G7 Tells Every Organization to Start PQC Migration – But the Procurement Signal Matters More Than the Headline
Table of Contents
3 Sep 2026 – On September 3, 2026, the G7 Cybersecurity Working Group published Preparing for the Post-Quantum Era: A Call to Action, urging governments and organizations across all sectors to begin transitioning to post-quantum cryptography. France’s national cybersecurity agency ANSSI led the working group under France’s 2026 G7 presidency.
The document was co-issued by the cybersecurity agencies of all seven member states: ANSSI (France), the Communications Security Establishment (Canada), the Federal Office for Information Security (Germany), Italy’s National Cybersecurity Agency, Japan’s National Cybersecurity Office, the UK’s National Cyber Security Centre, and the Cybersecurity and Infrastructure Security Agency (CISA) in the United States. The European Commission and ENISA participated as guests.
The working group called on organizations to reframe the quantum threat “from a distant future problem to a near-term threat that demands action across all sectors, not just critical infrastructure.” It described post-quantum cryptography as protection against both classical and quantum attacks, and stated that governments and organizations should begin their PQC transition “as soon as possible.”
Five priority areas
The document identified five areas for coordinated action:
- Raising awareness – framing the quantum threat as an economic and business risk extending beyond cryptography
- Developing national strategies – building both the supply of PQC hardware and software and the demand for adoption
- Research and development – funding pilot projects and testbeds
- Public-private partnerships – developing domestic expertise and sharing playbooks and case studies across sectors
- Integrating PQC into cybersecurity requirements – treating PQC adoption as an evolution of cryptographic best practices and introducing PQC requirements into public procurement
Harvest now, supply chain, and procurement
The working group stated that harvest-now-decrypt-later collection is already possible: adversaries can intercept and store encrypted data protected by public-key cryptography today. Where confidentiality must outlast the time required to develop a cryptographically relevant quantum computer – government records, trade secrets, and sensitive personal information – organizations “may already be exposed to the threat today.”
The document also addressed authentication, stating that attackers with access to CRQCs could “impersonate trusted entities, compromise equipment, forge trusted data, or access confidential data.”
On supply chains, the working group stated that “the vulnerabilities of one organization may expose other organizations and sectors to these risks” because authentication compromises enable lateral movement.
On procurement, the document contained what may be its sharpest sentence for enterprise readers: organizations delaying their PQC transition “may lose competitive advantage or may be excluded from contracting opportunities, including public procurement.”
Relationship to the earlier migration statement
The call to action builds on the G7 Cybersecurity Working Group Statement on Preparing for a Post-Quantum Cryptography Migration, negotiated under Canada’s 2025 G7 presidency and published June 1, 2026. That earlier document provided detailed technical recommendations: adopt a phased and risk-based strategy, inventory cryptographic assets, map dependencies, develop a transition plan, update procurement policies to require PQC, and purchase PQC-integrated products as part of standard renewal schedules. It also specified dedicated project teams, including an engagement team covering procurement, vendor risk, and supply chain governance.
My Analysis
The G7 Cybersecurity Working Group just told governments and organizations across all sectors to start migrating to post-quantum cryptography. A week of media coverage has duly noted this, mostly by restating the headline. Much of the crypto press framed the document as a warning about Bitcoin and exposed addresses, even though the text does not mention digital assets. Enterprise readers who actually need to act on this document get nothing useful from either approach – both omit the procurement, vendor relationship, and migration funding implications.
Three G7 documents, three different purposes
The G7 produced three PQC documents in 2026, from two different bodies. Much of the first-week coverage conflates them.
The G7 Cyber Expert Group’s financial-sector roadmap, published in January 2026, advises finance ministers and central bank governors. It orients critical financial systems toward migration in the 2030–2032 range, with 2035 as a broader reference point drawn from existing national guidance. The audience is regulators and financial institutions, and the document explicitly states that it does not set guidance or regulatory expectations. For financial institutions specifically: the September call to action adds supply chain and procurement framing but does not supersede the January roadmap’s sector-specific guidance.
The G7 Cybersecurity Working Group’s migration statement, negotiated under Canada’s 2025 presidency and published June 1, 2026, is the operational document. It gives technical leadership a detailed playbook: cryptographic inventories, dependency mapping, phased migration planning, dedicated project teams (including a vendor and supply chain engagement team), procurement policy updates, and contractual PQC requirements for cloud providers and tenders. It already frames PQC as a business risk and instructs organizations to designate a board member accountable for migration.
The September 3 call to action is the political document. It is addressed to decision-makers. It moves PQC urgency from a technical recommendation into a coordinated G7-level statement visible to boards, procurement functions, and national policymakers. It does not duplicate the migration statement’s operational detail. What it adds is a wider audience (“all sectors, not just critical infrastructure”), a sharper consequence for inaction (the procurement exclusion warning), and the collective weight of seven national cybersecurity agencies issuing a single message.
In sequence, the three documents show how the G7’s approach has evolved. January identified the risk and outlined planning, especially for finance. June gave operational migration detail, including vendor and procurement requirements. September extended the scope to every sector and warned that delays could cost procurement eligibility.
The procurement exclusion signal
The sentence on procurement exclusion is the one to brief upward: organizations that delay “may be excluded from contracting opportunities, including public procurement.”
This is not a mandate. The G7 Cybersecurity Working Group does not write procurement law. But it is a signal from the cybersecurity agencies that advise the governments that write procurement law. And the signal arrives in a year when the regulatory calendar is already filling in around it.
The EU’s Coordinated Implementation Roadmap expects member-state PQC strategies by the end of 2026 and high-risk use-case migration by 2030. The UK NCSC expects migration plans by 2028 and highest-priority migration by 2031. US Executive Order 14412, signed June 22, 2026, directed the FAR Council to publish a proposed rule – due by approximately mid-December 2026 – requiring covered federal contractors to comply with NIST FIPS, including PQC-compliant algorithms, by December 31, 2030.
And the agency that chaired this working group is already implementing the procurement recommendation domestically. ANSSI announced in June 2026 that it will stop certifying security products lacking PQC from 2027, and that French businesses should purchase only quantum-safe products by 2030. ANSSI certification is a prerequisite for products sold to French government agencies and critical infrastructure operators. The G7 procurement sentence is not hypothetical; the chair’s own agency has a date.
For an enterprise that sells to governments – defence contractors, IT service providers, cloud platforms, managed security vendors – these overlapping deadlines indicate where procurement requirements are heading within the next two to four years. Organizations that have not started a PQC migration program before those deadlines will be scrambling to qualify. Those already compliant will have a clear advantage. For suppliers further down the chain, the pressure is indirect but equivalent: if your customers face procurement requirements, so do your products. The vendor and supply chain governance question that enterprise programs keep deferring now coincides with deadlines already on the EU, UK, and US procurement calendars.
What the document does not say
What the call to action omits is as instructive as what it includes.
It sets no specific migration deadlines. The deadlines already exist – NIST IR 8547’s proposed deprecation trajectory (still an initial public draft: quantum-vulnerable algorithms deprecated after 2030, disallowed after 2035), the UK NCSC’s 2028–2031–2035 milestones, the EU roadmap, EO 14412 – and the G7 calls on organizations to complete their transitions within timelines already set by their national cybersecurity authorities. It adds no G7-level deadline and no specific algorithms – nor does the June migration statement – and both documents operate above the protocol stack. ML-KEM, ML-DSA, SLH-DSA, FN-DSA – none appear in either document. The specific algorithms, hybrid-versus-pure deployment questions, and crypto-agility positions are left to national authorities, which is the correct level for them.
The document also has no enforcement mechanism; it is a coordinated policy statement from cybersecurity agencies, distinct from a regulation, a directive, or a standard. Seven national cybersecurity agencies endorsed it, and the regulators drafting binding rules consult those agencies. Several of those rules are already in progress.
What this changes for enterprise programs
For organizations that already have a PQC program underway, the call to action changes very little operationally. The migration steps are the same ones the June statement outlined and that practitioners have been executing: inventory, prioritize, plan, pilot, deploy.
Three things are different after September 3.
First, the audience expanded. The June statement targeted “technical management of medium-to-large organizations.” The September document addresses all sectors and is aimed at decision-makers. An organization that justified deferring PQC because it was “not critical infrastructure” lost that argument when the G7 cybersecurity agencies collectively stated that the threat demands action across all sectors.
Second, the political weight increased. A CISO who has struggled to get PQC onto the board agenda now has a G7-level statement, co-issued by seven national cybersecurity agencies, that frames the quantum threat as “an economic and business risk, and not merely a cryptographic risk.” The June statement already made this argument in its governance section. The September document dedicates every page to that argument.
Third, the procurement exclusion warning is new. In June, the working group told organizations to update procurement policies; in September, it told them that failing to do so may cost them government contracts. That shifts the incentive from internal security improvement to external market access. Procurement teams and vendor risk functions that have not asked their suppliers about PQC readiness will start asking – not because they read this document, but because their auditors and the regulators advising their customers will.
Procurement planning
The G7’s call to action creates no new obligations and carries no regulatory force. But it is the clearest signal from the world’s major cybersecurity agencies that PQC migration is a business-level priority for every organization, not just those handling classified data or operating critical infrastructure. The procurement exclusion language previews where compliance requirements are heading. And the supply chain argument means that even organizations without direct government exposure will feel the pressure through their customers’ vendor assessments.
If you have a PQC migration program, this document is ammunition for your next budget conversation. If you don’t, the global migration clock has another entry, and your procurement eligibility may depend on catching up before binding rules are enforced.