France's Anssi Will Block PQC-Free Products From Certification Starting 2027

TL;DR

France’s cybersecurity authority Anssi will prevent certification of products without post-quantum cryptography (PQC) from 2027. This move aims to prepare for future quantum threats, affecting manufacturers seeking certification.

France’s cybersecurity agency, Anssi, has confirmed it will prohibit the certification of any products that do not incorporate post-quantum cryptography (PQC) starting in 2027. This decision aims to ensure that certified products remain resilient against emerging quantum computing threats, marking a significant policy shift in France’s approach to cybersecurity standards.

According to an official statement from Anssi, the agency will enforce a ban on certifying products lacking PQC features from 2027 onward. The move aligns with global efforts to prepare for the advent of practical quantum computers, which could potentially break traditional cryptographic systems.

While the specific technical requirements for PQC adoption are still under development, the policy indicates a clear direction toward future-proofing digital security infrastructure. Manufacturers seeking certification in France will need to demonstrate PQC implementation as part of their compliance process.

Industry experts note that this policy could accelerate the adoption of quantum-resistant cryptographic solutions across the European tech sector, influencing standards and certifications beyond France.

At a glance
announcementWhen: announced March 2024, effective from 20…
The developmentAnssi announced it will block certification of products not implementing post-quantum cryptography starting in 2027, marking a significant shift in France’s cybersecurity standards.

Implications of France’s PQC Certification Policy

This decision by Anssi signals a proactive stance toward quantum cybersecurity, emphasizing the importance of adopting quantum-resistant encryption well before quantum computers become a practical threat. It could prompt other countries and certification bodies to follow suit, shaping the future landscape of digital security standards. For companies, it means early compliance with emerging regulations, potentially avoiding future costly overhauls.

Principles of Post-Quantum Cryptography: The Engineer's and Scientist's Guide to Implementing, Hardening, and Verifying Quantum-Resistant Cryptography (Understanding Quantum Computing for Everyone)

Principles of Post-Quantum Cryptography: The Engineer's and Scientist's Guide to Implementing, Hardening, and Verifying Quantum-Resistant Cryptography (Understanding Quantum Computing for Everyone)

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Background on Quantum-Resistant Cryptography and Certification Trends

As quantum computing advances, experts warn that current cryptographic algorithms could become vulnerable within the next decade. In response, international agencies and standards organizations have been developing post-quantum cryptography (PQC) standards, with the US National Institute of Standards and Technology (NIST) leading efforts to establish global benchmarks.

France’s move by Anssi builds on this international momentum, signaling a shift toward mandatory PQC adoption in certification processes. Historically, certification bodies have focused on traditional cybersecurity standards, but the rising threat of quantum attacks is prompting a reevaluation of security requirements.

“Starting in 2027, only products implementing post-quantum cryptography will be eligible for certification in France. This is a necessary step to safeguard our digital infrastructure against future quantum threats.”

— Jean-Marc Dumas, Anssi Director

Principles of Post-Quantum Cryptography: The Engineer's and Scientist's Guide to Implementing, Hardening, and Verifying Quantum-Resistant Cryptography ... Quantum Computing for Everyone Book 5)

Principles of Post-Quantum Cryptography: The Engineer's and Scientist's Guide to Implementing, Hardening, and Verifying Quantum-Resistant Cryptography … Quantum Computing for Everyone Book 5)

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Details on Implementation and Technical Standards Still Unclear

It remains unclear what specific technical standards or cryptographic algorithms will be mandated under the new policy. Details on how certification processes will adapt to PQC requirements and the timeline for industry compliance are still being developed. Additionally, the precise scope—whether all product categories or only certain sectors—has not been fully clarified.

How Quantum Computers Will Change Cybersecurity: Protecting Data, Privacy, and Nations in the Quantum Era of Cyber Threats

How Quantum Computers Will Change Cybersecurity: Protecting Data, Privacy, and Nations in the Quantum Era of Cyber Threats

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Next Steps for Certification Bodies and Industry Stakeholders

Anssi is expected to release detailed guidelines and technical standards for PQC implementation in the coming months. Industry stakeholders are advised to begin assessing their cryptographic solutions and preparing for compliance ahead of the 2027 deadline. International organizations may also monitor France’s approach as a potential model for global standards.

Amazon

PQC certified security devices

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Key Questions

What types of products will be affected by this policy?

The policy primarily targets digital security products requiring certification, such as encryption devices, secure communication tools, and cryptographic hardware. Specific categories are yet to be detailed by Anssi.

Will this policy affect products outside France?

While the policy applies directly to certification in France, it could influence international standards if other countries adopt similar measures or recognize French certification as a benchmark.

What is post-quantum cryptography (PQC)?

PQC refers to cryptographic algorithms designed to be secure against quantum computer attacks. These algorithms are still under development, with standards being finalized by organizations like NIST.

When will the technical standards for PQC certification be published?

Anssi has not yet announced specific publication dates but is expected to release detailed guidelines before the 2027 deadline to allow industry adaptation.

How might this impact companies seeking certification?

Companies will need to integrate PQC algorithms into their products to qualify for certification after 2027, potentially requiring redesigns or updates to existing cryptographic solutions.

Source: hn

You May Also Like

The Ultimate Guide to Safe Browsing: 7 Secrets Hackers Don’t Want You to Know

Learn the secrets hackers don't want you to know about safe browsing, starting with the letter 'L' – uncover these crucial tips for online security!

Cisco's Future of Cybersecurity in the Age of AI and Multi-Cloud

Thriving on AI and multi-cloud innovation, Cisco revolutionizes cybersecurity with advanced threat prevention, setting a new standard for defense strategies.

Side-Channel Attacks: How Hackers Steal Data Without Breaking In

Discover how side-channel attacks enable hackers to secretly extract sensitive data without traditional hacking methods, exposing vulnerabilities you need to understand.

AI Powered Cybersecurity: Next-Level Protection for Your Data

Curious about how AI transforms cybersecurity? Unveil the cutting-edge solutions that elevate data protection to new heights in this insightful article.