STANDARDS
CNSA 2.0's phased deadlines for National Security Systems
The NSA's Commercial National Security Algorithm Suite 2.0 sets concrete dates for migrating National Security Systems to post-quantum algorithms. It mandates ML-KEM for key exchange and ML-DSA for digital signatures, starting with new acquisitions in January 2027 and reaching full compliance by December 2031, with earlier milestones for specific equipment categories.
Check a domain →
CNSA 2.0 (Commercial National Security Algorithm Suite 2.0) is the National Security Agency‘s set of cryptographic requirements for National Security Systems. It mandates a phased transition to post-quantum algorithms starting January 1, 2027, and requires ML-KEM for key exchange and ML-DSA for digital signatures. Full compliance is required by December 31, 2031.
What is CNSA 2.0?
CNSA 2.0 is the NSA’s updated cryptographic standard for systems handling U.S. national security information. It replaces the original CNSA suite and specifically mandates two NIST-standardized post-quantum algorithms: ML-KEM (FIPS 203) for key exchange, and ML-DSA (FIPS 204) for digital signatures. Note that SLH-DSA (FIPS 205), NIST’s third post-quantum standard, is not currently approved under CNSA 2.0.
What are the CNSA 2.0 deadlines?
Date
Requirement
January 1, 2027
New National Security System acquisitions must be CNSA 2.0 compliant
2030
Software and firmware signing, traditional networking equipment must transition
December 31, 2030
Equipment and services that can't support PQC and CNSA must be phased out
December 31, 2031
Full use of CNSA 2.0 algorithms required
2033
Web browsers and servers, cloud services, operating systems, niche devices, large PKI, custom applications, and legacy equipment must transition
These dates also appear, alongside every other Standards date, on the PQC Compliance Timeline, the single maintained source for the full chronology.
Does CNSA 2.0 apply to my organization?
CNSA 2.0 directly applies to systems processing National Security Information and National Security Systems. It’s increasingly relevant to federal contractors and suppliers more broadly, since agencies are expected to cascade similar requirements down their supply chain. A June 2026 Department of War strategy calls for adding PQC requirements to CMMC, with a December 31, 2031 deadline for DoW systems specifically. See Federal PQC Requirements for how that’s playing out.
Why doesn't CNSA 2.0 approve SLH-DSA?
NIST standardized three post-quantum algorithms in August 2024: ML-KEM (FIPS 203), ML-DSA (FIPS 204), and SLH-DSA (FIPS 205). SLH-DSA is positioned as a structurally different backup in case ML-DSA is later found vulnerable. CNSA 2.0 currently only mandates ML-KEM and ML-DSA. That doesn’t mean SLH-DSA is discouraged, only that it isn’t a current CNSA 2.0 requirement. See NIST PQC Standards for how all three fit together.
Wondering if your systems are CNSA 2.0 ready?
Written by the team behind Anvil Secure.