In this scientific and technical opinion, ANSSI summarizes the different aspects and challenges of the quantum threat on current cryptographic systems. After a brief overview of contexte of this threat, this document introduces a provisional planning for migration to post-quantum cryptography, ie resistant to the attacks that the emergence of large quantum computers would make possible.

The goal is to anticipating this threat while avoiding any regression in the resistance to attacks achievable by means of current conventional computers. This notice aims to provide guidance to manufacturers developing security products and to describe the impacts of this migration on obtaining security visas issued by ANSSI.

Document structure What is a quantum computer? Quantum threat: what would be the impact on current digital infrastructures? Quantum threat: the case of symmetric cryptography Why should the quantum threat be taken into account today? Could quantum key distribution be a solution? What is post-quantum cryptography? What are the different post-quantum algorithms? What is France's involvement in the face of the quantum threat? Will future NIST standards be mature enough