Skip to main content
CybersecurityVulnerability Management

G7 Pushes for Swift Adoption of Quantum-Safe Cybersecurity Measures

Empty podium in a formal briefing room with a laptop screen in the foreground.

"We recognize the growing threat that quantum computing poses to public-key cryptography, and the security of both public and private organizations."

ANSSI and the G7 Cybersecurity Working Group lead a call to action

On September 3, under France's 2026 G7 Presidency, the French National Cybersecurity Agency (ANSSI), which chairs the G7 Cybersecurity Working Group, published a document urging a faster transition to post-quantum cryptography (PQC). The call asks governments and organizations to “reframe” the quantum threat “from a distant future problem” to “a near-term threat that demands action across all sectors, not just critical infrastructure.” The document acknowledges that the exact timeline for quantum-capable machines is uncertain, but says “several recent advances” make the development of quantum computers that can break widely used public-key cryptography a credible risk.

The five G7 priorities for a PQC transition

The document lays out five priorities for governments, policymakers and the private sector:

  • Raising awareness about quantum threats;
  • Developing national strategies on transitioning to PQC, including goals to build “an adequate supply of PQC hardware and software products” and to encourage user adoption;
  • Focusing research and development on advancing PQC through innovation and practical solutions;
  • Developing public‑private partnerships among government, industry and academia to promote and develop domestic expertise and capabilities in quantum‑safe technologies;
  • Integrating PQC into cybersecurity requirements.

Practical recommendations for organizations

The G7 text recommends a risk‑based, phased approach. It instructs governments and organizations to first identify systems that hold the most critical data and assets and to prioritize PQC transition efforts accordingly. It explicitly warns against waiting for confirmed availability of quantum computers capable of breaking current encryption, saying proactive action is important to managing quantum risk.

The document further advises organisations to inventory cryptographic assets, map dependencies and develop a transition plan. To limit transition costs, it suggests purchasing products that already integrate PQC and replacing systems with quantum‑safe ones as part of normal renewal schedules. The call also notes that starting the transition early could yield lower overall migration costs.

Signatories: G7 national cybersecurity agencies, the EU Commission and ENISA

The call to action was signed by the national cybersecurity agencies of all G7 member states — Canada, France, Germany, Italy, Japan, the UK and the US — and is supported by the EU Commission and the EU Agency for Cybersecurity (ENISA). The document therefore represents a coordinated appeal across G7 cyber authorities and explicit backing from European Union cyber bodies.

Separately, ANSSI has already signalled policy moves at the national procurement level: it announced it will stop vetting products that lack quantum‑safe encryption beginning in 2027, and that post‑quantum security will become a mandatory feature in procurement of some security products by 2030.

How technologists, policymakers, and procurement leaders are likely to respond

  • Technologists and security teams will be asked to perform the inventories and dependency mappings the document prescribes and to draft phased migration plans that prioritize systems holding critical data, as the guidance specifies.
  • Policymakers and regulators are urged to develop national strategies that include supporting an “adequate supply of PQC hardware and software products,” and to integrate PQC into cybersecurity requirements, aligning regulation with the five priorities set out by the G7.
  • Procurement leaders and affected enterprises are advised to favor products that integrate PQC and to fold the transition into standard renewal cycles, a step the document promotes explicitly to limit transition costs and encourage adoption.

The G7 statement reframes a technical debate into a policy and procurement clock. It asks public and private actors to plan now — through inventories, transition roadmaps, purchasing choices and national strategies — rather than waiting for a definitive quantum breakthrough. With ANSSI's 2027 and 2030 procurement milestones already on the calendar, the document sets measurable expectations for action and signals that delay could raise costs and operational complexity.

Read the original G7 call to action here: https://www.infosecurity-magazine.com/news/g7-urges-quantum-safe-cyber-rules/