France has put a date on the calendar. Starting in 2027, the country's security agency will refuse to certify any product that still leans on encryption a future quantum computer could eventually break. That is the substance of the reporting Decrypt published, and while it reads like a procurement footnote, it carries weight for anyone holding cryptographic keys. Bitcoin holders included.
The rationale officials offered is not about the machines that exist today. It is about the ones that do not exist yet, and about the data being copied right now in anticipation of them.
The threat that hasn't happened yet
Security researchers have a phrase for this: "harvest now, decrypt later." An adversary does not need a working quantum machine today to benefit from one in 2035. They need only to capture encrypted traffic or stolen ciphertext now and sit on it. When a sufficiently powerful quantum computer arrives, everything in that vault becomes readable in retrospect.
That reframes the entire problem. Encryption you would call safe today becomes a liability for data that has to stay secret for a decade or more: diplomatic cables, medical records, intellectual property, the contents of a long-term cold wallet. France's position, as the reporting lays it out, is essentially that a certification regime ought to stop blessing algorithms with a known expiration date.
The 2027 timing is not arbitrary. It gives vendors a runway. Most of the cryptography in question (RSA and elliptic-curve schemes) will not be torn out overnight. The plan is to phase in post-quantum standards alongside the existing ones, a belt-and-suspenders arrangement the cryptography community calls hybrid. You run the old and the new together, so that breaking one is not enough.
Let me state a view plainly, because it is worth stating: a government setting a hard certification cutoff is more useful than another conference panel about quantum risk. Deadlines force engineering. Vague warnings do not.
Why Bitcoin keeps coming up
Bitcoin gets dragged into every quantum conversation, and the reason is structural. The network relies on elliptic-curve digital signatures, specifically ECDSA, to prove that whoever spends a coin actually controls the private key behind it. A quantum computer running Shor's algorithm at scale could, in theory, derive a private key from its corresponding public key.
Here is where the nuance matters, and it does matter. Your public key is not always visible. In older pay-to-public-key-hash addresses, the public key is revealed on chain only when you spend from that address. So the exposure window is narrowest for coins that have never moved. Funds sitting in addresses whose public keys are already exposed, including a great many very old wallets and reused addresses, would be the first targets in any realistic attack scenario.
Estimates of how much Bitcoin sits in exposed addresses vary, but the figure runs into the millions of BTC across early P2PK outputs and reused keys. Satoshi's presumed holdings fall in that bucket. None of this is an emergency today. No quantum machine capable of the attack exists, and serious researchers put a fault-tolerant version that could threaten ECDSA years out, possibly more. But "years out" is precisely the horizon France is planning against.
The migration nobody can do quietly
Upgrading Bitcoin's cryptography is harder than upgrading a corporate server, and not for technical reasons alone. The protocol changes by rough consensus. A move to post-quantum signatures would require a soft fork or hard fork that node operators, miners, exchanges and wallet developers all coordinate around. Bitcoin has done this before, SegWit in 2017 and Taproot in 2021, but those took years of debate, and neither was as foundational as swapping out the signature scheme itself.
There are proposals already in circulation. Developers have floated schemes that would let holders move funds into quantum-resistant address types, and some have suggested setting a future block height after which old-style outputs could no longer be spent. That last idea is controversial for an obvious reason: it effectively threatens to freeze coins whose owners never migrate. Lose your keys, or simply go inactive, and you might find your stack stranded by a protocol upgrade designed to protect everyone else. The community has not resolved that hypothetical. It is a genuine fight waiting to happen.
Post-quantum signatures also tend to be larger than the elliptic-curve ones in use now. Lattice-based and hash-based schemes can produce signatures and keys measured in kilobytes rather than dozens of bytes. On a network that prices block space at a premium, that bloat has real consequences for fees and throughput. The cryptography that survives a quantum computer is heavier, and Bitcoin would have to absorb the weight.
So when a national authority commits to phasing out the vulnerable algorithms by 2027, it does two things at once for crypto. It validates the threat model some Bitcoiners have been dismissing as science fiction. And it sets a benchmark that makes the protocol's own indecision look more conspicuous by comparison.
France isn't moving alone
The French announcement sits inside a broader push that has been building for a couple of years. In August 2024, the US National Institute of Standards and Technology finalized its first post-quantum cryptography standards, publishing algorithms with names like ML-KEM and ML-DSA after a multi-year selection process. Those standards are the reference point most of the world is now building toward.
Governments have signaled urgency in different dialects. The US has its own migration guidance, pushing federal agencies to inventory vulnerable systems and begin swapping them out over the coming decade. Various European agencies have favored the hybrid approach, pairing classical and post-quantum schemes rather than betting everything on algorithms that are still relatively young and less battle-tested.
What France adds is teeth. A certification body that will not stamp non-compliant products changes vendor behavior in a way that recommendations do not. If you want to sell certified security gear into the French market after 2027, you build for the post-quantum era. That kind of market pressure tends to ripple outward, because vendors rarely maintain a separate product line for one jurisdiction.
Whether the 2027 date holds is a fair question. Regulatory deadlines slip. The hard part is not writing the rule, it is the migration underneath it, and large institutions are notoriously slow to rotate cryptography woven into legacy systems. But even a deadline that slips a year still pulls the whole timeline forward, compared with no deadline at all.
What to watch
The useful signal over the next 18 months will not come from price action. It will come from engineering roadmaps.
Watch whether major wallet providers begin shipping quantum-resistant address options, even experimental ones, ahead of any protocol-level change. Several have research underway. Watch the Bitcoin development mailing lists and proposal repositories for any post-quantum signature scheme that gains traction beyond a single author. As of now, no such proposal has anything close to consensus, which is itself worth noting.
Keep an eye on whether other certification regimes follow France's lead with cutoff dates of their own. One country setting a deadline is a policy. Three or four doing it is a market reality that hardware and software makers cannot route around.
And watch the quiet, less glamorous metric: how much old Bitcoin starts moving. If a credible quantum timeline ever firms up, you would expect long-dormant coins in exposed addresses to get swept into safer ones. A wave of movement from ancient wallets would be a tell that someone with information thinks the clock is shorter than the public estimates suggest. For now, those coins sit still, which tells you the people closest to the problem still think there is time.
The encryption protecting most of the digital world has an expiration date nobody can pin down precisely. France has decided to stop pretending otherwise. Bitcoin, for all its talk of being future-proof money, has not made the same call yet.