Commercial National Security Algorithm Suite
The Commercial National Security Algorithm Suite (CNSA) is a set of cryptographic algorithms selected by the U.S. National Security Agency (NSA) for protecting sensitive and classified data, such as secure communications and classified information exchange. It defines which encryption and authentication methods are approved for use on national security systems. A newer version, CNSA 2.0, updates these algorithms to include quantum-resistant options intended to withstand future attacks by quantum computers.
CNSA is a suite of cryptographic algorithms promulgated by the NSA to secure National Security Systems (NSS), covering functions such as encryption, key establishment, digital signatures, and hashing. The original suite (commonly referenced as CNSA 1.0) specified algorithms for classical cryptographic protection, while CNSA 2.0 is described in the evidence as the suite of quantum-resistant (QR) algorithms approved for NSS use, addressing the anticipated threat posed by cryptographically relevant quantum computers. As applied through profiles for protocols such as SSH, CNSA 2.0 designates specific algorithms and their functions, specifications, and applicable use cases. The evidence does not provide the complete algorithm list, transition timelines, or version-specific parameters; practitioners should confirm the current approved algorithms and migration requirements against the authoritative NSA CNSA 2.0 guidance and any protocol-specific profiles. Note that CNSA governs national security systems and is distinct from cryptographic requirements applicable to federal civilian or CUI-bearing systems under other authorities.
Why it matters
CNSA defines the cryptographic algorithms the NSA has approved for protecting National Security Systems (NSS), so it directly governs which encryption, key establishment, digital signature, and hashing methods are permissible for securing classified and other sensitive national security data. For organizations that build, operate, or supply components for NSS, using algorithms outside the approved suite can mean a system does not meet baseline cryptographic requirements, regardless of how otherwise robust its security posture may be. This makes CNSA a foundational reference point rather than an optional best practice for the systems it covers.
The significance of CNSA has increased with the introduction of CNSA 2.0, which the evidence describes as the suite of quantum-resistant (QR) algorithms approved for NSS use. The motivation is the anticipated threat posed by cryptographically relevant quantum computers, which could undermine classical public-key cryptography. Because migration to quantum-resistant algorithms is a substantial engineering effort that touches protocols, hardware, and long-lived data, planning against CNSA 2.0 guidance is a forward-looking concern for programs whose data must remain protected well into the future.
A common and consequential mistake is assuming CNSA requirements apply uniformly across all federal systems. CNSA governs national security systems and is distinct from the cryptographic requirements applicable to federal civilian systems or CUI-bearing systems under other authorities. Equally important, the evidence provided here does not include the complete algorithm list, specific transition timelines, or version-specific parameters; treating any secondhand summary as authoritative is risky, and practitioners should confirm current approved algorithms and migration requirements against official NSA CNSA 2.0 guidance and any protocol-specific profiles.
Who it's relevant to
Inside CNSA
Common questions
Answers to the questions practitioners most commonly ask about CNSA.