ZeroHour
Infosecurity Magazinepublished ()ingested Kevin Poireault

G7 Urges Fast-Track on Quantum-Safe Cybersecurity Rules

infoPolicy & legalimportance 60
AI summary · glm-5.3-flash

G7 cybersecurity agencies led by France's ANSSI urged accelerated transition to post-quantum cryptography, prioritizing critical systems and phased, risk-based migration.

Under France's 2026 G7 Presidency, ANSSI, chairing the G7 Cybersecurity Working Group, published a September 3 call to action urging governments and organizations to begin quantum-safe (PQC) transitions now, reframing the quantum threat as near-term. The document, signed by the national cyber agencies of all G7 members and supported by the EU Commission and ENISA, outlines five priorities including national PQC strategies, R&D, public-private partnerships, and integrating PQC into cybersecurity requirements. It recommends cryptographic inventories, dependency mapping, prioritizing the most critical systems, and buying PQC-integrated products during normal renewal cycles. ANSSI will stop vetting non-quantum-safe products in 2027, with PQC mandatory in some security product procurement by 2030.

  • Call to action signed by national cyber agencies of all G7 states, backed by EU Commission and ENISA.
  • Recommends cryptographic inventories, dependency mapping, and prioritizing PQC migration for the most critical systems first.
  • Urges buying PQC-integrated products and migrating during normal renewal cycles to limit costs.
  • ANSSI will stop vetting non-quantum-safe products in 2027; PQC becomes mandatory in some procurement by 2030.
Full article467 words · extracted from infosecurity-magazine.com · click to collapse

The G7 is urging nations to accelerate the post-quantum cryptography (PQC) transition.

As part of France's 2026 G7 Presidency, the French National Cybersecurity Agency (ANSSI), chairing the G7 Cybersecurity Working Group, has spearheaded a new call to action urging governments and organizations to begin transitioning to quantum-safe encryption ahead of the threat posed by quantum computing.

The document, published on September 3, urges the public and private sectors to “reframe” the quantum threat “from a distant future problem” to “a near-term threat that demands action across all sectors, not just critical infrastructure.”

“We recognize the growing threat that quantum computing poses to public-key cryptography, and the security of both public and private organizations,” the document reads.

“Although the exact timeline is uncertain, several recent advances suggest an anticipation of the development of quantum computers able to break widely used public-key cryptography mechanisms and threaten the security of digital infrastructures.”

The document stated that, to mitigate risks, governments and organizations should first identify the systems holding the most critical data and assets and prioritize their PQC transition efforts accordingly. It emphasized that acting proactively, rather than waiting for confirmed the availability of quantum computers capable of breaking some current encryption algorithms, was important to managing quantum risk.

Furthermore, the document recommended that organizations adopt a phased and risk-based strategy, inventory their cryptographic assets, map their dependencies and develop a transition plan.

It advised that, to limit transition-related costs, organizations should opt to purchase products that integrated PQC and replace their systems with quantum-safe ones as part of their standard renewal schedule.

It further noted that starting the transition early could result in lower migration costs overall.

The G7 document also outlines five priorities that must be addressed by governments, policymakers and the private sector:

  • Raising awareness about quantum threats
  • Developing national strategies on transitioning to PQC, with additional goals of developing “an adequate supply of PQC hardware and software products” and encouraging users to adopt them
  • Focusing research and development efforts on advancing PQC through innovation and the development of practical solutions
  • Developing public-private partnerships between government, industry and academia, particularly to promote and develop domestic expertise and industry capabilities in quantum-safe technologies
  • Integrating PQC into cybersecurity requirements

This call to action was signed by the national cybersecurity agencies of all the G7 member-states (Canada, France, Germany, Italy, Japan, the UK and the US, and is supported by the EU Commission and the EU Agency for Cybersecurity (ENISA).

It comes a few months after ANSSI announced it will stop vetting products that lack quantum-safe encryption starting in 2027, with post-quantum security to become a mandatory feature in the procurement of some security products by 2030.

Read more about how some cybersecurity vendors are preparing for the PQC migration here.

Image credits: IgorGolovniov / Rawpixel.com / Shutterstock.com

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/g7-urges-quantum-safe-cyber-rules/