Skip to content
All news
News

CISA and G7 issue joint call to action on PQC

By quantakrypto Research4 min read

Also mentioned

NISTNISTNational Institute of Standards and TechnologyThe U.S. National Institute of Standards and Technology, the agency that develops and publishes cryptographic standards, including the FIPS series and post-quantum algorithms.Read the full entry, PQCPQCpost-quantum cryptographyCryptographic algorithms designed to run on today's classical computers while remaining secure against attacks by both classical and future quantum computers.Read the full entry are defined in the glossary.

TL;DR

Read this first

On September 3, 2026, CISA and the G7 Cyber Security Working Group published Preparing for the Post-Quantum Era: A Call to Action, co-signed by the UK's NCSC, France's ANSSI, Germany's BSI, Canada's CSE, Japan's NCO and Italy's ACN. It names five priorities: raise awareness of quantum risk, build national PQC strategies, fund quantum-safe research, deepen public-private cooperation, and put PQC into procurement and security requirements. It states plainly that organizations "can no longer afford to postpone" the transition. It changes no deadline that NIST IR 8547 or Executive Order 14412 had not already set. What it changes is who can no longer file quantum risk as someone else's timeline.

National cyber agencies rarely publish the same document. Each writes its own guidance on ransomware, on cloud configuration, on supply-chain risk, and each occasionally cites the others' work in a footnote. On September 3, seven of them put their names on one page: CISA for the United States, the NCSC for the United Kingdom, ANSSI for France, the BSI for Germany, the CSE for Canada, the NCO for Japan, and the ACN for Italy.

Seven signatures, one statement

The document is titled Preparing for the Post-Quantum Era: A Call to Action, and it is hosted in two places worth noting for what they represent rather than what they say: on cisa.gov, and on cyber.gouv.fr, the French national cyber agency's site. A joint publication mirrored on both a US and a French government domain is the format doing the arguing. Quantum risk is not being framed here as a national compliance exercise with seven separate flavors. It is being framed as one exercise that seven governments happen to be issuing at once.

  • Raise awareness. Quantum risk is still, in the document's own words, "off the radar for many organizations and not properly resourced."
  • Build national strategies. Each signatory commits to strategies that support PQC adoption and integration domestically.
  • Advance research and development. Continued investment in quantum-safe technologies, named as a shared priority rather than a national one.
  • Deepen public-private partnership. Expertise and resources shared across the government-industry line, not held inside either side.
  • Put PQC into procurement and security requirements. The priority with the most teeth, because it is the one a supplier feels first, in a tender document rather than a speech.

What is actually new here

Nothing in the five priorities is a novel idea. Every one of them already appears in NIST's guidance, in CISA's own PQC initiative, and in the national strategies several of these same agencies had already published on their own. Read the document for a new algorithm requirement, a new date, or a new mandate, and there is none to find.

The news is the signature block. A CISO who has been telling a board that post-quantum migration is a US federal concern, or a UK one, or a German one, loses that argument the day seven agencies sign the same sentence. A vendor selling into multiple jurisdictions loses the option of waiting to see which country moves first. The document does not raise the bar technically. It removes the excuse that quantum risk is any single government's idiosyncrasy.

What this changes for a migration plan

If your plan is already keyed to NIST IR 8547's 2030 and 2035 dates, or to the federal timeline in Executive Order 14412, this statement adds no new obligation to track. What it adds is leverage for the conversation that gets a migration funded in the first place, particularly at an organization that operates across the US, UK, EU, Canada and Japan and has been treating each jurisdiction's guidance as a separate, deferrable line item.

The fifth priority, procurement and security requirements, is the one to act on directly. It means a cryptographic bill of materials stops being an internal engineering artifact and starts being the answer to a question a customer or a regulator will ask across more than one of these seven jurisdictions at once. An organization that cannot produce one today is the organization this call to action is describing.

TL;DR

The point

A joint statement from seven cyber agencies sets no deadline of its own, and that is not the same as setting nothing. It converts post-quantum migration from a set of national compliance exercises, each arguable on its own timeline, into one shared statement that the transition is already overdue. Anyone still scoping a migration or an audit around a single jurisdiction's clock should read that as the signal to widen the plan, not wait for a sharper one.

References

Get started

Turn quantum risk into a credential.

Book a discovery call and get an indicative scope and pricing for your organisation.