Quantum-Safe Encryption: Monaco 2027
Compliance·6 min read·4 September 2026

Quantum-Safe Encryption: Monaco 2027

France's ANSSI stops certifying non quantum-safe products in 2027. What Monaco businesses should inventory now, and what to ask suppliers before 2030.

There is no working quantum computer capable of breaking the encryption your website uses today. There may not be one for a decade. The deadlines, however, have already started landing — which is the part most business owners have not registered.

Nothing here requires a purchase this month. But the first hard date is a year out, and the work that makes it painless is not the kind you can do in a hurry.

The date that arrives first

France's cybersecurity agency, ANSSI, has said it will stop awarding its security certifications to products lacking quantum-resistant encryption from 2027. Its position beyond that is blunter still: organisations should be buying only quantum-safe products by 2030.

That is a procurement rule, not a criminal offence, and it applies to French certification rather than to Monaco. But certification is how security products get sold into regulated sectors, so the effect flows downstream: vendors re-engineer to keep the label, and the version that reaches you a year later is already updated.

The European timeline runs alongside it. The EU's coordinated roadmap, published in June 2025 by the NIS Cooperation Group, asks member states to have national strategies and cryptographic inventories underway by the end of 2026, high-risk critical systems migrated by 2030, and everything else by 2035.

Note what that first milestone asks for: an inventory. Not new hardware. A list of where encryption lives in your business.

Why anyone is in a hurry at all

The reason to act before the machine exists is a problem with an inelegant name: harvest now, decrypt later.

Encrypted traffic can be intercepted and stored today, then decrypted years from now when the capability arrives. So the question is not "when will quantum computers work?" but "how long does this data need to stay confidential?" For most marketing sites the honest answer is: not long.

For a good number of Monaco businesses the answer is different. Client wealth structures, family office records, legal correspondence, medical data, M&A material, the ownership documents behind property and vessel transactions — much of that is expected to stay private for twenty or thirty years. If it crossed the network in 2026 and someone kept a copy, the protection it has is the protection it had when it was sent. Firms handling private wealth work sit squarely there.

That is the entire argument for starting early, and it is a narrow one: it covers long-lived secrets, not your restaurant's booking form.

Where Monaco actually stands

Monaco is not an EU member state, and the EU roadmap is not Monegasque law. We are not aware of a published Monegasque post-quantum deadline, and nothing here should be read as one — if this matters to your risk file, verify the position with the relevant authorities or your own counsel.

What does apply is the general duty. Law No. 1.565 of 3 December 2024 requires controllers to secure personal data with measures appropriate to the risk, under the supervision of the APDP. "Appropriate" is a moving standard by design: it tracks the state of the art. An algorithm that is unremarkable in 2026 and deprecated by 2032 does not stay appropriate because it was fine on the day you deployed it. The mapping behind data protection compliance is, conveniently, most of the inventory work below.

The other route in is commercial. Monaco businesses sell to French and EU clients, bank with institutions inside those regimes, and buy from suppliers certified under them. Procurement questionnaires are where it shows up first.

Start with an inventory, not a purchase

The most useful thing to do in the next six months costs nothing but attention: write down where cryptography lives in your business.

  • Public-facing: TLS certificates on your website, subdomains, APIs and mail servers
  • Access: VPNs, SSH keys, single sign-on, password managers, admin credentials
  • Data at rest: backups, archives, anything encrypted and retained for years
  • Integrations: payment gateways, CRM connections, e-signature tools, client portals
  • Ownership: which of these you control, and which belong to a vendor

For a typical Monaco SME this is an afternoon and a spreadsheet. It converts a vague anxiety into a short list of owners and renewal dates — exactly what any future audit or client questionnaire will ask for.

Questions worth putting to your suppliers

You will not implement post-quantum cryptography yourself; almost all of it arrives inside products you already pay for. The practical lever is the question you ask at renewal:

  • Do you support hybrid post-quantum key exchange today, and on which services?
  • What is your migration timeline for the standardised algorithms — ML-KEM, ML-DSA, SLH-DSA?
  • Will this be delivered as a platform update, or will it require us to re-platform?

Ask your hosting provider, your CDN, your payment provider and your CMS vendor. A supplier with a clear answer is telling you something useful; one with no answer is telling you something too.

One caution: the standards bodies favour hybrid deployments — a post-quantum algorithm paired with a classical one — so treat "we replaced everything" as a claim to examine. And be sceptical of anything sold to a small business as quantum-proof at a premium.

The reassuring part

A meaningful share of this is already happening without you. Hybrid post-quantum key exchange has been shipping in mainstream browsers and major CDN and cloud platforms since 2024. If your site sits behind a modern platform with current TLS, a good deal of your public traffic may already be protected against harvest-now-decrypt-later attacks. Shortening certificate lifetimes helps too: short-lived certificates get replaced often enough to absorb algorithm changes quietly.

Which points at the real lesson. The businesses that handle this smoothly will not be the ones that bought something early. They will be the ones whose systems are maintained — current platform versions, no abandoned plugins, no server nobody has logged into since 2021. Crypto-agility is mostly just good website maintenance: the discipline that keeps a build patched is what makes an algorithm swap routine rather than a rebuild. If a TLS change frightens your stack, that is the finding — and it argues for modern web development long before it argues about quantum computing.

What to do before the end of 2026

Make the inventory. Identify which of your data has a confidentiality life measured in decades, and treat only that as urgent. Add the three supplier questions to your next renewal conversations. Get your platform current and keep it there. That is a proportionate response to a real but slow-moving risk, and it leaves you with a maintained estate whether or not the timeline holds.

Not sure what your hosting stack supports? Get in touch — we will walk your site and its integrations with you and say plainly what needs attention and what does not.

cybersecurityencryptioncompliancemonaco
BSS Digital Agency

BSS Digital Agency

Digital agency based in Monaco. Web, apps, AI, marketing.

Get in touch