French cybersecurity agency ANSSI will stop certifying non-quantum-safe products from 2027, forcing government and critical infrastructure operators to migrate.
Summary
- ANSSI will cease certifying security products that lack quantum-resistant encryption from 2027.
- Businesses supplying French government or critical infrastructure should be offering only quantum-safe products by 2030.
- ANSSI certification is mandatory for use in French government agencies and critical infrastructure, making this a de facto phase-out of legacy encryption.
- The policy was announced by ANSSI chief of staff Samih Souissi at the France Quantum conference.
- No corroborating sources were available at time of publication; the briefing is based on a single primary source.
France has put a date on the end of classical encryption certification. The country’s national cybersecurity agency, ANSSI, announced this week that it will stop certifying security products that do not incorporate quantum-resistant encryption from 2027. By 2030, the expectation is that businesses should be procuring only quantum-safe products. The announcement was made at the France Quantum conference by ANSSI chief of staff Samih Souissi.
Why This Is More Than a Policy Signal
ANSSI certification is not optional for organisations operating within French government or critical infrastructure. It is a regulatory requirement. That distinction matters enormously: this is not an aspirational roadmap or an industry recommendation. When ANSSI withdraws certification from a product category, those products become ineligible for use in regulated environments. The practical effect is a mandated transition, not a voluntary one.
The Timelines in Plain Terms
Two dates carry weight here. The first is 2027, when ANSSI will stop issuing new certifications to products that lack quantum-safe cryptography. Any vendor seeking certification after that point must have post-quantum capabilities built in. The second is 2030, by which point Souissi indicated that businesses should be buying only quantum-safe products. That second date is framed as an expectation rather than a hard regulatory cutoff, but given the procurement cycles involved in government and critical infrastructure, the practical window is already narrower than it appears.
Procurement Cycles Are the Hidden Constraint
Security product procurement in regulated environments rarely moves quickly. Government agencies and critical operators typically run multi-year contract cycles, conduct lengthy evaluation and accreditation processes, and require extended deployment and testing periods before products go live. A 2027 certification cutoff, viewed through that lens, means procurement decisions being made today and over the next twelve to eighteen months need to account for post-quantum requirements. Organisations that wait until 2026 to begin assessing their options will find themselves under real pressure.
Context: Where This Fits in the Broader Shift
France is not moving in isolation. The United States National Institute of Standards and Technology finalised its first post-quantum cryptography standards in 2024, and other national bodies have been advising organisations to begin planning transitions. What distinguishes France’s approach is the use of a certification mechanism as the enforcement lever — a concrete, regulatory consequence for non-compliance rather than guidance alone. Whether other nations’ cybersecurity agencies follow with similar hard deadlines remains to be seen; no corroborating sources were available at time of publication.
What This Means for Vendors
For security vendors selling into the French government and critical infrastructure market, the message is straightforward: post-quantum capabilities are now a prerequisite for continued market access, not a differentiating feature. Vendors without a credible post-quantum roadmap risk losing certification eligibility and, with it, their position in a significant regulated market. Those already investing in post-quantum development gain a structural advantage.
Why it matters
For CISOs operating in or supplying to regulated French environments, this is a compliance deadline with teeth. ANSSI certification is a market-access requirement, not a badge of honour — losing it means losing eligibility. More broadly, this is an early signal of what regulatory pressure on post-quantum migration may look like in other jurisdictions. CISOs should treat France’s 2027 cutoff as a leading indicator and use it to pressure-test their own cryptographic inventories, vendor roadmaps, and procurement timelines now, regardless of whether their organisation has direct French exposure.
What to do now
- Review your current security product portfolio for any products that hold or are seeking ANSSI certification, and assess their post-quantum readiness.
- Engage existing and prospective security vendors to understand their post-quantum cryptography roadmaps and expected certification timelines ahead of 2027.
- Factor post-quantum requirements into upcoming procurement decisions for cryptographic and security products, particularly those with multi-year contract horizons.
- Begin a cryptographic inventory to identify where classical encryption is embedded in systems that serve or connect to French government or critical infrastructure environments.
- Monitor whether other national cybersecurity agencies introduce similar certification-based enforcement mechanisms, and adjust your migration planning accordingly.
