France will stop certifying any security product without post-quantum cryptography starting in 2027. This is not a recommendation. It is a binding mandate. Vendors have 18 months to re-engineer their cryptographic cores or lose access to one of Europe's largest cybersecurity markets. The post-quantum transition just stopped being a research problem and became a supply chain compliance deadline.

18 months to zero
The policy was announced by Samih Souissi, ANSSI's chief of staff, at the France Quantum conference. The language left no room for interpretation. Starting in 2027, the agency will halt certification of any security product that lacks quantum-resistant encryption. Souissi added a second deadline: businesses should purchase only quantum-safe products by 2030.

The mechanism is simple. ANSSI certification is a de facto requirement for any product sold to French government agencies and critical infrastructure operators, according to Bruce Schneier's security blog. Without it, a vendor's product is frozen out of the public sector, defense, energy, and telecommunications contracts that form the backbone of the French market.
The policy is driven by a specific threat: harvest now, decrypt later. Adversaries are already storing encrypted traffic, waiting for quantum computers capable of cracking today's public-key algorithms. IBM executive Jerry Chow told the same conference that the quantum threat to current cryptography could materialize by the mid-2030s. ANSSI is not waiting to find out.
The agency has already proven the certification mechanism works. In October 2025, it issued the first two French security certifications for products incorporating post-quantum cryptography based on Euclidean lattice algorithms. The certified products were Thales' Smartcard MultiApp 5.2 Premium PQC, certified on September 29, and Samsung's S3SSE2A microcontroller, certified on October 1, according to ANSSI's own announcement. The evaluation infrastructure exists. The template is set. Now the clock is running for everyone else.
The industrial mandate takes shape
The 2027 deadline was not a surprise to anyone watching ANSSI's trajectory. France launched its national quantum strategy in 2021 with 1.8 billion euros in public and private funding, including more than 1 billion euros in direct government investment. ANSSI published a position paper in 2023 predicting that the first French security visas for products implementing hybrid post-quantum cryptography would arrive around 2024-2025. In March 2025, the agency updated its cryptographic approval doctrine to formally support PQC and began training its network of security evaluation labs, known as CESTIs, on the new standards.
What changed in 2026 is the binding date. The theoretical migration path became a hard regulatory cliff. Every hardware security module vendor, every smart card manufacturer, every cryptographic library maintainer that wants to sell into the French government market must now allocate R&D budget, renegotiate product roadmaps, and secure one of the limited evaluation slots at a CESTI lab — private-sector facilities accredited by ANSSI to perform Common Criteria evaluations — within a compressed timeline.
Souissi framed the decision in terms that go well beyond technical cybersecurity. "It's not only a technical issue," he said. "It's a matter of governance, industrial planning, regulation, and sovereignty," as reported by Post-Quantum.com. The word sovereignty is the signal. France is not outsourcing its cryptographic transition timeline to NIST or to Brussels. It is setting its own clock, and that clock is faster than anyone else's.
The bottleneck is not the crypto
The cryptography itself is not the hard part. NIST has standardized post-quantum algorithms. Hybrid implementations that pair classical and post-quantum algorithms in parallel are well understood. The bottleneck is the evaluation infrastructure.
ANSSI's certification process requires Common Criteria evaluation, a resource-intensive, months-long procedure performed by accredited CESTI labs. There are a finite number of these labs, and they are now being asked to evaluate an entirely new class of cryptographic algorithms across every product category simultaneously. Vendors who wait until late 2026 to submit their products for evaluation will find themselves in a queue that extends past the deadline.
Fanny Bouton, head of quantum at OVHcloud, described the dual pressure. "We face two challenges: auditing our products and securing all the data we hold in order to meet ANSSI's requirements," she told Post-Quantum.com. The auditing challenge alone is significant for large cloud operators with sprawling product portfolios. Every cryptographic module, every key management system, every TLS termination point must be inventoried, assessed, and migrated or replaced.
The compliance landscape is also fragmenting. ANSSI's requirements do not map cleanly onto the European Commission's Cyber Resilience Act or NIS2 directive, and neither aligns perfectly with NIST's U.S. standards. A vendor that achieves ANSSI certification does not automatically satisfy other regulatory regimes. The result is a compounding compliance burden that hits smaller vendors hardest. They lack the regulatory affairs teams and the capital to pursue multiple certifications simultaneously.
Why three countries will follow by mid-2028
The most important consequence of France's move is not what happens in France. It is what happens next in Berlin, The Hague, and Stockholm.
France has just created a regulatory template. The logic that drove ANSSI's decision — the harvest-now-decrypt-later threat, the sovereignty argument, the industrial policy dimension — applies identically to every EU member state with a serious cybersecurity agency. Germany's BSI, the Netherlands' NCSC, and Sweden's MSB all face the same threat model and the same political pressure to protect their government networks. None of them wants to be the weak link that adversaries target for encrypted data harvesting.
The mechanism is competitive regulatory pressure, accelerated by procurement interdependence. Once one major EU state sets a certification deadline, the others face a choice: announce their own deadline or accept that their government networks will be perceived as softer targets. But there is a second force at work. Thales and Samsung now have ANSSI-certified post-quantum products on the market. Those products become the reference point for German and Dutch procurement officers evaluating their own options. The market does not wait for every regulator to act — it converges on the available certified products, and the regulators follow to avoid being seen as obstructionist. No national cybersecurity director wants to explain to a parliamentary committee why France acted and they did not.
By mid-2028, at least three major EU countries will announce similar certification deadlines. The timelines will not be harmonized. Each country will set its own date, its own approved algorithm list, and its own evaluation requirements. The result will be a fragmented but accelerating regulatory patchwork that forces global hardware security module and smart card vendors to prioritize European compliance over other markets.
The consequences will cascade. Small vendors without the R&D capacity to re-engineer their cryptographic cores and fund a Common Criteria evaluation will exit the French market by 2027. Large vendors will then reallocate engineering resources from North American and Asian product lines to meet European deadlines, creating supply constraints in other regions. The structural outcome: the EU becomes the de facto global standard-setter for post-quantum certification, not because its standards are technically superior to NIST's, but because its regulatory deadlines are binding and earlier. Markets follow the clock.
Pascal Brier, chief innovation officer at Capgemini, told Global Banking and Finance that the market is "becoming big. It's going to be very substantial." He is understating the case. The market is about to become mandatory, and mandatory markets do not grow linearly. They flip.
What operators must do now
For CISOs, procurement officers, and product managers, the 2027 deadline eliminates the luxury of waiting for standards to stabilize.
Audit your current cryptographic inventory. Identify every product, module, and library that relies on classical public-key algorithms and map it against your French government and critical infrastructure contracts. If a product touches a French government network, it is in scope. Engage with ANSSI-accredited CESTI labs immediately — evaluation slots are a finite resource, and the queue will lengthen as the deadline approaches. A vendor that secures a slot in early 2026 will have time for remediation. A vendor that calls in December 2026 will not.
Plan for hybrid migration. ANSSI's approved approach pairs classical and post-quantum algorithms in parallel, maintaining backward compatibility while adding quantum resistance. This is the only path that preserves both security and interoperability during the transition. And budget accordingly: a Common Criteria evaluation for a complex product can exceed 500,000 euros, and that does not include the engineering cost of re-implementing cryptographic modules. This is a capital expenditure that belongs in the current fiscal year's budget, not next year's.
The clock is not a metaphor
The 2027 deadline is not a future event. It is the present constraint on every product decision made today. A hardware revision cycle takes 12 to 18 months. A Common Criteria evaluation takes months. The math is brutal: a vendor that starts now might make it. A vendor that delays will not.
France has turned post-quantum cryptography from a research agenda into a supply chain compliance deadline. The regulatory wave will not stop at its borders. Vendors who treat this as a French anomaly will discover otherwise when Berlin and The Hague follow suit. The quantum-safe transition is no longer a question of when the technology matures. It is a question of whether your product portfolio clears the certification cliff.