Fintech Regulatory Brief
The G7 Just Warned That Delaying PQC Could Cost You Government Contracts
September 12, 2026 · PQCClear · 6 minute read
On September 3, all seven G7 cybersecurity agencies co-signed a document urging every organization, not just critical infrastructure, to start post-quantum migration. Most coverage stopped at that headline. The sentence worth actually planning around is further down the page.
The G7 Cybersecurity Working Group, led by France’s ANSSI under its 2026 G7 presidency, published Preparing for the Post-Quantum Era: A Call to Action on September 3, co-issued by the cybersecurity agencies of all seven member states, with the European Commission and ENISA joining as guests. The framing was direct: the quantum threat should shift from a distant future problem to a near-term threat that demands action across all sectors.
There Are Three G7 Documents Here, Not One
Coverage of this announcement has largely treated it as a single, standalone event. It isn’t. It is the third of three related G7 documents published in 2026, from two different working groups, each serving a distinct purpose. Getting these straight matters for anyone trying to work out what actually applies to them.
January 2026
The financial-sector roadmap
G7 Cyber Expert Group, co-chaired by Treasury and the Bank of England. Orients critical financial systems toward 2030 to 2032. Explicitly non-regulatory, aimed at finance ministers and central bank governors.
June 1, 2026
The operational statement
G7 Cybersecurity Working Group, under Canada's 2025 presidency. The technical playbook: inventories, dependency mapping, phased plans, a named vendor and supply chain engagement team, procurement policy updates.
September 3, 2026
The call to action
G7 Cybersecurity Working Group, under France's 2026 presidency. The political document, widened to every sector, and the one carrying the procurement exclusion warning.
Each does something different. January gave the financial sector a technical planning target with no regulatory force, and it is the document the new Treasury Quantum-Readiness Task Force builds directly on. June gave technical leadership an operational playbook, including that first explicit mention of a dedicated vendor and supply chain engagement function. September took the same underlying urgency and made it a political statement, addressed to boards and procurement functions rather than to technical teams alone.
The Sentence Worth Reading Twice
Buried in the September document’s procurement section is what may be its most consequential line for any organization that sells to, or through, institutions with government exposure:
…may lose competitive advantage or may be excluded from contracting opportunities, including public procurement.
G7 Cybersecurity Working Group, Preparing for the Post-Quantum Era: A Call to Action, September 3, 2026.
This is not a mandate. The working group does not write procurement law, and the document itself sets no binding deadline and names no specific algorithm. But it is a signal from the cybersecurity agencies that advise the governments who do write that law, and it lands in a year where the regulatory calendar is already filling in around it.
This Isn't Hypothetical. The Dates Already Exist.
| Date | Milestone | What it sets |
|---|---|---|
| ~Dec 2026 | US FAR Council proposed rule due | Directed by Executive Order 14412, requiring covered federal contractors to comply with NIST FIPS, including PQC algorithms. |
| End of 2026 | EU member-state PQC strategies | The Coordinated Implementation Roadmap expects national strategies by the end of the year, with high-risk use-case migration by 2030. |
| 2027 onward | ANSSI stops certifying non-PQC products | The agency chairing this working group already has its own domestic deadline. ANSSI certification is a prerequisite for products sold to French government agencies and critical infrastructure operators. |
| 2028 / 2031 | UK NCSC milestones | Migration plans expected by 2028, and the highest-priority systems migrated by 2031. |
| 2030 | France: quantum-safe products only | ANSSI's stated expectation for French businesses generally, not just for government suppliers. |
| Dec 31, 2030 | US federal contractor deadline | The date the FAR Council rule is expected to set for covered contractors under EO 14412. |
None of these deadlines were created by the September document. They were already on the calendar. What the Call to Action adds is the collective weight of seven national cybersecurity agencies stating, in one voice, that these deadlines are converging on a real, near-term procurement consequence rather than a distant compliance exercise.
Why This Reaches Past Government Contractors
The document also addresses supply chains directly, stating that the vulnerabilities of one organization can expose other organizations and sectors, since authentication compromises enable lateral movement across connected systems. The practical consequence for anyone not selling to government directly: the pressure does not stop at the prime contractor.
If your customers face procurement requirements, so do your products.
That is the mechanism worth internalizing. A bank facing vendor-assessment expectations from its own examiners creates exactly the same downward pressure on its vendors that a government prime contractor creates on its suppliers. Procurement teams and vendor risk functions that have not asked their suppliers about PQC readiness will start asking, and increasingly not because they read this specific document, but because their own auditors and the regulators advising their customers will expect an answer.
What This Means Practically
- 01
Treat 2027 to 2030 as a real planning window if your institution sells to government, or your vendors do. It is not a distant reference point. ANSSI, the FAR Council, and the EU roadmap all place real dates inside it.
- 02
Start asking vendors about PQC readiness ahead of your own auditors asking you. The document's own logic is that this pressure cascades downward through supply chains, whether or not any single vendor sells to government directly.
- 03
Use the procurement exclusion language as budget ammunition. “We could lose contracting eligibility” is a sharper, more board-ready argument than a general reference to quantum risk.
Get ahead of the vendor questions your auditors will start asking
PQCClear helps banks, credit unions, and payment processors assess the quantum readiness of every fintech vendor in their portfolio, producing a Quantum Readiness Score, a full CBOM, and an examination-ready report for each one, before procurement requirements make it mandatory.
Request accessThis post represents the editorial analysis of PQCClear as of September 12, 2026. It should not be construed as legal advice. Organizations should consult legal counsel and compliance advisors regarding their specific procurement obligations.
Key sources: G7 Cybersecurity Working Group, “Preparing for the Post-Quantum Era: A Call to Action” (cyber.gouv.fr, September 3, 2026); G7 Cybersecurity Working Group, migration statement (cyber.gc.ca, June 1, 2026); G7 Cyber Expert Group, financial-sector roadmap (home.treasury.gov, January 2026); Marin Ivezic, “G7 Tells Every Organization to Start PQC Migration,” PostQuantum.com (September 4, 2026), whose analysis of the procurement exclusion signal and the three-document structure informed this piece; Executive Order 14412 (whitehouse.gov, June 22, 2026).