France’s reported decision to stop certifying security products that do not include quantum-safe encryption marks an important shift in cybersecurity policy. 

For years, post-quantum cryptography has been treated as a future problem. A risk to monitor. A migration to plan. A standards process to follow. 

That period is ending. 

The question is no longer whether organizations should prepare for quantum-safe encryption. It is whether products that cannot support it should continue to be trusted for sensitive environments at all. 

Certification is becoming a forcing function 

Certification matters because it turns abstract risk into operational reality. 

A regulator or national authority does not need to predict the exact date a Cryptographically Relevant Quantum Computer (CRQC) will arrive. It only needs to recognise that products deployed today may remain in service for many years, and that the data they protect may need to remain confidential for even longer. 

That is the real issue. 

Security products are often purchased on long refresh cycles. They sit deep inside networks, industrial systems, government environments and critical infrastructure. Replacing them quickly is difficult. Replacing them in a crisis is worse. 

This does not mean every existing product is suddenly insecure. But it does mean that products without a credible quantum-safe transition path are becoming harder to justify. 

The trust boundary is moving

The shift to quantum-safe encryption is often discussed as an algorithm change. 

That understates the challenge. 

The real question is one of trust and control. Who controls the cryptographic boundary? Who owns the keys? Who can demonstrate that algorithms can be changed without replacing the entire platform? 

For organizations operating sensitive networks, these are not theoretical questions. They go directly to sovereignty, auditability and operational resilience. 

Security teams should be asking: 

  1. Does this product support a practical path to post-quantum cryptography? 
  2. Can it operate in hybrid mode while standards, policies and interoperability mature? 
  3. Who controls the keys and the cryptographic policy? 
  4. Can the organization prove compliance to regulators, customers and national authorities? 
  5. Will the product still be certifiable over its expected service life? 

Procurement and finance teams should be asking: 

  1. What is the cost of re-platforming if a vendor’s encryption is deprecated or decertified? 
  2. Does the contract lock us into a single cryptographic approach, or does it allow for algorithm agility? 
  3. Are certification and recertification costs included, or do they sit outside the procurement scope? 
  4. What is the liability exposure if data encrypted today is compromised in the quantum era? 

These are no longer questions that sit with the security team alone. When the answer affects budget cycles, vendor contracts and organizational liability, they belong in the boardroom. 

The cost of waiting 

The finalisation of the first NIST post-quantum standards gave the market something it had been waiting for: a credible starting point. But standards alone do not modernise infrastructure. 

Migration still requires discovery, testing, policy updates, interoperability work and governance. In high-assurance environments, it also requires certification. 

That is why France’s move is significant. It suggests that quantum readiness is moving from “good practice” to an explicit condition of trust. 

A growing number of other governments have moved from guidance to mandate — with dates attached to consequences. The US requires National Security Systems to be post-quantum compliant by 2027. The EU — covering 27 member states — has set 2030 as a binding deadline for high-risk use cases, with full transition mandated by 2035. Australia requires vulnerable asymmetric cryptography to be retired entirely by 2030. These are not aspirational targets. They are procurement and compliance obligations — and the organizations that treat them as distant IT problems will find themselves outside certification windows before migration is complete. 

The next generation of secure infrastructure will not be defined only by the strength of its encryption today. It will be defined by whether that encryption can evolve safely tomorrow. 

Quantum-safe encryption is no longer just a technical feature. It is becoming a condition of certification, procurement and sovereign control. 

The organizations that prepare now will not simply be more secure. They will be easier to trust. 

 

Written by Julian Fay, Co-Founder & Chief Technology Officer, Senetas 

Stay up to date with the latest cybersecurity news from Senetas. Subscribe to "The View"

Go back
Senetas Logo
Senetas Logo