NSA CNSA 2.0 - Commercial National Security Algorithm Suite (Post-Quantum)
Description
Maps a project’s cryptographic inventory to the NSA CNSA 2.0 timeline for national security systems: post-quantum algorithms are to be the default by 2030 and the exclusive option by 2033, with hybrid classical+PQC constructions not approved for NSS.
Rationale
CNSA 2.0 is the NSA’s mandated suite for national security systems. Unlike hybrid-friendly civilian roadmaps it requires pure post-quantum algorithms, so the same Shor-broken inventory is judged against a stricter timeline and hybrid posture.
Benefits
Vendors and operators of national security systems get early, auditable evidence of which cryptographic assets fall outside CNSA 2.0 and by when they must be replaced with pure PQC.
CNSA 2.0 — Cryptographic Inventory Established
ID |
cnsa_2_0_pqc/crypto_inventory_established |
Severity |
high |
Category |
cryptography/post_quantum |
Optional |
false |
Tags |
cnsa-2.0, crypto, inventory, pqc |
Description
Checks that a cryptographic inventory (a CBOM) has been established for the project as the basis for the CNSA 2.0 post-quantum migration.
Rationale
Migrating national security systems to CNSA 2.0 requires first knowing which cryptographic algorithms are in use. Without an inventory the migration cannot be planned, scoped or audited.
CNSA 2.0 — No Quantum-Vulnerable Cryptography
ID |
cnsa_2_0_pqc/no_quantum_vulnerable_crypto |
Severity |
high |
Category |
cryptography/post_quantum |
Optional |
false |
Tags |
cnsa-2.0, crypto, pqc, quantum |
Description
Checks the project’s cryptographic inventory for quantum-vulnerable (Shor-broken) public-key cryptography and evaluates it against the NSA CNSA 2.0 timeline for national security systems: CNSA 2.0 algorithms default by 2030, exclusive by 2033.
Rationale
For national security systems the NSA requires migration to pure post-quantum algorithms; classical public-key cryptography must be retired on the CNSA 2.0 schedule and hybrid constructions are not an approved end state.