Forgot your password?
typodupeerror
Encryption

France To Stop Certifying Products Without Quantum-Safe Encryption 35

Starting in 2027, France's cybersecurity agency ANSSI will stop certifying security products that lack quantum-resistant encryption, effectively forcing government agencies and critical infrastructure operators to phase out older cryptographic systems. Reuters reports: Samih Souissi, ANSSI's chief of staff, said at the France Quantum conference that the agency would halt such certifications from 2027, and that businesses should be buying only quantum-safe products by 2030. ANSSI approval is required for use in French government agencies and critical infrastructure, making the policy a de facto phase-out of older encryption.

"It's not only a technical issue," Souissi said. "It's a matter of governance, industrial planning, regulation, and sovereignty." The move reflects concern that attackers may store encrypted data now and unlock it later when quantum computers become strong enough to crack today's protections, a risk known as "harvest now, decrypt later."
This discussion has been archived. No new comments can be posted.

France To Stop Certifying Products Without Quantum-Safe Encryption

Comments Filter:
  • I had no idea what that might be, so I did some checking. I think that we can all agree that everyone should use:

    CRYSTALS-Kyber encryption
    and
    CRYSTALS-Dilithium

    Wireguard in shambles.

  • by jmccue ( 834797 ) on Tuesday June 16, 2026 @05:26PM (#66196200) Homepage

    I wonder if OpenSSH will be acceptable. Or does this certification only apply to commercial products ? AFAIK OpenSSH would be acceptable.

    https://www.openssh.org/pq.html

  • by CEC-P ( 10248912 ) on Tuesday June 16, 2026 @05:49PM (#66196252)
    They called it ANSSI? I'm sure that's not confused. Well off-brand, counterfeit, Temu ANSI here is right. If you're going to put in a product right now in 2026 with a useable life of even 5 years, it may legitimately be hackable by a quantum computer in that time. There's really no reason not to use the more modern, advanced methods. They don't even require special hardware.
    • Re:Really? (Score:5, Informative)

      by test321 ( 8891681 ) on Tuesday June 16, 2026 @06:13PM (#66196268)

      They called it ANSSI?

      1) It was actually DCSSI (Direction Centrale de Securite des Systemes d'information) as a branch of the Ministry of Defence until 2009 when it was elevated to the rank of an Agency.
      2) Agencies in France are prefixed with AN for Agence Nationale. For example in France ANSES (environment safery), ANSP (public health), ANR (Research), ANPE (employment agency), therefore renaming it AN + SSI.
      3) ANSI is unrelated (the French equivalent of ANSI is AFNOR) and therefore not ambiguous.

    • They called it ANSSI?

      There is a limited number of TLAs, and FLAs. And any TLA/FLA(as in four)/FLA(F as in Five) abbreviations will eventually get overloaded and reused. I don't care would ANSSI has abbreviated itself to, what I care about is what their authorities are.

  • 2030 is the post-quantum computing deadline. Every country should already be doing concrete actions. Every new hardware should be, at least, "PQC-minded". FIPS 203, FIPS 204, and FIPS 205 should be the basis of everything data-related going forward. Yet... who cares about "harvest now, decrypt later"? That's just woke stuff. Look: brand-new, shiny DDR6 is out! What a relief.
  • by dohzer ( 867770 )

    Weren't the French responsible for intentionally weakening GSM security during the 80s & 90s?

  • Which will happen first crypto relevant quantum computers or compromise of new post quantum crypto algorithms? I think the latter is more likely.

    • Agreed, in fact I think that's a major reason to avoid use of non-hybrid PQC.

      • by gweihir ( 88907 )

        Definitively. Always insist to get the security of a known-good classical algorithm in addition. Relying on something "quantum safe" alone is pure insanity at this time.

    • by gweihir ( 88907 )

      My bet would be that breaking something like RSA 2048 with a QC is not possible in this universe. It is too small and has not enough remaining lifetime.

  • What I have been seeing when talking to bunch of customers who are anxious about the quantum computers breaking ciphers is not so much encryption (as in transmission of data without eavesdropping learning the contents). If your credit card number leaks because you sent it over TLS session that someone captured and cracked with a quantum computer, that's an inconvenience to get a new card, but still minor.

    The big interest is in quantum-secure digital *signatures*. No, not the ones on website certificates. Bu

    • Fortunately, this is the easiest case since you don't have to rely on any new cryptographic primitives, SLH-DSA can do it relying only on hashes. It's very slow and produces large signatures, which for many applications is a problem, but not for single important transactions such as these.
  • It is not old enough and may still fail with catastrophic weaknesses. The way to go for new products is to use hybrid encryption, where a successful attack requires breaking both a quantum safe algorithm and a classical (good) one. Or, if you can, stay classical, since Quantum Computers are very, very, very, very far removed from being able to break any real encryption. In fact, after more than 50 years of research, these "machines" can factor 29 currently (well, one could and that was with moderate cheatin

    • Good points. I'm no expert in the field, but I've taken master's level courses in the relevant math and physics. I particularly remember my math professor saying that no encryption has been mathematically proven safe. We only know the current schemes are safe insofar as nobody has published an attack yet.

      We do know how to break certain classical encryption schemes with hypothetical quantum computers. This clearly doesn't mean other schemes will stay quantum-unbreakable forever, because people keep invent

      • by gweihir ( 88907 )

        In theory, your professor was right. In practice, not so much. The thing is theory requires perfect proofs. Practice only "good enough" ones. (We will ignore that the one-time-pad is mathematically proven secure, because it has little practical relevance...)

        So that state of things is that ElGamal has a security proof relying on an unproven assumption that is very likely true. RSA is much weaker on the theory side and current block ciphers or crypto-hashes are even weaker on the proof side.

        As to QC, the prob

"It's when they say 2 + 2 = 5 that I begin to argue." -- Eric Pepke

Working...