Zero Day Room
Live
Incidents

G7 Calls for Accelerated Quantum-Safe Encryption Transition

The G7, chaired by France’s ANSSI during its 2026 presidency, issued a September 3 call urging governments and businesses to prioritize post-quantum

The G7, chaired by France’s ANSSI during its 2026 presidency, issued a September 3 call urging governments and businesses...

The G7, led by France’s National Cybersecurity Agency (ANSSI) under the 2026 G7 presidency, issued a September 3 call urging governments and enterprises to fast-track quantum-safe encryption adoption. The appeal frames quantum computing as a near-term risk and sets out a phased post-quantum cryptography (PQC) migration plan.

Background and Threat Outlook

The G7 document recharacterises the quantum threat from a distant concern to an imminent challenge that affects all sectors, not only critical infrastructure. It notes that while the exact arrival of quantum computers capable of breaking current public-key algorithms is uncertain, recent advances suggest the danger is closing in. "We recognize the growing threat that quantum computing poses to public-key cryptography," the paper states.

Recommended Transition Strategy

The guidance advises organisations to start by inventorying cryptographic assets, mapping dependencies, and identifying systems that store the most sensitive data. A risk-based, phased approach is recommended, with priority given to high-value assets. To curb costs, the paper suggests purchasing solutions that already embed PQC and aligning replacements with regular renewal cycles. "Starting the transition early could result in lower migration costs " the text adds.

Priorities for Governments and Industry

Five priority areas are outlined for policymakers and the private sector:

  • Raising awareness of quantum risks.
  • Crafting national PQC transition strategies and ensuring a sufficient supply of PQC hardware and software.
  • Boosting research and development to produce practical quantum-safe solutions.
  • Forming public-private partnerships that involve government, industry, and academia to build domestic expertise.
  • Embedding PQC requirements into cybersecurity standards.

All seven G7 national cybersecurity agencies-Canada, France, Germany, Italy, Japan, the United Kingdom and the United States-signed the call, with support from the EU Commission and ENISA.

Timeline and Procurement Milestones

The document aligns with recent French policy moves. ANSSI announced it will cease vetting products lacking quantum-safe encryption starting in 2027, and it aims to make PQC a mandatory feature in certain security procurements by 2030. The timeline can be summarised as follows:

YearMilestone
2026France chairs G7, issues quantum-safe call
2027ANSSI stops vetting non-PQC products
2030PQC becomes mandatory for selected security purchases

The call to action shows that early adoption not only mitigates future risk but also spreads migration costs over normal upgrade cycles. The G7 hopes the coordinated push will accelerate the development and deployment of quantum-resistant technologies worldwide.

Related coverage

More from Incidents