Global cybersecurity

The G7's Post-Quantum Cryptography Advisory Gets the Sequencing Right — Funding It Is the Harder Problem

G7 and CISA urge immediate post-quantum migration over 'harvest now, decrypt later' risk, but the inventory-first approach needs money, not just mandates.

The Post-Quantum Migration Clock People of Internet Research · Global 3 Standards finalized NIST finalized FIPS 203, 204, and … 8 years Years to standardize NIST's PQC competition ran from 20… 2030 Key-establishment deadline US federal high-value systems must… 2035 Full migration deadline Target year for complete US federa… peopleofinternet.com
The Post-Quantum Migration Clock People of Internet Research · Global 3 Standards finalized 8 years Years to standardize 2030 Key-establishment deadline 2035 Full migration deadline peopleofinternet.com

Key Takeaways

A threat with no clock, and no waiting for one

On September 3, 2026, the G7 Cyber Security Working Group and the US Cybersecurity and Infrastructure Security Agency (CISA) published a joint call to action telling governments and companies to stop waiting for a "cryptographically relevant" quantum computer before migrating to quantum-resistant encryption. The advisory's logic is straightforward: a quantum computer capable of breaking RSA and elliptic-curve cryptography doesn't need to exist today for the threat to be live. An adversary can harvest encrypted traffic now — diplomatic cables, health records, source code, trade secrets — and simply wait, decrypting it once the hardware catches up. For data that needs to stay secret for a decade or more, that clock is already running (The Record).

The advisory, led by France's ANSSI during its G7 presidency and titled "Preparing for the Post-Quantum Era: A Call to Action," sets out five priorities: raising awareness, building national strategies, funding quantum-safe R&D, forming public-private partnerships, and — the line with teeth — folding post-quantum cryptography (PQC) into procurement requirements (CISA; cyber.gouv.fr). CISA has been explicit that vendors who drag their feet risk losing government contracts entirely.

The case for urgency is genuinely strong

It's worth granting the strongest version of the G7's argument before poking at it. Standardization is no longer the bottleneck: NIST finalized FIPS 203 (ML-KEM), FIPS 204 (ML-DSA), and FIPS 205 (SLH-DSA) on August 13, 2024, capping an eight-year public competition and declaring the algorithms "ready for immediate use" (NIST). There is no longer a credible excuse that the tools don't exist. And the asymmetry of the risk is real: encryption that fails silently, years after the fact, is uniquely dangerous because victims often never learn a breach occurred until the stolen data is already circulating. A government cable encrypted in 2026 that leaks in 2036 is still a functioning intelligence failure. Waiting for certainty about when a quantum computer will arrive is a bet against a downside with no clear floor.

The advisory's chosen mechanism — inventory first, prioritize by sensitivity, migrate inside routine refresh cycles rather than mandating rip-and-replace — is also the right instinct. It mirrors what US federal agencies are already being told to do: Executive Order 14412 and a subsequent OMB memo require agencies to finalize migration plans, appoint a migration lead, and prioritize high-value systems, with key-establishment migration due by 2030, digital signatures by 2031, and full completion by 2035 (FedScoop). A phased, risk-ranked approach is far more defensible than an arbitrary flag-day cutover that forces organizations to swap working systems wholesale.

Where proportionality breaks down: funding and small-vendor exposure

The design is sound; the enforcement lever is where this gets uneven. "Lose government contracts" is a blunt instrument when compliance capacity is not evenly distributed. FedScoop's reporting on the US timeline flags the actual obstacles: legacy systems that can't easily be re-keyed, limited commercial availability of PQC-compliant hardware, and a migration mandate that experts warn "cannot be an unfunded mandate" without congressional appropriations to match it. A large defense contractor can absorb a multi-year cryptographic re-architecture. A regional cloud provider, a mid-sized SaaS vendor serving a state agency, or a security contractor two tiers down the supply chain in a smaller G7 economy cannot necessarily do the same on the same clock — and losing a government contract for lagging on a mandate with no dedicated funding stream punishes capacity gaps as if they were negligence.

There is also a coordination risk the advisory doesn't fully resolve: seven governments each writing PQC into their own procurement rules, on possibly different timelines and with different acceptable-algorithm lists, is exactly the kind of fragmentation that raises compliance cost for any vendor selling across G7 markets without meaningfully raising security. NIST's standards give everyone a common technical baseline; the G7 should use that shared foundation to harmonize procurement language across member states now, rather than let seven parallel contract regimes emerge from a shared advisory.

The right call, incompletely funded

None of this argues against migrating. "Harvest now, decrypt later" is not a hypothetical — it describes a data-collection strategy that costs an attacker almost nothing today and pays off entirely on someone else's timeline. Governments are right to force the inventory conversation now, while the standards are settled and the deadline is still years out rather than months. But a procurement stick aimed at contractors works only if it's paired with money and harmonized rules, not just a shared advisory. The G7's sequencing — inventory, prioritize, migrate on the upgrade cycle — is the proportionate model. Whether it stays proportionate depends on whether member governments fund the mandate they're now writing into their own contracts, and whether "post-quantum by 2030" ends up meaning the same thing in Washington, Paris, and Tokyo.

Sources & Citations

  1. CISA — Preparing for the Post-Quantum Era: A Call to Action
  2. NIST — First 3 Finalized Post-Quantum Encryption Standards
  3. ANSSI (cyber.gouv.fr) — G7 Post-Quantum Call to Action
  4. The Record — G7 urges organizations to prepare for quantum cyber threats
  5. FedScoop — Agencies have four months to finalize quantum-ready migration plans