Bỏ qua đến nội dung chính
Back to home
Tech 3 min read

France to Mandate Post-Quantum Cryptography for Security Certifications by 2027

The French National Cybersecurity Agency (ANSSI) will stop certifying security products that lack post-quantum cryptography (PQC) starting in 2027.

Tier 2 · sources 51% confidence Reviewed
Sources postquantum.com

The French National Cybersecurity Agency (ANSSI) recently announced a roadmap to tighten its security certification process, officially halting the certification of products that do not integrate post-quantum cryptography (PQC) starting in 2027. This decision marks a decisive step by the French government to prepare for the quantum computing era, where traditional cryptographic algorithms run the risk of being completely broken. This move also sets a new benchmark for hardware and software security developers looking to enter the European market.

Key Developments

According to ANSSI, the transition roadmap to post-quantum cryptography was planned well in advance to mitigate risks from 'Store Now, Decrypt Later' (SNDL) attacks. Starting in 2027, any cybersecurity product applying for security certification in France that does not support standardized PQC algorithms will be rejected outright. This new regulation forces tech companies to rapidly upgrade their systems and integrate new security methods into their product roadmaps starting now to meet the deadline. This transition is expected to trigger a massive wave of security infrastructure upgrades across the region.

Technical & Technological Analysis

From a technological standpoint, post-quantum cryptography (PQC) focuses on developing complex mathematical algorithms that even the most powerful future quantum computers will not be able to solve in real-time. Current encryption methods like RSA or ECC rely on the difficulty of integer factorization or discrete logarithm algorithms—problems that are highly vulnerable to Shor's algorithm on a quantum computer. To replace them, ANSSI encourages the adoption of lattice-based cryptography, such as Kyber (ML-KEM) or Dilithium (ML-DSA), which have been standardized by NIST. During the transition phase, a hybrid approach combining traditional and post-quantum algorithms is considered the optimal solution to ensure backward compatibility and prevent risks arising from bugs in new software.

Expert Opinions & Insights

Cybersecurity experts view ANSSI's move as highly necessary and pioneering in Europe. Enforcing a hard deadline in 2027 will compel the market to take action rather than continuously delaying this complex and costly transition. However, some analysts have expressed concerns regarding the capability of small and medium-sized enterprises (SMEs) to comply, as PQC integration requires significant technical resources and high auditing costs. Nonetheless, the general consensus remains that migrating to PQC is no longer an option but a mandatory requirement to safeguard national and corporate data against global strategic threats.

Impact & Outlook

France's new regulations are bound to trigger a domino effect, prompting other countries in the European Union (EU) and worldwide to swiftly enact similar mandatory standards. For Vietnamese tech companies aiming to export software or hardware security products to the European market, this is a crucial wake-up call that demands proactive and serious preparation. Delaying the adoption of PQC technology will not only cost these enterprises their competitive edge but also run the risk of completely shutting them out of global tech supply chains in the near future.