By Ann Marie van den Hurk, Mind The Gap Advisory

France just set a clock.

Starting in 2027, ANSSI — France’s national cybersecurity agency — will stop certifying security products that lack quantum-resistant encryption. By 2030, organizations operating in regulated environments should be purchasing only quantum-safe products. ANSSI approval is required for use across French government bodies and critical infrastructure operators, which means this is not guidance. It is a de facto phase-out with a hard deadline.

The technical commentary that followed focused on post-quantum algorithms, migration timelines, and crypto inventory challenges. All of that is real and worth understanding.

But the most consequential question is not technical.

ANSSI’s chief of staff, Samih Souissi, said it plainly at the France Quantum conference:

“It’s not only a technical issue. It’s a matter of governance, industrial planning, regulation, and sovereignty.”

Samih Souissi, Chief of Staff, ANSSI

He handed organizations their real assignment. Most will miss it.

The Question Nobody Is Asking

 

When a mandate like this lands, every security team reads it and thinks: new tools, new standards, new migration projects.

That is the wrong read.

The right question is not “what cryptography do we need to replace?” The right question is this: when your organization receives a mandate with a hard deadline, who is authorized to act?

Not who is aware of it. Not who is concerned about it. Who has the authority to commit resources, resolve competing priorities, approve exceptions, and be accountable for execution?

Most organizations cannot answer that question cleanly. Not because the people are incompetent. Because the authority has never been formally assigned.

That is the problem France just handed every CISO, General Counsel, and Chief Risk Officer in a regulated organization.

What Actually Happens Inside Organizations

 

Here is what the next eighteen months will look like inside most organizations that receive this mandate.

 

The Pattern

Security assumes IT owns the transition. IT assumes the vendors handle it. Vendors assume leadership will fund it. Legal wants to understand liability before anything moves. Procurement is waiting for a budget line. Leadership assumes Security has it under control.

Eighteen months pass. Nothing happens.

Then a client asks: what is your post-quantum transition plan? Nobody has an answer.

 

This is governance drift. Authority, accountability, and decision-making become disconnected from operations. The organization knows something requires action but cannot translate awareness into authorized, coordinated response.

The technical challenge is real. The governance failure is what slows everything down.

This Pattern Is Not New

 

Post-quantum cryptography is the latest example of a pattern that repeats with every major cyber mandate.

AI governance initiatives stall because nobody owns the decision authority to set policy across legal, security, and product simultaneously. CMMC readiness programs move slowly because the authority to commit to remediation costs sits in a different seat than the authority to identify the gaps. Software supply chain security efforts fragment because accountability is distributed across teams that each assume someone else is driving.

The technology is rarely the blocker. The governance structure is.

Every new cyber requirement eventually hits the same wall: the organization can detect the risk faster than it can decide what to do about it. And the reason it cannot decide is not a lack of information. It is a lack of defined decision authority.

Souissi named this explicitly. Governance. Industrial planning. Regulation. Sovereignty. Not algorithms.

The Harvest Now, Decrypt Later Problem

 

There is a technical dimension worth understanding because it removes the option to wait.

Sophisticated adversaries are already collecting encrypted data today with the intention of decrypting it later, once quantum computing capability matures. For organizations holding long-lived sensitive data — patient records, financial data, defense contracts, legal files — the exposure is not a future problem. It is a current one.

 

Why This Cannot Be Deferred

Organizations that wait for the technical urgency to force the issue will be making rushed decisions under pressure rather than deliberate decisions under structure. That is exactly the scenario governance drift creates.

 

The window for organized, authorized action is now. The governance conversation cannot be deferred until quantum computers become a practical threat.

What Prepared Organizations Do Differently

 

The organizations that adapt fastest to mandates like this are not always the ones with the most mature technical infrastructure. They are the ones that can make clear, authorized decisions faster than everyone else.

That speed comes from having answered a set of questions before the mandate arrives.

Who owns this decision? Not who is interested in it — who is authorized to commit the organization to a course of action. Who owns the budget authority? Who approves exceptions when the timeline creates conflict with operational priorities? How are competing demands between security, legal, IT, and procurement resolved? Who is accountable if the deadline is missed?

These are not cryptography questions. They are governance questions. And organizations that have answered them in advance move through mandates like this in weeks rather than months. The ones that have not answered them discover the gap when the deadline is close and the decisions are expensive.

The Broader Pattern

 

France is not acting alone. The EU, UK, Canada, Australia, and the United States have all published post-quantum transition roadmaps with target dates between 2030 and 2035. The regulatory pressure will compound across jurisdictions over the next decade.

That means organizations will face this pattern repeatedly. Post-quantum cryptography today. AI governance requirements. Expanded CMMC scope. New cyber regulations that do not exist yet.

The common failure point will not be the technology. The common failure point will be the same one it always is: the organization cannot determine who is authorized to act, what must be done, and how quickly decisions can be made.

 

Technology identifies the requirement. Governance determines whether the organization can actually respond to it. And in most organizations, governance drift breaks things operationally long before systems fail.

 

The organizations that understand this are building the governance infrastructure to handle it. The ones that do not will spend the next decade relearning the same lesson in different technical contexts.

 

If This Pattern Sounds Familiar Inside Your Organization

Governance Continuity Assessment

A 90-minute structured session that surfaces where governance drift has created decision authority gaps — and what that exposure looks like before a mandate, deadline, or incident forces it into view. Written finding delivered within 48 hours.

Book a Discovery Call →


Ann Marie van den Hurk, MSc., APR is the founder of Mind The Gap Advisory and originator of the CrisisOS5™ Framework. She advises CISOs, General Counsel, Chief Risk Officers, and boards on decision authority and executive crisis readiness for the AI era. Based in Newport, Rhode Island — serving organizations across New England, nationally, and globally. mindthegapcyber.com

Share This