{
  "slug": "cnsa-2-0",
  "name": "CNSA 2.0: U.S. National Security Systems",
  "body": "NSA (U.S. National Security Agency)",
  "date": "2022-09-07 (algorithm list updated 2025-05)",
  "status": "In force",
  "summary": "CNSA 2.0 is the NSA's required algorithm suite for U.S. National Security Systems. It mandates ML-KEM-1024, ML-DSA-87, LMS/XMSS for firmware signing, AES-256, and SHA-384/512, with a phased timeline that starts in 2025 and ends with exclusive post-quantum use by 2035. From 2027-01-01 all new NSS acquisitions must be CNSA 2.0 compliant.",
  "milestones": [
    [
      "2025",
      "Software and firmware signing, web browsers, servers, and cloud services: support and prefer CNSA 2.0"
    ],
    [
      "2026",
      "Traditional networking equipment (VPNs, routers): support and prefer CNSA 2.0"
    ],
    [
      "2027-01-01",
      "All new National Security System acquisitions must be CNSA 2.0 compliant"
    ],
    [
      "2030",
      "Software/firmware signing and networking equipment: exclusive CNSA 2.0 use"
    ],
    [
      "2033",
      "Operating systems, browsers, servers, cloud services, custom applications: exclusive CNSA 2.0 use"
    ],
    [
      "2035",
      "All National Security Systems quantum-resistant"
    ]
  ],
  "notes": [
    "Required algorithms: ML-KEM-1024 (FIPS 203), ML-DSA-87 (FIPS 204), LMS and XMSS (SP 800-208) for firmware signing, AES-256, SHA-384 or SHA-512.",
    "Hybrid schemes are allowed for interoperability but the post-quantum component must be CNSA 2.0 compliant."
  ],
  "url": "https://media.defense.gov/2022/Sep/07/2003071834/-1/-1/0/CSA_CNSA_2.0_ALGORITHMS_.PDF",
  "url_page": "https://pqaudit.org/timelines/cnsa-2-0/",
  "updated": "2026-09-12"
}