France plans to change how it certifies cybersecurity products by requiring quantum-resistant encryption for government use. Multiple outlets report that the French cybersecurity agency will stop certifying security products that do not include quantum-resistant encryption starting in 2027. The policy is described as a phase-out of non-quantum encryption standards for certified products used in the public sector.
The transition is expected to take several years. Sources indicate that full adoption is targeted for 2030, implying a staged rollout rather than an immediate nationwide switch. The move is framed as part of broader planning for future cryptographic threats, including the risk that emerging quantum technologies could weaken commonly used encryption methods over time.
While the sources differ slightly in emphasis, they agree on the core timeline: certification requirements will shift in 2027, and the broader transition toward quantum-resistant encryption is intended to be completed by 2030. The reporting centers on government certification and researchers’ certification practices rather than on a direct ban on all non-quantum encryption globally.