NSA CNSA 2.0: Post-Quantum Readiness
MOD is tracking NSA Commercial National Security Algorithm (CNSA) 2.0 requirements for post-quantum cryptography. This page describes what MOD supports today and the roadmap to adopting post-quantum algorithms as validated cryptographic modules become available.
Important: MOD does not provide, claim, or validate compliance with CNSA 2.0. This page describes algorithms MOD supports for cryptographic operations, not a compliance or certification status.
What MOD Supports Today
Classical Algorithms (Approved Through 2030–2033)
MOD supports the following classical (pre-quantum) algorithms, which remain approved for use through at least 2030:
| Algorithm | What It Does | Status |
|---|---|---|
| AES-256 | Symmetric encryption (data at rest and in transit) | Supported today |
| SHA-384 / SHA-512 | Cryptographic hashing | Supported today |
| RSA-3072+ | Asymmetric encryption and signatures | Supported today |
| ECDH P-384 | Elliptic curve key agreement | Supported today |
| ECDSA P-384 | Elliptic curve digital signatures | Supported today |
| Ed25519 | Modern elliptic curve signatures (FIPS 186-5) | Supported today |
These algorithms will remain available and supported through the transition period to post-quantum cryptography. For web and cloud services (MOD's category), NSA's exclusive PQC migration deadline is 2033.
Post-Quantum Algorithms (Not Yet Available)
MOD does not yet support the following post-quantum algorithms. We are waiting for FIPS 140-3 validated cryptographic modules to become available before adopting them:
| Algorithm | Purpose | NSA Preferred By | Exclusive Use By |
|---|---|---|---|
| ML-KEM-1024 (Kyber) | Key establishment (replaces RSA/ECDH) | 2025 | 2033 |
| ML-DSA-87 (Dilithium) | Digital signatures (replaces RSA/ECDSA) | 2025 | 2033 |
| LMS / XMSS | Hash-based signatures (firmware/software signing) | 2025 | 2030 |
Why not yet? NIST is currently validating these algorithms under the FIPS 140-3 program. MOD will not adopt post-quantum algorithms until a validated cryptographic module is available (e.g., an OpenSSL 3.x FIPS provider or a Go standard library module validated by NIST). Adoption before validation would introduce untested code into production; validation after deployment is the practical path.
Adoption Timeline
Phase 1: Readiness
Starts when: Internal decision to begin post-quantum integration planning.
- Monitor NIST/FIPS 140-3 validation status of OpenSSL and Go post-quantum modules.
- No code changes; MOD continues using classical algorithms.
- This documentation is updated quarterly as validation progresses.
Phase 2: Preparation
Starts when: A FIPS 140-3 validated cryptographic module (OpenSSL 3.x FIPS provider, Go stdlib, or UBI image) includes ML-KEM-1024 and ML-DSA-87.
- Integrate ML-KEM-1024 and ML-DSA-87 into Python and Go cryptographic libraries.
- Add support for hybrid key exchange (classical + post-quantum) in optional stacks.
- Internal testing and security review.
Phase 3: Adoption
Starts when: Post-quantum dependencies are validated and our signing tooling (e.g., cosign) supports ML-DSA-87 signatures.
- Release post-quantum-enabled worker distributions.
- Add platform settings to prefer post-quantum algorithms in new deployments.
- Provide guidance to customers on PQC adoption.
Phase 4: Classical-only end of support
Starts when: NSA's exclusive-use deadline approaches for web/cloud services (2033 per NSA timeline).
- Announce end-of-support date for classical-only deployments.
- Require post-quantum support in all new production builds.
- Maintain hybrid mode (classical + post-quantum) for backward compatibility.
For Your Compliance Program
If your organization requires CNSA 2.0 compliance:
-
For the 2025 NSA preference milestone: MOD will support post-quantum algorithms once validated FIPS 140-3 modules are available. No action needed from you until Phase 2 begins.
-
For the 2033 NSA exclusive-use deadline: MOD will transition classical algorithms to hybrid or post-quantum mode. You will have advance notice (12+ months) before classical-only deployments reach end of support.
-
Mixed deployments: MOD will support hybrid encryption (classical + post-quantum) to ensure backward compatibility and graceful transition during the adoption period.
See Also
- FIPS mode at install — FIPS-approved cryptography setup and limitations.
- Crypto inventory — Detailed listing of all cryptographic algorithms used in MOD.
- NSA Commercial National Security Algorithm Suite 2.0 — NSA's official CNSA 2.0 document.
- NIST FIPS 140-3 — Cryptographic Module Validation Program.