France has become one of the first countries in Europe to link security certification directly to Post-Quantum Cryptography (PQC). The decision says as much about procurement, sovereignty and industrial policy as it does about quantum computing.

For years, Post-Quantum Cryptography (PQC) has been discussed as a future challenge. Governments, standards bodies and technology vendors have warned that sufficiently powerful quantum computers could eventually undermine many of the public-key cryptographic systems that secure today’s digital infrastructure. The debate has largely centred on timelines, migration strategies and technical readiness.

France has now shifted that conversation.

The Agence nationale de la sécurité des systèmes d’information (ANSSI), France’s national cybersecurity agency, has announced that products seeking certain forms of security certification will increasingly be expected to incorporate quantum-resistant cryptography, with new certification requirements beginning to take effect from 2027. While the announcement may appear procedural, its implications extend well beyond cryptography. France is signalling that the quantum transition is becoming a procurement and certification issue rather than simply a research or technology issue.

This Is Not About Quantum Computers

At first glance, the decision may appear premature. Large-scale quantum computers capable of breaking widely deployed cryptographic algorithms do not yet exist. The immediate threat remains largely theoretical.

The challenge, however, is not defined by the capabilities of today’s quantum systems but by the lifespan of the systems being deployed today. Critical infrastructure, industrial control systems, identity platforms, payment systems and government services often remain operational for a decade or more. Decisions made now will determine whether those systems remain secure throughout their operational life.

This long-term perspective has become increasingly important as concerns grow around “harvest now, decrypt later” strategies, where encrypted data is collected today with the expectation that future quantum capabilities may eventually render it readable. The question facing governments is no longer when quantum computers become powerful enough to pose a threat. The question is whether the infrastructure being deployed today will still be trusted when that moment arrives.

France’s answer is increasingly clear.

Certification Becomes Policy

The most significant aspect of the announcement is not the technology itself. It is the mechanism through which the policy is being implemented. ANSSI is not banning products that rely on conventional cryptography. Instead, it is altering the certification framework through which security products are evaluated and approved and that distinction matters.

Certification influences procurement decisions. Procurement decisions influence investment priorities. Investment priorities shape product roadmaps. A change to certification criteria can therefore influence an entire market without introducing a direct legal prohibition.

For vendors seeking to serve government agencies, operators of critical infrastructure or highly regulated sectors, certification often represents the gateway to commercial opportunity. When certification requirements evolve, the market inevitably follows.

This is why the announcement should be viewed as more than a technical update. France is using certification as a policy instrument to accelerate the adoption of PQC across strategically important sectors.

Cryptography as Strategic Infrastructure

The decision also reflects a broader shift in how governments are approaching digital trust.

For decades, cryptography was often viewed as a specialised technical discipline managed largely by security teams and standards bodies. Increasingly, governments are treating it as a component of national infrastructure.

The transition to PQC intersects with questions of technological sovereignty, supply-chain resilience, industrial competitiveness and national security. Decisions about cryptographic standards now influence procurement frameworks, technology investment strategies and long-term digital resilience.

As ANSSI Deputy Director General Samih Souissi observed, the transition is not solely a technical challenge. It is equally a question of governance, industrial planning, regulation and sovereignty.

That perspective is becoming increasingly common across Europe. Whether the discussion centres on cybersecurity, artificial intelligence, digital identity or quantum technologies, governments are demonstrating a growing willingness to shape markets through standards, certification and regulatory frameworks.

The objective is not merely to encourage adoption. It is to create the conditions under which adoption becomes inevitable.

The Clock Has Started

France’s announcement does not emerge in isolation. The National Institute of Standards and Technology (NIST) has already standardised the first generation of PQC algorithms. National cybersecurity agencies across Europe have published migration guidance. Governments are developing transition roadmaps and beginning to assess the long-term resilience of critical systems.

What France has done is attach practical consequences to those discussions. For years, PQC has been framed as a future technology problem. France has reframed it as a present procurement decision.

The significance of this week’s announcement is not that a deadline exists. It is that one of Europe’s largest economies has started the clock.

As the transition from conventional cryptography to PQC gathers pace, certification frameworks may prove to be just as influential as technological breakthroughs. Organisations that view PQC as a distant issue may find themselves overtaken not by quantum computers, but by procurement requirements, certification expectations and market realities that arrive far sooner.

TQS Insight

The story here is not quantum computing. The story is enforcement. France is demonstrating how governments can accelerate technological transitions through certification, procurement and policy. In doing so, it offers a glimpse of a broader trend that is becoming increasingly visible across Europe. Trust is moving from guidance to obligation.


Discover more from The Quantum Space

Subscribe to get the latest posts sent to your email.

2 responses to “France Draws a Line: No Quantum-Safe Encryption, No Certification”

  1. […] France Draws a Line: No Quantum-Safe Encryption, No Certification […]

  2. […] France Draws a Line: No Quantum-Safe Encryption, No Certification […]

Leave a Reply

Trending

Discover more from The Quantum Space

Subscribe now to keep reading and get access to the full archive.

Continue reading

Discover more from The Quantum Space

Subscribe now to keep reading and get access to the full archive.

Continue reading