A new G7 call to action says public- and private-sector organizations should begin a risk-based transition to post-quantum cryptography now, with cryptographic inventories, supplier engagement and procurement requirements among the practical first steps.

Key takeaways

  • The G7 Cybersecurity Working Group released its post-quantum cryptography call to action on September 3, 2026.
  • The publication is guidance rather than a new binding regulation, but it explicitly calls for PQC to be incorporated into cybersecurity requirements and procurement processes.
  • Organizations should start by locating public-key cryptography in devices, applications, certificates, remote access, firmware-signing systems and third-party services.
  • Long-retention data and systems with long replacement cycles should receive early attention because adversaries can collect encrypted information before a cryptographically relevant quantum computer exists.
  • Integrators and facility operators should ask manufacturers for PQC roadmaps, upgrade paths, support commitments and likely interoperability constraints.

A coordinated G7 call to begin the transition

The G7 Cybersecurity Working Group has called on governments and organizations to begin moving toward post-quantum cryptography (PQC), arguing that the migration needs to start before a quantum computer is capable of defeating widely used public-key cryptography. The group’s “Preparing for the Post-Quantum Era: A Call to Action” was published on September 3, 2026, with CISA, France’s ANSSI and Canada’s Centre for Cyber Security among the agencies publishing the joint initiative.

The publication identifies five priorities: improving awareness of quantum-related cyber risk; developing national strategies; advancing research and deployment; strengthening public-private cooperation; and incorporating PQC into cybersecurity requirements and purchasing processes. It is not itself a regulatory mandate or a product-approval program. Its importance is that it places procurement and implementation planning alongside national policy as core elements of a successful migration.

Why the risk exists before quantum computers arrive

PQC addresses the future risk that a cryptographically relevant quantum computer could break many currently deployed public-key mechanisms. Those mechanisms underpin functions such as encrypted connections, digital certificates, software signatures, device identity and remote authentication. The date at which such a quantum computer may arrive remains uncertain, but the G7 agencies say uncertainty is not a reason to defer preparation.

The immediate concern is commonly called harvest-now, decrypt-later activity: an attacker can capture encrypted traffic or steal encrypted records today and retain them for later decryption. That creates a present planning issue for information that must remain confidential for many years, including sensitive facility records, personal data, designs, credentials and certain video or access-control archives. The agencies also warn that future quantum capability could affect authentication and integrity protections, not only data confidentiality.

What this means for physical-security and infrastructure environments

For security-product manufacturers, integrators and enterprise facility teams, the PQC project will extend beyond a corporate web server. Public-key cryptography may be embedded in video-management platforms, access-control servers, intercom and visitor-management systems, network appliances, VPNs, wireless infrastructure, cloud connectors, mobile credentials, PKI services, and firmware or software update workflows.

The earlier G7 technical migration guidance recommends creating a map of cryptographic dependencies covering internal systems and third-party-delivered services. In operational environments, this should include the dependencies that are easy to overlook: device certificates, certificate authorities, management workstations, remote-support channels, API integrations, backup archives, signed firmware packages and legacy equipment with constrained processors or limited bandwidth.

This discovery work also helps distinguish a near-term configuration or software update from a replacement problem. Some older products may lack a vendor path to PQC-capable protocols, while other systems may be upgraded under an existing maintenance agreement. A complete answer requires direct confirmation from each supplier rather than assumptions based on a product’s age or encryption label.

Crypto agility should become a procurement question

The G7’s technical guidance advises organizations to engage vendors early and to include PQC requirements in tenders. For buyers, a practical starting point is to request a written PQC and cryptographic-agility roadmap for any system expected to remain in service into the 2030s. The request should cover supported protocols, planned certificate and signature support, software and firmware update availability, hardware limitations, support-term coverage, migration dependencies and anticipated interoperability testing.

Procurement teams should also avoid treating PQC as a single checkbox. Post-quantum algorithms can bring different key, ciphertext and signature sizes, which may affect low-bandwidth links, embedded devices, radios and storage-constrained applications. Testing should evaluate performance, certificate lifecycle operations, failover behavior, monitoring and interoperability with existing management tools and partner systems.

NIST’s 2024 publication of FIPS 203, FIPS 204 and FIPS 205 provides an important standards foundation for quantum-resistant key establishment and digital signatures. But an available standard does not automatically make a deployed estate ready. Product support, protocol adoption, implementation quality and a controlled migration plan remain decisive.

A risk-based first work plan

The G7 recommends a phased, risk-based approach. Organizations can begin by assigning executive ownership, establishing a cross-functional working group and building an inventory of where cryptography protects data, communications and device trust. Security engineering, network operations, procurement, legal or compliance, facilities technology and major vendors should all be represented.

Prioritization should consider the value and required confidentiality life of the data, exposure to interception, the business impact of compromised authentication, and the time required to change the system. Long-lived PKI environments, externally accessible services, software-signing processes and systems carrying data with extended retention requirements are reasonable candidates for early analysis.

For installers and integrators, the near-term opportunity is disciplined documentation: record cryptographic settings and certificate relationships during design, commissioning and service work. That information can substantially reduce the cost and disruption of a future PQC migration. The G7 message is not that every field device must be replaced immediately; it is that organizations should stop treating quantum-resistant cryptography as a distant problem and start making it part of lifecycle, design and purchasing decisions.