フランスのアンシが2027年からPQC非搭載製品の認証を停止
## Japanese Translation:
フランスの ANSSI は 2026 年 6 月 17 日に、量子耐性暗号化を備えていないセキュリティ製品については 2027 年までに認証を停止し、企業には 2030 年までに量子安全な製品を購入することをお勧めすると発表しました。NIS2 ディレクティブの下、フランスの政府機関および重要インフラに対する認証は引き続き必須であり、準拠しないことはヨーロッパ最大の政府テック市場へのアクセス喪失というリスクを意味します。この動きは、「現在データを暗号化して保存し、 cryptographically relevant quantum computer が利用可能になった時点で復号化する」という「Harvest Now, Decrypt Later」の脅威を対象としています。専門家の推計によれば、そのような量子コンピュータの利用が可能になるのは 2030 年代半ば頃です。フランスの 2021 年国家量子戦略では、公的および私的資金で合わせて 4 年間で 18 億ユーロ(Reuters は最大 30 億ユーロとの引用)へのコミットメントを行っています。ANSSI のポスト量子暗号に関する初の位置取り論文は 2022 年に発表され、2023 年末のアップデートで 2027 年の認証停止期限が設定されました。これは、2027 年 1 月 1 日に有効になる米国の NSA CNSA 2.0 調達ゲートと密接に整合しています。ただし、ANSSI のタイムラインは実質的により厳格です:ANSSI は 2030 年以降、古典的アルゴリズムとポスト量子アルゴリズムを組み合わせたハイブリッドメカニズムを強く推奨する一方、NSA CNSA 2.0 は過渡措置として純粋な PQC を許容しています。ANSSI が委託した 2025 年 5 月の調査では、調査対象組織のいずれも移行計画を有していなかったことが判明し、CISO には正確なタイムラインがなく、多くの使用例は特定されていませんでした。12 月 2025 年の CEPS レポートで引用された ENISA の評価では、EU 加盟国全体にわたり、ほとんどの欧州関係者は依然として大いに準備ができていないと結論付けられました。通常、認定プロセスには 12 ヶ月から 18 ヶ月かかりますので、2026 年半ばにパイプラインに入った製品は 2027 年の截止期限までに認証を取得する必要があります。ベンダーは二重のコンプライアンス負担に直面しており、ANSSI/EU の基準を満たす一方で、米国の NIST/NSA の要件にも対処しなければなりません。具体的な懸念点としては、銀行や公共サービスが積極的に露出度を評価していること、ブロックチェーンシステムにおける ECDSA が最も早期に量子攻撃の標的となること、そしてこの技術変化の中で重要インフラを保護することに伴う組織全体の摩擦が含まれます。
## Text to translate:
France's ANSSI confirmed on June 17, 2026, that it will cease certifying security products lacking quantum-resistant encryption by 2027; businesses are advised to purchase quantum-safe products by 2030. Certification remains mandatory for French government agencies and critical infrastructure under the NIS2 directive, meaning non-compliance risks loss of access to Europe's largest government technology markets. The move targets "Harvest Now, Decrypt Later" threats where adversaries store encrypted data now to decrypt it once a cryptographically relevant quantum computer becomes available, which experts estimate could occur in the mid-2030s. France's 2021 national quantum strategy commits €1.8 billion (with Reuters citing up to €3 billion) over four years for public and private funding. ANSSI's first position paper on post-quantum cryptography arrived in 2022, with a late 2023 update setting the 2027 certification cutoff, aligning closely with the U.S. NSA CNSA 2.0 procurement gate effective January 1, 2027. However, ANSSI's timeline is stricter in practice: it strongly recommends hybrid mechanisms combining classical and post-quantum algorithms beyond 2030, whereas NSA CNSA 2.0 permits pure PQC as an interim measure. A May 2025 study commissioned by ANSSI found none of the surveyed organizations had a transition plan, with CISOs lacking precise timelines and many unidentified use cases; an ENISA assessment cited in a December 2025 CEPS report concluded most European stakeholders across EU member states remain largely unprepared. Qualification processes typically take 12 to 18 months, so products entering the pipeline in mid-2026 must achieve certification before the 2027 cutoff. Vendors face a dual compliance burden: meeting ANSSI/EU standards while also addressing U.S. NIST/NSA requirements. Specific concerns include banks and public services actively assessing exposure, ECDSA in blockchain systems being among the earliest quantum attack targets, and the broader organizational friction of securing critical infrastructure amid this technological shift.