The G7 Cybersecurity Working Group, chaired this year by France’s national cyber agency ANSSI, published a joint call to action on September 3 urging governments and private-sector organizations to begin migrating to post-quantum cryptography now rather than treating the quantum threat as a future problem. The statement frames the shift bluntly: “the transition to post-quantum cryptography is a critical security issue that calls for a collective and coordinated effort,” and it builds on a 2025 statement Canada issued during its own G7 presidency, extending that groundwork into a five-priority action plan for member governments and industry.
The recommendations are procedural rather than technical: build an inventory of where cryptography is actually used across an organization’s systems, identify which of those systems are critical, map the dependencies between them, and develop a phased migration plan rather than a single cutover date. None of that is new advice in isolation. What is new is a G7-wide government body stating it collectively, which raises the likelihood that procurement requirements and regulatory expectations follow the same timeline in the countries that adopt it.
The original insight here is about sequencing, not urgency. Most quantum-readiness advice to date has focused on the threat itself, harvest-now-decrypt-later collection of encrypted traffic for future decryption once quantum computers mature. The G7 statement instead treats crypto-asset inventory as the actual bottleneck: organizations cannot migrate what they have not mapped, and most have never built that map for anything outside a compliance checklist. That inventory step, not algorithm selection, is where most security teams will lose the most time.
Related on CyberTech: a bipartisan Senate bill that would push the power grid toward quantum-readiness, and a look at Washington’s broader push to harden critical infrastructure supply chains.