The G7 Cybersecurity Working Group has called on governments and organizations across all sectors to begin preparing immediately for a transition to post-quantum cryptography (PQC). The group highlighted the current “harvest now, decrypt later” threat: adversaries can collect encrypted information today and retain it until cryptographically relevant quantum computers can break existing public-key encryption, placing long-lived sensitive data at risk.
The non-binding call prioritizes awareness, national strategies, research, public-private cooperation, and embedding PQC in cybersecurity requirements. Organizations should begin with a cryptographic inventory, defined ownership, limited pilots, crypto-agile architecture, hybrid standardized deployments, and PQC-focused procurement. EU member states are expected to have initiated national PQC strategies by the end of 2026, while high-risk environments—particularly critical infrastructure—should transition as early as possible and no later than the end of 2030; delayed adoption could also affect supplier eligibility for public-sector and other contracts.

Track how attackers are adapting to this technology.
5 events from the most recent confirmed update back to the earliest known activity.
The G7 Cybersecurity Working Group published “Preparing for the Post-Quantum Era: A Call to Action,” urging governments and organizations in all sectors to begin PQC migration as soon as possible. Co-issued by G7 cybersecurity authorities, the call highlighted harvest-now-decrypt-later risks and prioritized awareness, national strategies, R&D, public-private partnerships, and PQC cybersecurity requirements.
US Executive Order 14412 directed the FAR Council to propose a rule requiring covered federal contractors to comply with NIST FIPS, including PQC-compliant algorithms, by December 31, 2030.
France’s ANSSI announced that it would cease certifying security products lacking PQC beginning in 2027, and advised French businesses to procure quantum-safe products by 2030. ANSSI certification is required for products sold to French government agencies and critical-infrastructure operators.
Under Canada’s 2025 G7 presidency, the G7 Cybersecurity Working Group published a statement on preparing for a PQC migration. It recommended phased, risk-based migration, cryptographic inventories, dependency mapping, transition planning, procurement updates, and dedicated project teams.
The G7 Cyber Expert Group published a separate post-quantum cryptography roadmap for the financial sector, orienting critical financial systems toward migration during 2030–2032 and using 2035 as a broader reference point.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.