United States (National Security Systems)

Commercial National Security Algorithm Suite (CNSA) 2.0

38 controls. 2 other frameworks in our corpus share controls with it. Here is all of it, and how much of it you are already doing.

Page built . This page is derived from the framework corpus, which changes when the corpus is extended rather than daily.

38 controls 2 frameworks share controls with it United States (National Security Systems) verified against its source document

Every control below is one this framework asks for. The right hand column counts how many other frameworks in our corpus carry the same control, which is the difference between doing this work once and doing it again for the next standard.

There is no implementation kit for this framework yet. The control list and the overlap above are free and complete.

What you already have

Frameworks whose controls overlap this one, most first. If you run any of them, the count is roughly what you have already evidenced.

Every control

CodeControlAlso in
CNSA2-CMVPFIPS 140-3 Validated Modules (CMVP)1
CNSA2-HASHHashing: SHA-384 or SHA-5121
CNSA2-HYBRIDHybrid and Dual-Algorithm Guidance0
CNSA2-INVENTORYCryptographic Inventory and Discovery2
CNSA2-KEMKey Establishment: ML-KEM-10242
CNSA2-NIAPNIAP Product Validation0
CNSA2-SIGDigital Signatures: ML-DSA-872
CNSA2-SWSIGSoftware/Firmware Signing: LMS or XMSS1
CNSA2-SYMSymmetric Encryption: AES-2562
CNSA2-TL-NETWORKTimeline: Networking Equipment0
CNSA2-TL-NSS-DEADLINEFinal NSS Migration Deadline0
CNSA2-TL-OSTimeline: Operating Systems0
CNSA2-TL-SWFWTimeline: Software and Firmware Signing0
CNSA2-TL-WEBCLOUDTimeline: Web/TLS and Cloud Services0
ALGThe suite: approved algorithms, parameters and what is not approved0
ALG-AESALG-AES AES-256 for symmetric encryption at all classification levels0
ALG-DSAALG-DSA ML-DSA-87 (FIPS 204) for digital signatures in any use case; HashML-DSA, FN-DSA and SLH-DSA are not approved0
ALG-HBSALG-HBS LMS or XMSS (SP 800-208) for software and firmware signing, with state managed and signing in hardware; HSS and XMSS-MT not allowed0
ALG-KEMALG-KEM ML-KEM-1024 (FIPS 203) for key establishment; Kyber variants that do not follow FIPS 203 are not compliant0
ALG-ONLYALG-ONLY No other public algorithms: unapproved algorithms need a waiver specific to algorithm, implementation and use case0
ALG-SHAALG-SHA SHA-384 or SHA-512 as the general-purpose hash; no SHA-3 or SHAKE for general use0
ALG-SHA3ALG-SHA3 SHA3-384 or SHA3-512 allowed only for internal hardware integrity processes0
CNSACNSA 2.0: what it is, under what authority, what is held and its status0
CNSA1CNSA 1.0 for comparison (advisory Table V)0
ENFEnforcement and reporting: authorizing officials, SC-12, NSM-10 and waivers0
ENF-FIELDEDENF-FIELDED Fielded NSS must be upgraded in a timely fashion or hold a waiver through the approved process0
ENF-REPORTENF-REPORT Authorizing officials report CNSA adoption and deviations under NSM-8 and NSM-10 while any component is not quantum-resistant0
ENF-SC12ENF-SC12 Measure compliance in the RMF at SC-12 as NSA-approved, never as FIPS-validated0
THREATThe threat, the choice of algorithms and the RFC guidance (advisory introduction; FAQ)0
TIMETransition timelines: CNSSP 15 dates, the per-technology schedule and NIAP Policy Letter 330
TIME-CNSSP15TIME-CNSSP15 CNSSP 15 dates: acquisitions compliant from 1 January 2027, non-capable equipment out by 31 December 2030, CNSA 2.0 mandated from 31 December 2031, all NSS quantum-res0
TIME-NIAP33TIME-NIAP33 NIAP Policy Letter 33: PQC contract language from 1 January 2027 and certification restrictions for products below CNSA 1.0 and CNSA 2.00
TIME-SIGNTIME-SIGN Software and firmware signing: transition immediately, new software signed with CNSA 2.0 by 2025, all deployed signatures CNSA 2.0 by 20300
TIME-TECHTIME-TECH The per-technology schedule of the 2022 advisory: support and prefer, then exclusively use0
VALValidation and product acceptance: NIAP, CAVP, CMVP and hardware-backed signing0
VAL-AGILEVAL-AGILE Cryptographic agility and prefer-then-require configuration through the transition0
VAL-NIAPVAL-NIAP Commercial products validated by NIAP against protection profiles that require CNSA 2.0; verification-only TOEs need CAVP not CMVP0
VAL-SIGNVAL-SIGN NSS signers use CMVP-validated hardware per SP 800-208 with no waiver; verifiers need CAVP-validated code0

Tell me when Commercial National Security Algorithm Suite (CNSA) 2.0 files something new

One email when a public company newly discloses something this framework governs, naming the company and what our corpus says it puts in scope. Nothing else, and one click to stop.

What this page is

A control-level reference for Commercial National Security Algorithm Suite (CNSA) 2.0, drawn from our framework corpus. Control codes and titles are references to the standard, not reproductions of it. The overlap counts and the auditor artefacts are our own work and are the part you will not find elsewhere.

Measure this against what you already run · All frameworks · Today's edition