PQC Audit IndexLast reviewed 2026-09-12

CNSA 2.0: U.S. National Security Systems

Direct answerCNSA 2.0 is the NSA's required algorithm suite for U.S. National Security Systems. It mandates ML-KEM-1024, ML-DSA-87, LMS/XMSS for firmware signing, AES-256, and SHA-384/512, with a phased timeline that starts in 2025 and ends with exclusive post-quantum use by 2035. From 2027-01-01 all new NSS acquisitions must be CNSA 2.0 compliant.
Issued by
NSA (U.S. National Security Agency)
Date
2022-09-07 (algorithm list updated 2025-05)
Status
In force
Source
https://media.defense.gov/2022/Sep/07/2003071834/-1/-1/0/CSA_CNSA_2.0_ALGORITHMS_.PDF

Milestones

Notes

Algorithms this timeline points to

ML-KEM, ML-DSA, SLH-DSA, FN-DSA, HQC, LMS / HSS, XMSS / XMSS^MT

Who can help you meet it

Cryptography audit firms listed on this index: zkSecurity, Trail of Bits, NCC Group (Cryptography Services), Cryspen, Kudelski Security, Quarkslab, Least Authority, Galois, atsec information security, Riscure (Keysight), Cure53, X41 D-Sec. See the audit checklist for what a migration review covers.