CNSA2-CMVP | FIPS 140-3 Validated Modules (CMVP) | 1 |
CNSA2-HASH | Hashing: SHA-384 or SHA-512 | 1 |
CNSA2-HYBRID | Hybrid and Dual-Algorithm Guidance | 0 |
CNSA2-INVENTORY | Cryptographic Inventory and Discovery | 2 |
CNSA2-KEM | Key Establishment: ML-KEM-1024 | 2 |
CNSA2-NIAP | NIAP Product Validation | 0 |
CNSA2-SIG | Digital Signatures: ML-DSA-87 | 2 |
CNSA2-SWSIG | Software/Firmware Signing: LMS or XMSS | 1 |
CNSA2-SYM | Symmetric Encryption: AES-256 | 2 |
CNSA2-TL-NETWORK | Timeline: Networking Equipment | 0 |
CNSA2-TL-NSS-DEADLINE | Final NSS Migration Deadline | 0 |
CNSA2-TL-OS | Timeline: Operating Systems | 0 |
CNSA2-TL-SWFW | Timeline: Software and Firmware Signing | 0 |
CNSA2-TL-WEBCLOUD | Timeline: Web/TLS and Cloud Services | 0 |
ALG | The suite: approved algorithms, parameters and what is not approved | 0 |
ALG-AES | ALG-AES AES-256 for symmetric encryption at all classification levels | 0 |
ALG-DSA | ALG-DSA ML-DSA-87 (FIPS 204) for digital signatures in any use case; HashML-DSA, FN-DSA and SLH-DSA are not approved | 0 |
ALG-HBS | ALG-HBS LMS or XMSS (SP 800-208) for software and firmware signing, with state managed and signing in hardware; HSS and XMSS-MT not allowed | 0 |
ALG-KEM | ALG-KEM ML-KEM-1024 (FIPS 203) for key establishment; Kyber variants that do not follow FIPS 203 are not compliant | 0 |
ALG-ONLY | ALG-ONLY No other public algorithms: unapproved algorithms need a waiver specific to algorithm, implementation and use case | 0 |
ALG-SHA | ALG-SHA SHA-384 or SHA-512 as the general-purpose hash; no SHA-3 or SHAKE for general use | 0 |
ALG-SHA3 | ALG-SHA3 SHA3-384 or SHA3-512 allowed only for internal hardware integrity processes | 0 |
CNSA | CNSA 2.0: what it is, under what authority, what is held and its status | 0 |
CNSA1 | CNSA 1.0 for comparison (advisory Table V) | 0 |
ENF | Enforcement and reporting: authorizing officials, SC-12, NSM-10 and waivers | 0 |
ENF-FIELDED | ENF-FIELDED Fielded NSS must be upgraded in a timely fashion or hold a waiver through the approved process | 0 |
ENF-REPORT | ENF-REPORT Authorizing officials report CNSA adoption and deviations under NSM-8 and NSM-10 while any component is not quantum-resistant | 0 |
ENF-SC12 | ENF-SC12 Measure compliance in the RMF at SC-12 as NSA-approved, never as FIPS-validated | 0 |
THREAT | The threat, the choice of algorithms and the RFC guidance (advisory introduction; FAQ) | 0 |
TIME | Transition timelines: CNSSP 15 dates, the per-technology schedule and NIAP Policy Letter 33 | 0 |
TIME-CNSSP15 | TIME-CNSSP15 CNSSP 15 dates: acquisitions compliant from 1 January 2027, non-capable equipment out by 31 December 2030, CNSA 2.0 mandated from 31 December 2031, all NSS quantum-res | 0 |
TIME-NIAP33 | TIME-NIAP33 NIAP Policy Letter 33: PQC contract language from 1 January 2027 and certification restrictions for products below CNSA 1.0 and CNSA 2.0 | 0 |
TIME-SIGN | TIME-SIGN Software and firmware signing: transition immediately, new software signed with CNSA 2.0 by 2025, all deployed signatures CNSA 2.0 by 2030 | 0 |
TIME-TECH | TIME-TECH The per-technology schedule of the 2022 advisory: support and prefer, then exclusively use | 0 |
VAL | Validation and product acceptance: NIAP, CAVP, CMVP and hardware-backed signing | 0 |
VAL-AGILE | VAL-AGILE Cryptographic agility and prefer-then-require configuration through the transition | 0 |
VAL-NIAP | VAL-NIAP Commercial products validated by NIAP against protection profiles that require CNSA 2.0; verification-only TOEs need CAVP not CMVP | 0 |
VAL-SIGN | VAL-SIGN NSS signers use CMVP-validated hardware per SP 800-208 with no waiver; verifiers need CAVP-validated code | 0 |