Summary
- France-led G7 cyber authorities have issued a new call for public and private organisations to accelerate preparation for post-quantum cryptography.
- The intervention builds on the G7’s 2025 migration work and coincides with new EU feedback on implementation milestones, prioritisation, and crypto agility.
- Migration is increasingly becoming a long-term infrastructure, procurement, and asset-management programme rather than a standalone cryptography upgrade.
G7 cybersecurity authorities are calling on public and private organisations to accelerate their transition towards quantum-resistant cryptography, as European policy begins to move from broad migration targets towards the practical sequencing of technology, procurement, and infrastructure changes.
France’s National Cybersecurity Agency, ANSSI, issued the call on Thursday under France’s 2026 G7 presidency. The G7 Cybersecurity Working Group brings together national cyber authorities from member countries, with the European Commission and the EU Agency for Cybersecurity, ENISA, participating as guests.
The group said the development timetable for cryptographically relevant quantum computers remains uncertain but argued that organisations should not use that uncertainty as a reason to defer preparation. Current public-key cryptography underpins authentication, digital signatures, secure communications, certificates, software distribution, and numerous other functions embedded deeply inside enterprise and public infrastructure.
Replacing those mechanisms is consequently not comparable to deploying an ordinary software update. Cryptographic dependencies can be buried inside long-lived hardware, embedded products, identity systems, certificates, third-party services, bespoke applications, and supplier contracts, creating migration programmes that may span several budget and technology cycles.
The latest G7 intervention builds on work carried out under Canada’s 2025 presidency, when the group established common recommendations for preparing a post-quantum transition. France is now pushing that work towards decision-makers beyond specialist cryptographic teams.
Europe is moving in the same direction. The EU’s NIS Cooperation Group published feedback this week from a consultation on its coordinated post-quantum implementation roadmap. It received 97 submissions, with respondents highlighting clear milestones, actionable steps, risk-based prioritisation, consistency between timelines, hybrid cryptographic approaches, and crypto agility as particularly useful elements.
The feedback also identified areas requiring further clarification, including how organisations should estimate quantum risk, prioritise systems, use hybrid schemes, and align national and European roadmaps. Those are implementation questions rather than arguments about whether migration will eventually be required.
That reflects the direction already visible in the UK and France. Cyber Insider has previously examined how post-quantum migration is becoming an executive resilience programme, requiring asset visibility, supplier readiness, governance, and multi-year planning.
The growing emphasis on crypto agility is particularly significant. Organisations cannot assume that selecting one new algorithm completes the transition permanently. Cryptographic standards, implementation guidance, and assurance requirements will continue to evolve, while some systems may need to support conventional and post-quantum methods in parallel during lengthy transition periods.
Procurement is therefore likely to become one of the main pressure points. Long-life infrastructure acquired now can remain operational well into the period when quantum-resistant mechanisms are expected to become standard. Buyers will increasingly need to know whether products can be upgraded, whether suppliers maintain inventories of cryptographic components, and whether contractual support extends through the transition.
The same problem applies to information with a long confidentiality life. Even before a cryptographically relevant quantum computer exists, organisations have to consider whether information captured today could retain sufficient value to make future decryption consequential.
The G7 call does not resolve the uncertainty over when quantum computing will cross the threshold required to threaten widely used public-key algorithms. It does, however, make the policy direction increasingly difficult to mistake: governments are treating the migration period itself as a resilience problem, and waiting for certainty would leave too little time to replace cryptography embedded across complex estates.





