PlatformPlatform architectureProduct tourProduct graphRisk intelligenceContinuous governanceEvidence & auditDeploymentIntegrationsExecutive view
BOM SuiteSBOMCBOMQBOMAIBOMHBOMBOM Governance
SolutionsSecurityComplianceSupply chain riskQuantum readinessAI governanceDigital trust
ComplianceCERT-InRBISEBI / CSCRFMeitYNISTEU CRAEU AI ActCERT-In SBOM guide
IndustriesBanking & Financial ServicesGovernment & Public SectorDefence & Critical InfrastructureHealthcareIndian enterprises
ResourcesResource centreSBOM resourcesCBOM resourcesQBOM resourcesAIBOM resourcesHBOM resourcesProgramme & regulationBlog
CompanyAboutSecurity & trustContact
Request a DemoTalk to an expert
Compliance3 min readReviewed September 20265 sources

CNSA 2.0 algorithms and timeline

The NSA's Commercial National Security Algorithm Suite 2.0 is the most specific post-quantum timeline in force. It binds U.S. national security systems, and it shapes the products their vendors sell worldwide.

Key takeaways
  • CNSA 2.0 specifies ML-KEM-1024, ML-DSA-87, LMS or XMSS for software and firmware signing, AES-256 and SHA-384 or SHA-512.
  • From 1 January 2027, new acquisitions for national security systems are required to be CNSA 2.0 compliant unless otherwise noted.
  • Category deadlines run from 2030 for software and firmware signing and networking equipment to 2033 for browsers, servers, operating systems and legacy.
  • NSA intends all national security systems to be quantum-resistant by 2035.
  • NSA does not require hybrid schemes for security and does not generally consider QKD practical for these systems.

What CNSA 2.0 is

The Commercial National Security Algorithm Suite 2.0 is the NSA's set of approved algorithms for U.S. national security systems (NSS), announced in September 2022 and updated after NIST finalised its post-quantum standards [1]. NSA's FAQ states that it intends all NSS to be quantum-resistant by 2035, in line with the goal of National Security Memorandum 10 [2]. NSM-10, signed on 4 May 2022, directs U.S. government agencies to migrate vulnerable cryptographic systems to quantum-resistant cryptography [3].

The algorithms

FunctionCNSA 2.0 algorithmStandard
Key establishmentML-KEM-1024FIPS 203
Digital signaturesML-DSA-87FIPS 204
Software and firmware signingLMS or XMSS (stateful hash-based)NIST SP 800-208
Symmetric encryptionAES-256FIPS 197
HashingSHA-384 or SHA-512FIPS 180-4

Sources: NSA advisory [1]; summary [4]. NSA's FAQ recommends LMS with SHA-256/192 for firmware signing and requires validated implementations for NSS signers [2].

Category timeline

CategorySupport and prefer byExclusively use by
Software and firmware signing20252030
Web browsers, servers and cloud services20252033
Traditional networking equipment (for example VPNs, routers)20262030
Operating systems20272033
Niche equipment (constrained devices)20302033
Custom applications and legacy equipmentUpdate or replace2033

Sources: NSA advisory [1]; summary [4].

Acquisition and enforcement dates

NSA's FAQ (version 2.1, December 2024) adds dates that matter for procurement [2]:

  • NSS validated against a NIAP or CSfC profile remain approved for the life of that validation, and no transition requirement is enforced before 31 December 2025.
  • By 1 January 2027, all new acquisitions for NSS will be required to be CNSA 2.0 compliant unless otherwise noted.
  • By 31 December 2030, equipment and services that cannot support CNSA 2.0 must be phased out unless otherwise noted.
  • By 31 December 2031, CNSA 2.0 algorithms are mandated for use unless otherwise noted.

Positions worth knowing

  • Hybrid. NSA has confidence in standalone CNSA 2.0 algorithms and does not require hybrid solutions for security, though interoperability may require them in limited cases [2]. This differs from some other agencies' guidance.
  • QKD. NSA does not generally consider quantum key distribution a practical security solution for protecting NSS [2].

Who should care outside the U.S.

CNSA 2.0 applies to U.S. national security systems, but vendors that sell to them build products to its requirements. Suppliers in India and elsewhere that serve U.S. defence customers will see the 2027 acquisition date in contracts. Others can use CNSA 2.0 as a reference for the strictest parameter choices.

The dates are also stricter than NIST's draft transition timeline in places. NIST IR 8547 proposes disallowing quantum-vulnerable algorithms after 2035 [5], while CNSA 2.0 expects exclusive use of quantum-resistant algorithms for signing and networking equipment by 2030. Where both apply, plan to the CNSA 2.0 date. A side-by-side view is in post-quantum compliance timelines.

Mapping CNSA 2.0 into a QBOM

  1. Tag each asset with its CNSA 2.0 category (signing, networking, operating system and so on).
  2. Check the parameter set, not just the algorithm: ML-KEM-768 or ML-DSA-65 does not meet CNSA 2.0 (see NIST PQC standards).
  3. Set the category's exclusive-use year as the due date, and flag any supplier roadmap that misses it.
  4. For firmware signing, link the signing key to the devices that trust it through the HBOM.

How IntelliXBOM helps

IntelliXBOM maps cryptographic and hardware inventory to framework controls, including CNSA 2.0, and produces timestamped evidence of compliance status. It correlates algorithms and parameter sets with the software, firmware and devices that use them, and keeps version history as categories migrate. This article summarises public guidance and is not legal advice; confirm requirements with NSA and your contracting authority.

Frequently asked questions

What algorithms does CNSA 2.0 require?

ML-KEM-1024 for key establishment, ML-DSA-87 for signatures, LMS or XMSS for software and firmware signing, AES-256 for symmetric encryption and SHA-384 or SHA-512 for hashing.

When must new national security system purchases be CNSA 2.0 compliant?

NSA's FAQ states that by 1 January 2027 all new acquisitions for national security systems will be required to be CNSA 2.0 compliant unless otherwise noted.

Does CNSA 2.0 require hybrid cryptography?

No. NSA says it has confidence in the standalone CNSA 2.0 algorithms and will not require hybrids for security, although interoperability may make them necessary in limited cases.

Sources

  1. Announcing the Commercial National Security Algorithm Suite 2.0NSA Cybersecurity Advisorymedia.defense.gov/2025/May/30/2003728741/-1/-1/0/CSA_CNSA_2.0_ALGORITHMS.PDF
  2. The Commercial National Security Algorithm Suite 2.0 and Quantum Computing FAQ (Ver. 2.1, December 2024)NSAmedia.defense.gov/2022/Sep/07/2003071836/-1/-1/0/CSI_CNSA_2.0_FAQ_.PDF
  3. President Biden Signs Memo to Combat Quantum Computing Threat (NSM-10, 4 May 2022)NSAwww.nsa.gov/Press-Room/News-Highlights/Article/Article/3020175/president-biden-signs-memo-to-combat-quantum-computing-threat/
  4. CNSA 2.0: Complete Guide to NSA's PQC RequirementsPostQuantum.compostquantum.com/cnsa-2-0/complete-guide/
  5. NIST IR 8547 (Initial Public Draft), Transition to Post-Quantum Cryptography Standards (November 2024)NISTnvlpubs.nist.gov/nistpubs/ir/2024/NIST.IR.8547.ipd.pdf

Sources checked in September 2026. Regulations and guidance change; always refer to the issuing body’s current publication. This content is for general information and is not legal advice.

Related QBOM guides

Across the BOM Suite

Put your QBOM under governance.Quantum readiness with continuous correlation and timestamped evidence.