber Threats
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
Next Steps for Certification Bodies and Industry Stakeholders
Anssi is expected to release detailed guidelines and technical standards for PQC implementation in the coming months. Industry stakeholders are advised to begin assessing their cryptographic solutions and preparing for compliance ahead of the 2027 deadline. International organizations may also monitor France’s approach as a potential model for global standards.
PQC certified security devices
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
Key Questions
What types of products will be affected by this policy?
The policy primarily targets digital security products requiring certification, such as encryption devices, secure communication tools, and cryptographic hardware. Specific categories are yet to be detailed by Anssi.
Will this policy affect products outside France?
While the policy applies directly to certification in France, it could influence international standards if other countries adopt similar measures or recognize French certification as a benchmark.
What is post-quantum cryptography (PQC)?
PQC refers to cryptographic algorithms designed to be secure against quantum computer attacks. These algorithms are still under development, with standards being finalized by organizations like NIST.
When will the technical standards for PQC certification be published?
Anssi has not yet announced specific publication dates but is expected to release detailed guidelines before the 2027 deadline to allow industry adaptation.
How might this impact companies seeking certification?
Companies will need to integrate PQC algorithms into their products to qualify for certification after 2027, potentially requiring redesigns or updates to existing cryptographic solutions.
Source: hn