CNSA 2.0: U.S. National Security Systems: dates and requirements ================================================================ CNSA 2.0 is the NSA's required algorithm suite for U.S. National Security Systems. It mandates ML-KEM-1024, ML-DSA-87, LMS/XMSS for firmware signing, AES-256, and SHA-384/512, with a phased timeline that starts in 2025 and ends with exclusive post-quantum use by 2035. From 2027-01-01 all new NSS acquisitions must be CNSA 2.0 compliant. Issued by: NSA (U.S. National Security Agency) Date: 2022-09-07 (algorithm list updated 2025-05) Status: In force Milestones: 2025: Software and firmware signing, web browsers, servers, and cloud services: support and prefer CNSA 2.0 | 2026: Traditional networking equipment (VPNs, routers): support and prefer CNSA 2.0 | 2027-01-01: All new National Security System acquisitions must be CNSA 2.0 compliant | 2030: Software/firmware signing and networking equipment: exclusive CNSA 2.0 use | 2033: Operating systems, browsers, servers, cloud services, custom applications: exclusive CNSA 2.0 use | 2035: All National Security Systems quantum-resistant Source: https://media.defense.gov/2022/Sep/07/2003071834/-1/-1/0/CSA_CNSA_2.0_ALGORITHMS_.PDF Source page: https://pqaudit.org/timelines/cnsa-2-0/ Compiled by: PQC Audit Index editors (https://pqaudit.org/about/) Last reviewed: 2026-09-12