Skip to main content
a promotional graphic telling you that PCI Compliance is no longer an annual exercise and that continuous monitory must be built in
ANSSI Just Changed the Crypto Timeline: What Does 2027 Mean for You?Audit & Certification
5 min readFor Compliance Officers

ANSSI Just Changed the Crypto Timeline: What Does 2027 Mean for You?

France's cybersecurity agency, ANSSI, has announced a significant deadline: by 2027, it will stop certifying security products that lack quantum-resistant encryption. By 2030, businesses are expected to purchase only quantum-safe products. This announcement has compliance officers recalculating their roadmaps.

Here's what compliance officers are asking and what you need to know right now.

Understanding the Impact

ANSSI's timeline is a firm deadline for product certification. If you're managing compliance programs related to French government contracts, critical infrastructure certifications, or multinational operations with European connections, you have three years to overhaul your cryptographic architecture.

Compliance officers managing SOC 2 Type II audits, ISO/IEC 27001 certifications, and NIST Cybersecurity Framework (CSF) 2.0 implementations are now factoring quantum-safe requirements into their control environments.

Q1: Does this only affect organizations doing business in France?

No. ANSSI's decision sets a precedent that will influence international standards bodies and certification frameworks. A major European cybersecurity authority's certification cutoff affects Common Criteria evaluations, vendor roadmaps for globally sold products, and pressures other national agencies to follow suit.

If you're maintaining ISO/IEC 27001 certification, your cryptographic controls in Annex A 8.24 (use of cryptography) will need to address quantum resistance. Auditors will soon ask about your transition plan for post-quantum cryptography requirements.

SOC 2 Type II reports covering cryptographic key management (typically under CC6.6 or CC6.7) will face similar scrutiny. Your service organization controls must demonstrate forward-looking risk assessment, as quantum computing represents a known, time-bounded threat.

Q2: What's vulnerable to quantum attacks?

Current public-key cryptography, specifically RSA, Elliptic Curve Cryptography (ECC), and Diffie-Hellman key exchange, is vulnerable. These algorithms protect TLS connections, digital signatures, certificate authorities, VPN tunnels, and encrypted data at rest.

A powerful quantum computer running Shor's algorithm can break these in hours. This "harvest now, decrypt later" threat is significant for data with long confidentiality requirements, such as health records and financial transactions.

Symmetric encryption like AES-256 is more resilient. Grover's algorithm reduces its effective strength, but doubling the key size addresses that risk. Your immediate concern is asymmetric cryptography protecting key exchange and authentication.

Q3: We just finished rotating to 4096-bit RSA keys. Did we waste time?

Not entirely. Longer RSA keys defend against classical computing attacks, which you need protection from today. However, they won't help against quantum threats. This is the reality: you're implementing controls with a defined shelf life.

Don't delay other security improvements while waiting for quantum-safe algorithms to mature. You still need defense-in-depth against current threats. When selecting new encryption products or renegotiating vendor contracts, ask about their quantum-safe roadmap and upgrade path.

Q4: What do I need to do before 2027?

First, build your cryptographic inventory. Map every system using public-key cryptography: where you're generating keys, where you're storing them, which protocols depend on them, and which vendors control the implementation.

For each system, document:

  • Cryptographic algorithms in use (RSA, ECC, DSA)
  • Key lengths and rotation schedules
  • Whether you control the implementation or a vendor does
  • Data classification and retention requirements
  • Compliance obligations tied to that system

This inventory feeds your risk assessment. Systems protecting high-value data with long retention periods should be prioritized for transition. Legacy systems that can't be easily upgraded need compensating controls or accelerated retirement plans.

Second, start testing post-quantum algorithms in non-production environments. NIST finalized its first post-quantum cryptographic standards in 2024: CRYSTALS-Kyber for key encapsulation and CRYSTALS-Dilithium for digital signatures. You need hands-on experience with these standards to understand their performance and compatibility.

Q5: How do I explain this to leadership who just approved our current crypto budget?

Frame it as a compliance timeline, not a technology preference. ANSSI's 2027 certification cutoff is a forcing function. If your organization depends on certified products for regulatory compliance, government contracts, or customer assurance, you'll lose access to newly certified solutions that lack quantum resistance.

The business risk: vendor products purchased in 2028 won't receive ANSSI certification if they use only classical encryption. That limits your vendor options and could disqualify you from certain markets or contracts.

The financial argument: transitioning cryptography takes years, not months. Waiting until 2026 means emergency spending and audit findings. Starting now spreads the cost across budget cycles and gives you time to negotiate vendor support.

Compare it to TLS 1.0 deprecation. Organizations that waited until browsers blocked it faced outages and emergency remediation. Those that started early transitioned smoothly.

Q6: Will this affect my current SOC 2 or ISO 27001 certification?

Not immediately, but your next audit will include forward-looking questions. Auditors assess whether your risk management process identifies emerging threats. Quantum computing is a known risk with published timelines.

For ISO/IEC 27001, your risk treatment plan (required in clause 6.1.3) should address cryptographic obsolescence. Your Statement of Applicability needs to explain how you're monitoring post-quantum developments and planning control updates.

For SOC 2 Type II, your risk assessment process should document quantum threats and your response timeline. If you're claiming a multi-year control design in your system description, auditors will ask whether that design accounts for cryptographic transitions.

You won't fail an audit for not having quantum-safe encryption deployed in 2025, but you could get an observation or finding for having no transition plan at all.

Q7: What if we're a small team without cryptography expertise?

You're not alone, and you don't need to become cryptographers. Focus on three things:

First, engage your vendors. Ask your SaaS providers, cloud platforms, and security tool vendors about their quantum-safe roadmap. Document their responses for your risk register.

Second, join industry working groups. The Cloud Security Alliance has a quantum-safe security working group. Your sector likely has an ISAC or industry forum discussing this transition. These groups share playbooks and lessons learned.

Third, treat this as a vendor management and architecture problem, not a cryptography problem. You need to know where encryption lives in your environment and who's responsible for updating it. That's a GRC skillset, not a PhD requirement.

Where to Go for More

NIST's National Cybersecurity Center of Excellence published migration guidance in its post-quantum cryptography project. It includes discovery tools, transition timelines, and interoperability considerations.

The Cloud Security Alliance's "Quantum-Safe Security Working Group" maintains practical resources for non-cryptographers, including vendor questionnaires and risk assessment templates.

ANSSI itself publishes technical guidance (in French and English) on its quantum-safe transition expectations. If you're in scope for French certifications, that's your authoritative source.

Start your cryptographic inventory this quarter. By the time ANSSI stops issuing non-quantum-safe certifications in 2027, you'll know exactly which systems need attention and have realistic timelines for addressing them.

a promotional banner asking how ready are you for PCI DSS 4.0? With a call-to-action to get the checklist now.

You Might Also Like