Certified Is Not Deployed: France's 2027 PQC Gate

June 16, 2026

EN | DE

France is the first country in Europe to put a real penalty on classical-only cryptography. Starting in 2027, ANSSI, the French cybersecurity agency, will stop certifying security products that lack quantum-resistant encryption. Certification is required to sell into French government and critical infrastructure. By 2030, businesses are expected to buy only quantum-safe products. This is real pressure on vendors. It only measures the product, though. Whether a deployed server negotiates post-quantum key exchange is a separate question, and today almost none do.

The Gate

ANSSI certification is the ticket into one of the largest government technology markets in Europe. A product without PQC after 2027 loses that ticket. Samih Souissi, ANSSI's chief of staff, called the decision "a matter of governance, industrial planning, regulation, and sovereignty."

Some coverage says France is forcing operators off older systems. The mechanism is smaller than that. The gate applies to new certifications and new purchases. Systems already deployed keep running. The pressure arrives when equipment gets replaced, which is where every crypto migration happens anyway.

The date was also announced years ago. ANSSI's 2022 position paper described a three-phase transition with hybrid PQC required through the first two phases. The 2023 follow-up moved the schedule up and said the first certifications of hybrid PQC products would come around 2024 to 2025. A 2027 cutoff for classical-only products is that plan arriving on time.

Certification Tests the Product

A certification says the product, as tested, contains quantum-resistant encryption. It says nothing about what your copy of that product negotiates on port 443 tonight. Our Q1 scorecard compared PQC announcements from 28 vendors with their actual TLS handshakes. The announcements and the handshakes often disagree. A government stamp on the announcement changes nothing on the wire.

This is the false floor with a legal layer added. Edge providers report PQC adoption above 50 percent. Origin servers sit near 1 percent. More than 90 percent of origin servers negotiate zero post-quantum key exchange today. France can run the strictest certification program in Europe and that number only moves when operators deploy, configure, and check. [PQ]probe grades the key exchange each server actually negotiates, per probe, per scan. That is the layer certification cannot see.

Hybrid, With Room to Diverge

ANSSI requires hybrid PQC, meaning a post-quantum algorithm combined with a classical one, and this includes signatures. ANSSI says in writing that this matches BSI's position in Germany. That puts France opposite CNSA 2.0's pure-PQC track and the new Geomys/OpenSSH position in the signature split.

ANSSI also keeps options open beyond NIST. The follow-up paper's annex lists FrodoKEM, a conservative algorithm NIST did not select. China is finishing its own standards on different math by 2029. The tracks keep multiplying. A server tuned to pass ANSSI can grade differently against a CNSA 2.0 profile, and both grades are correct. Every new national gate adds one more profile to score against.

A Fourth Clock

CNSA 2.0 wants key exchange done by 2030 and signatures by 2035. EO 14412 wants civilian key exchange by the end of 2030 and signatures a year later for high-impact systems. BSI says classical encryption should no longer be used alone after 2031. The EU roadmap wants high-risk systems migrated by 2030 and everything by 2035. ANSSI's 2027 cutoff runs ahead of all of them, and its 2030 buying guidance matches the rest. The full list is on [PQ]time.

Souissi gave harvest-now-decrypt-later as the reason: attackers record encrypted traffic today and decrypt it when quantum computers can. That threat is why key exchange comes first in every serious migration plan. These deadlines run on purchasing and certification cycles, with or without a working quantum computer. The hardware debate does not change any of them.

France put a date on the gate. The wire shows who got through, and the wire is already reporting.


Sources:


Scan your endpoints with [PQ]probe to see which side of the gate your deployments stand on.