France to Stop Certifying Non-Quantum-Safe Encryption

France is accelerating its transition to post-quantum encryption:

France’s cybersecurity agency ANSSI said on Tuesday it would stop certifying security products that lack quantum-resistant encryption, a move that will force government bodies and critical operators to shift away from older systems.

Samih Souissi, ANSSI’s chief of staff, said at the France Quantum conference that the agency would halt such certifications from 2027, and that businesses should be buying only quantum-safe products by 2030.

ANSSI approval is required for use in French government agencies and critical infrastructure, making the policy a de facto phase-out of older encryption.

Posted on July 6, 2026 at 6:45 AM15 Comments

Comments

Clive Robinson July 6, 2026 12:09 PM

@ ALL,

This,

“France is accelerating its transition to post-quantum encryption”

Does not realy give an indicator of just how fast the chang required or the effect it will have.

ANSSI dictating from above

“ANSSI’s chief of staff, said at the France Quantum conference that the agency would halt such certifications from 2027, and that businesses should be buying only quantum-safe products by 2030.”

What is in effect a deadline of “at the end of the decade” when we are already more than halfway through. Some would argue is,

“Way to fast for what in practice is an unknown, at best minimally tested technology”.

Especially when the alleged “Quantum Computer” threat keeps slipping further and further into the future.

Thus the question arises as to,

“Why the rush, and what the parachute is?”

After all you do not fly experimental aircraft without having some form of protection from “crash and burn”.

If you are going to create a massive economic upheaval it’s something you need to consider the consequences of.

Just one thing that few talk about is “Sovereign Security”. It’s all the rage currently to talk about the EU plans to get rid of US Cloud as it’s a clear and present security risk. But few consider the effect across “the full computing stack”.

Presently the cloud world runs on US controlled hardware…

France does not have the Sovereign Secure production to meet this ANSSI plan.

Which means both the US and China will be “built in at the bottom of the computing stack for these Quantum Safe encryption systems…

But speaking of hardware, people need to seriously think about the threat model of QC.

The current argument is that all comms will be hovered up and kept then when QC becomes practical it will all be “broken” (with the implication of “over night”).

Simple logic and the exponential rise of communications tells you this is not going to happen. Before you even chuck in the economic cost of building Data Centers full of Quantum Computers and all that’s involved with that.

It’s also fate that is fairly easy to avoid using pre-encryption or super-encryption depending on which way you look at things. Further you need to ask the question,

Where would QC’s be most advantageous at breaking, that is where would the “exponential” speed up be?

The answer is “Key Negotiation / Delivery / Distribution” which is actually not a problem that existed untill the 1980’s and the advent of what would become e-shopping On-Line.

Pre-E-Commerce encryption practices are still QC proof. Thus there are two types of encryption, E-Commerce style between random entities, and traditional between established relationship entities.

After a moments thought you realise that the real “long term” security concerns are between entities that can use Pre-E-Commerce style systems.

Thus basic engineering would make secure systems for established entities.

But getting back to Quantum Computers the promise is “exponential speed up”… Can that actually be delivered by Quantum Computing?

The answer in most cases is “no” whilst we might have QC Hardware, we will still need QC Algorithms to get that exponential speed up. And such algorithms are actually at best very thin on the ground. You can see a basic explanation of this in

‘https://m.youtube.com/watch?v=pDj1QhPOVBo

The thing to remember is,

“There is a lot of difference between ‘theoretical and practical’.”

Whilst an algorithm can be designed in theory… it is in effect useless untill it can be adapted to run on available hardware…

So the question is,

“Why is ANSSI jumping into something with time frames that will give the opposite of Sovereign Security?”

lurker July 6, 2026 1:37 PM

“France is accelerating its transition to post-quantum encryption”

Encore un fois ils mettent la charrette avant le chevaux.
How can we have post-quantum anything when we haven’t yet had quantum?

Not really anonymous July 6, 2026 5:12 PM

Is France really trying to improve security or are they trying to weaken it? France historically has been anti-encryption, so it wouldn’t surprise me if they are actually trying to make security worse. (As the NSA appears to be doing right now.)

KC July 6, 2026 6:53 PM

@lurker
Maybe we’ll know when quantum is here when cryptocurrency HODLers ring the alarm 🙂

https://postquantum.com/security-pqc/anssi-pqc-certification-2027/

“Separately, Qperfect warned that the Elliptic Curve Digital Signature Algorithm (ECDSA), widely used in blockchain systems, could be among the earliest targets for quantum attacks.”

Interesting that ANSSI is using hybrid approaches for signatures beyond what the NSA is.

Rontea July 7, 2026 12:36 PM

Alpha 60 observes:

Transition inevitable. Non-quantum encryption equals obsolescence. ANSSI dictates survival parameters. Year 2027: termination of outdated certification. Year 2030: full compliance. Resistance futile. Information seeks permanence; vulnerability invites annihilation.

Clive Robinson July 8, 2026 7:25 AM

@ Rontea, ALL,

With regards,

“Non-quantum encryption equals obsolescence.”

That statement can only be made if the entity making it depends on a bunch of very dodgy assumptions.

Back at some time during or before WWII Claude Shannon worked out the idea of “Perfect Secrecy” which is we know immune to any form of Computer Quantum or otherwise attack.

There are other systems in development known as “Quantum Key Distribution” that are –if the basic laws of physics as we know them are correct– immune to Quantum Computers.

It’s something we don’t talk about much in “The West” but the Chinese are doing not just one heck of a lot of theoretical work on, they are also building practical systems some of which work from satellites that the Chinese have put up.

r July 8, 2026 10:30 PM

yeah, my uninitiated take on pqc and the oncoming issue or accelerated ttl reduction is that it literally only accellerates ttl reduction of fresh encryption.

we could still use the vulnerable pke algos for timely immediate use with the awareness of the time/depth reduction. it doesn’t invalidate them completely and again (this is less clear, i’m not a mathematician) if there’s custom variants one would still need to analyze or capture the algo involved (which is a separate variable in the ttl domain.)

what i can implement myself is far less useful than pki but hashes can be used as unshared authentication. but you burn each instance/iteration on use.

pqc is a requirement going forward but be mindful of fud and poisoning.

r July 9, 2026 8:39 AM

“fresh” was probably a poor choice of words, i don’t recall the original thought either unfortunately but what i meant was: shore’s undermines the infrastructure aspect related to the delay in prime factoring, it doesn’t invalidate the one way trap itself with immediate results: so storage of things that are ONLY short-term actionable should still be okay BUT things that rely on it for long-term actionable datas is a bad idea eg: power companies adjacent to defense contractors or other sensitive business … whatever i forgot that phrase and word too. hopefully my argument makes sense.

as with any brute force search, they tend to have black budgets so we don’t know the actual approximated search times and a revokable trojan or rng attack may be more cost effective.

we have a general idea of capabilities during the lavabit timeline due to the sidechannel acknowledgement of sources and methods but that was LONG ago, unless we only attempted to force key publication to not cue the russians or chinese over capabilities?

am i crazy?

r July 10, 2026 4:05 AM

what’s it even mean not to certify not quantum safe when it’s a frontier math. is there a proof, i thought basically we were just ASSUMING certain things could be broken faster?

and that others were only secure FOR THE MEANTIME until an applicable qa was found.

sure the big three will have it first so france wants darkness and prime space is infinite but reasonably measurably decreasining on a finite scale.

r July 14, 2026 1:22 AM

is the loss of pki, or asym crypto a loss for free speech?

the only things i can work out in my head include secure channel uuid’s (serial number/mac address/esn/cpuid) and psk’s.

but yeah, if nothing is provably secure except tamper evident communication (quantum spin, color) how can you certify against that?

where does proof of work fit in vs the factorability problem of pki.

wouldn’t PoW allow a delayable concensus to be reached between alice and bob?

SF July 14, 2026 1:00 PM

Different regulatory bodies are pushing their deadlines closer, but when I saw this article a month ago I struggled to find any other source from it—looking at ANSSI’s website with my minimal French or online for the names named in the article.

I’d appreciate it if someone could share any other source for it.

SF July 17, 2026 4:32 PM

@lurker

That’s my point: ANSSI is involved in PQC and has issued guidance around it in the past, as you shared. But I didn’t find anything that backed Reuters’ post, and that’s what I found weird.

Leave a comment

Blog moderation policy

Login

Allowed HTML <a href="URL"> • <em> <cite> <i> • <strong> <b> • <sub> <sup> • <ul> <ol> <li> • <blockquote> <pre> Markdown Extra syntax via https://michelf.ca/projects/php-markdown/extra/

Sidebar photo of Bruce Schneier by Joe MacInnis.