CNSA 2.0: U.S. National Security Systems
Direct answerCNSA 2.0 is the NSA's required algorithm suite for U.S. National Security Systems. It mandates ML-KEM-1024, ML-DSA-87, LMS/XMSS for firmware signing, AES-256, and SHA-384/512, with a phased timeline that starts in 2025 and ends with exclusive post-quantum use by 2035. From 2027-01-01 all new NSS acquisitions must be CNSA 2.0 compliant.
- Issued by
- NSA (U.S. National Security Agency)
- Date
- 2022-09-07 (algorithm list updated 2025-05)
- Status
- In force
- Source
- https://media.defense.gov/2022/Sep/07/2003071834/-1/-1/0/CSA_CNSA_2.0_ALGORITHMS_.PDF
Milestones
- 2025Software and firmware signing, web browsers, servers, and cloud services: support and prefer CNSA 2.0
- 2026Traditional networking equipment (VPNs, routers): support and prefer CNSA 2.0
- 2027-01-01All new National Security System acquisitions must be CNSA 2.0 compliant
- 2030Software/firmware signing and networking equipment: exclusive CNSA 2.0 use
- 2033Operating systems, browsers, servers, cloud services, custom applications: exclusive CNSA 2.0 use
- 2035All National Security Systems quantum-resistant
Notes
- Required algorithms: ML-KEM-1024 (FIPS 203), ML-DSA-87 (FIPS 204), LMS and XMSS (SP 800-208) for firmware signing, AES-256, SHA-384 or SHA-512.
- Hybrid schemes are allowed for interoperability but the post-quantum component must be CNSA 2.0 compliant.
Algorithms this timeline points to
ML-KEM, ML-DSA, SLH-DSA, FN-DSA, HQC, LMS / HSS, XMSS / XMSS^MT
Who can help you meet it
Cryptography audit firms listed on this index: zkSecurity, Trail of Bits, NCC Group (Cryptography Services), Cryspen, Kudelski Security, Quarkslab, Least Authority, Galois, atsec information security, Riscure (Keysight), Cure53, X41 D-Sec. See the audit checklist for what a migration review covers.