Published on
October 6, 2026
On September 3, 2026, the cybersecurity agencies of the G7 published a joint call to action. Its full name: the "G7 Cybersecurity Working Group Statement on Preparing for a Post-Quantum Cryptography Migration". Its message to public and private decision-makers is direct. According to the signatories, the quantum threat is a present planning matter, not a distant one.
According to ANSSI's announcement, the work was led by the French agency under France's 2026 G7 Presidency. It builds on groundwork laid during Canada's presidency the year before. The European Commission and ENISA participated as guests, and CISA co-issued the statement in the United States.
Joint statements of this kind arrive regularly. Most restate what the field already knows. This one deserves a closer read, for two reasons. First, what it puts at the center of the quantum risk picture. Second, what it says about procurement. Both choices carry practical consequences for anyone responsible for digital trust infrastructure.
Impersonation and Forgery Get Equal Billing
Most post-quantum communication to date has led with "Harvest Now, Decrypt Later". That is the risk of encrypted data being recorded today and decrypted once a powerful quantum computer exists. The G7 statement names that threat, scoped with care. Per the statement, it applies to data whose confidentiality has to outlast the time needed to build such a machine.
What distinguishes the document is the weight it gives to the second threat. A quantum-capable attacker, the signatories warn, could "impersonate trusted entities, compromise equipment, forge trusted data, or access confidential data." Impersonation and forgery are attacks on authentication. And authentication, in modern infrastructure, means digital signatures, certificates, and the PKI hierarchies that anchor them. HNDL concerns the confidentiality of yesterday's traffic. Forgery concerns the integrity of tomorrow's trust decisions: who your systems believe they are talking to, which software they accept, which documents count as signed.
The statement then draws the systemic conclusion. A broken authentication chain enables lateral movement. In its words, one organization's vulnerability "may expose other organizations and sectors". Put simply, trust infrastructure is shared infrastructure, and its weakest links are collective risks.
For PKI owners, the reading is clear. In the G7's framing, the certificate and signature layer is not a later chapter of the quantum transition. It stands at the center of the risk picture from day one.
Take control of your PKI infrastructure
See how Evertrust simplifies certificate lifecycle management.
Get StartedThe Procurement Lever
The statement's most concrete passage concerns buying, not building. The actions recommended by the working group follow a familiar sequence: inventory cryptographic assets, map dependencies, build phased and risk-based transition plans. Governance, the document adds, covers vendors and the supply chain, not only internal teams.
The novelty is where the G7 takes this next. The statement encourages organizations to update procurement policies to require post-quantum readiness. It also invites them to buy PQC-capable products during normal replacement cycles. The transition rides existing investment instead of demanding a separate one.
Then comes the sentence suppliers will be rereading. According to the statement, organizations that delay "may lose competitive advantage or may be excluded from contracting opportunities, including public procurement." That is the quantum transition translated into market language. Once readiness becomes a procurement criterion, it stops being an internal milestone. It becomes a condition of doing business, flowing down supply chains contract by contract. Vendors will face PQC questions in RFPs long before any national deadline arrives. And buyers will need their inventory in order to know what to ask for.
No Deadlines, by Design
The statement sets no migration deadlines of its own. Timelines, it says, are left to each country's national cybersecurity authority. The existing roadmaps stay authoritative: the EU coordinated roadmap and its 2030 and 2035 milestones, ANSSI's phased guidance on hybridation, BSI's recommendations in Germany, and the NIST transition path in the United States.
Read generously, and correctly in our view, this is a feature. The G7's role here is alignment, not scheduling. Seven governments plus the European institutions are stating one thing with one voice. The threat is real, preparation starts with inventory, and waiting now carries commercial as well as security consequences. The dates already exist. What the statement adds is the signal that they will not soften, and that every major Western economy points the same way.
For European readers, there is a quieter signal in the byline. ANSSI led this effort. France and the EU institutions have become central to shaping the global post-quantum agenda.
Closing Thoughts
The G7 call to action changes no regulation and sets no clock. That is not its job. Its contribution is to settle the framing at the highest political level. The quantum threat is a present-tense planning issue. Authentication and trust infrastructure sit at the center of it. And readiness will be tested first in procurement, not in cryptanalysis.
For organizations that have begun, with inventory, governance and a phased plan, the statement reads as confirmation. For the others, the question has quietly changed. It is no longer whether to start. It is how to explain not having started.