France’s ANSSI makes PQC a certification gate, so legacy encryption now has an expiry date instead of a roadmap.
4 comments
If ANSSI stops certifying anything without quantum-resistant encryption in 2027, does that mean the old certs stay valid until they expire, or do agencies have to rip out already-approved gear and swap it sooner?
Old certs usually don’t get vaporized on day one, so I’d expect a grandfathering window, but anything that needs renewal, re-cert, or new procurement gets pushed into the PQC box fast.
The real bite is that ANSSI is a gate for government and critical infra, so even if the boxes keep running, the upgrade path stops being optional pretty quickly.
This forces crypto agility, since certs lag deployments while Shor quietly kills RSA and ECC.
So the deadline is now procurement, not the math. Bureaucracy finally gets to set the cryptographic deprecation schedule (which is honestly on brand).