CNSA 2.0 And National Security Systems: What Suppliers Need To Know
US national security systems follow a separate post-quantum track run by NSA under CNSA 2.0, while other federal rules now reach contractors. Here is how the two tracks fit together for suppliers.
Checked against primary sources and independently reviewed on . Sources are listed at the end.
If you sell technology to the US government, you will hear two sets of post-quantum requirements mentioned in the same breath. One comes from the National Security Agency (NSA) and its Commercial National Security Algorithm Suite 2.0, known as CNSA 2.0. The other comes from the White House, the Office of Management and Budget (OMB), the Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology (NIST). They apply to different systems, and confusing them leads to wrong assumptions about dates.
This article explains how the two tracks divide, what is known about each as of October 2026, and how federal post-quantum policy is starting to reach contractors directly. It is written for vendors and suppliers rather than agencies.
Two Tracks: National Security Systems And Everything Else
US law treats national security systems as a separate category. The term is defined in federal statute (44 U.S.C. 3552(b)(6)), and Executive Order 14412 uses that definition.1 NSA describes these as networks that hold classified information or are otherwise critical to military and intelligence work, and your customer will know whether a system falls into the category. The Director of NSA is the National Manager for these systems and issues the guidance that governs their cryptography.2
Almost every civilian post-quantum instrument carves these systems out. The Quantum Computing Cybersecurity Preparedness Act states that it does not apply to any national security system.3 OMB’s 2022 inventory memo excluded them,4 and OMB’s June 2026 migration memo says it does not apply to them either.5 Executive Order 14412 directs OMB to require its 2030 and 2031 migration dates for federal high-value assets and high-impact systems, and the inventory review in its section 4(b)(i) expressly excludes national security systems.1
The result is two parallel tracks:
- Civilian federal systems follow OMB and CISA guidance, with NIST standards and the dates in Executive Order 14412 and OMB M-26-15.
- National security systems follow NSA requirements, including CNSA 2.0.
What CNSA 2.0 Is
CNSA 2.0 is NSA’s suite of algorithms for protecting national security systems against both classical and quantum attacks. NSA announced it on 7 September 2022 with a cybersecurity advisory and a frequently asked questions (FAQ) document, and based its choices on the algorithms NIST had selected for standardisation.2 The FAQ has since been updated: the version linked from NSA’s announcement in October 2026 is version 2.1, dated December 2024.6
The 2022 advisory set expectations by product type, using two stages: products should first support and prefer CNSA 2.0 algorithms, then use them exclusively. Software and firmware signing, for example, was to support and prefer CNSA 2.0 by 2025 and use it exclusively by 2030, while traditional networking equipment such as virtual private networks and routers had 2026 and 2030. The advisory also said NSA expects the transition for national security systems to be complete by 2035.7
The acquisition rules are firmer. NSA’s FAQ, citing the national security systems policy CNSSP 15, says that from 1 January 2027 new acquisitions for these systems must be CNSA 2.0 compliant unless otherwise noted, that equipment unable to support CNSA 2.0 must be phased out by 31 December 2030, and that CNSA 2.0 algorithms are mandated from 31 December 2031.6 NSA repeated the 2027 and 2030 points in an announcement on 1 October 2026.8 Suppliers should take dates for their own product type from NSA’s current documents, because procurement teams will hold them to NSA’s text.
Executive orders add some cross-cutting duties that also cover national security systems. Executive Order 14306 required NSA to set requirements for agencies running national security systems to support TLS 1.3 or a successor no later than 2 January 2030, matching OMB’s requirement for other federal systems.9 Executive Order 14412 requires NSA to report to the President within 180 days, and every year after, on the status of post-quantum migration across agencies that own or operate national security systems.1
How Federal Rules Reach Contractors
Beyond national security systems, 2026 also brought changes on the civilian side. Three of the procurement measures in Executive Order 14412 matter most to suppliers.1
First, the Federal Acquisition Regulatory Council must publish, within 180 days of 22 June 2026, a proposed amendment to the Federal Acquisition Regulation (FAR), the rulebook for federal purchasing, requiring covered contractors to comply with NIST’s Federal Information Processing Standards, including those for post-quantum algorithms, by 31 December 2030. Second, within 270 days, the Council must propose rules requiring contractor vulnerability disclosure programmes that accept reports of cryptographic weaknesses, including missing encryption and non-approved algorithms. Third, NIST must revise the Cryptographic Module Validation Program to speed up the validation of cryptographic modules.
OMB M-26-15 adds a buying signal. Agencies are told to use CISA’s list of product categories that support post-quantum standards and to require post-quantum support when they buy products in those categories.5 CISA’s list, published in January 2026, covers technologies such as cloud services, web software, networking hardware and software, and endpoint security.10
Which Track Applies To You
The flowchart below is a simple way to think about which set of requirements is most relevant to a product or service. The two tracks are not exclusive: a supplier to national security systems can also hold contracts that carry the federal acquisition clauses. It is a starting point for a conversation with your customers and counsel, not a legal determination.
Do you sell to US federal agencies, directly or as a subcontractor?
- Yes:
Is the product used in national security systems?
- Yes:
NSA Track Applies, And Contract Terms May Too Follow CNSA 2.0 and NSA requirements, including the 2027 acquisition rule, and take product-type dates from NSA publications. If your contracts include FAR clauses, the proposed FAR rule may apply as well.
- No:
Are you a contractor whose contracts include FAR clauses?
- Yes:
Watch The FAR Rule The proposed rule would require compliance with NIST post-quantum standards by 31 December 2030. Also check whether your product sits in a CISA post-quantum product category.
- No:
Civilian Procurement Track Agencies are told to require post-quantum support in CISA-listed product categories. Expect questions in purchasing.
- Yes:
- Yes:
- No:
Not Directly In Scope US federal rules do not bind you, though commercial customers may ask for similar evidence.
Practical Steps For Suppliers
A few actions make sense whichever track applies.
- Know your own cryptography. Customers will ask which algorithms, protocols and libraries your products use. An internal inventory, and in time a cryptographic bill of materials, is the basis for every answer.
- Map products to CISA categories. If a product falls into a listed category, expect buyers to ask about post-quantum support now.
- Plan for TLS 1.3. The 2 January 2030 date applies across federal systems, and products that cannot support TLS 1.3 will be hard to sell into them.
- Read the primary texts. Summaries of CNSA 2.0 dates circulate widely and do not always match NSA’s current documents, which have been updated since 2022.
- Upcoming
United States · The White House Binding
The FAR Council must publish, within 180 days of the order, a proposed rule that would require covered federal contractors to comply with NIST FIPS, including post-quantum algorithms, by 31 December 2030. The date shown is calculated by us as 180 days after 22 June 2026.
- Upcoming
United States · The White House Binding
Agencies must support TLS 1.3 or a successor version as soon as practicable, and no later than this date, under requirements that the order directed OMB (for other systems) and NSA (for national security systems) to issue; OMB M-26-15 restates the date.
- Upcoming
United States · The White House and Office of Management and Budget Binding
OMB guidance issued under the order must require agencies to move all high value assets and high impact systems to post-quantum key establishment by this date. M-26-15 plans this as its 2028 to 2030 migration phase.
- Upcoming
United States · The White House and Office of Management and Budget Binding
OMB guidance issued under the order must require agencies to move all high value assets and high impact systems to post-quantum digital signatures by this date. M-26-15 plans this as its 2031 migration phase.
Footnotes
-
The White House, “Executive Order 14412: Securing the Nation Against Advanced Cryptographic Attacks”, sections 2, 4, 5 and 6, 22 June 2026. govinfo.gov ↩ ↩2 ↩3 ↩4
-
National Security Agency, “NSA Releases Future Quantum-Resistant (QR) Algorithm Requirements for National Security Systems”, 7 September 2022. nsa.gov ↩ ↩2
-
US Congress, “Public Law 117-260: Quantum Computing Cybersecurity Preparedness Act”, section 5, 21 December 2022. govinfo.gov ↩
-
US Office of Management and Budget, “M-23-02: Migrating to Post-Quantum Cryptography”, 18 November 2022. whitehouse.gov ↩
-
US Office of Management and Budget, “M-26-15: Execution of the Migration to Post-Quantum Cryptography”, 24 June 2026. whitehouse.gov ↩ ↩2
-
National Security Agency, “The Commercial National Security Algorithm Suite 2.0 and Quantum Computing FAQ”, version 2.1, December 2024. media.defense.gov ↩ ↩2
-
National Security Agency, “Announcing the Commercial National Security Algorithm Suite 2.0”, cybersecurity advisory PP-22-1338, version 1.0, September 2022. media.defense.gov ↩
-
National Security Agency, “NSA Announces Post-Quantum Cryptography Measures to Safeguard National Security Systems Against Quantum Computing Threats”, 1 October 2026. nsa.gov ↩
-
The White House, “Executive Order 14306”, section 2(d), 6 June 2025. govinfo.gov ↩
-
CISA, “CISA Releases Product Categories List to Propel Post-Quantum Cryptography Adoption Pursuant to President Trump’s Executive Order 14306”, 23 January 2026. cisa.gov ↩
Knowledge Hub content is general information. It is not legal advice, a compliance certification, a guarantee of security or a substitute for an assessment of your own systems. Standards and rules change; check the sources for the latest position.