Skip to main content
Category: Cryptography & Encryption

Commercial National Security Algorithm Suite

Also known as: CNSA, CNSA Suite, CNSA 1.0, CNSA 2.0
Simply put

The Commercial National Security Algorithm Suite (CNSA) is a set of cryptographic algorithms selected by the U.S. National Security Agency (NSA) for protecting sensitive and classified data, such as secure communications and classified information exchange. It defines which encryption and authentication methods are approved for use on national security systems. A newer version, CNSA 2.0, updates these algorithms to include quantum-resistant options intended to withstand future attacks by quantum computers.

Formal definition

CNSA is a suite of cryptographic algorithms promulgated by the NSA to secure National Security Systems (NSS), covering functions such as encryption, key establishment, digital signatures, and hashing. The original suite (commonly referenced as CNSA 1.0) specified algorithms for classical cryptographic protection, while CNSA 2.0 is described in the evidence as the suite of quantum-resistant (QR) algorithms approved for NSS use, addressing the anticipated threat posed by cryptographically relevant quantum computers. As applied through profiles for protocols such as SSH, CNSA 2.0 designates specific algorithms and their functions, specifications, and applicable use cases. The evidence does not provide the complete algorithm list, transition timelines, or version-specific parameters; practitioners should confirm the current approved algorithms and migration requirements against the authoritative NSA CNSA 2.0 guidance and any protocol-specific profiles. Note that CNSA governs national security systems and is distinct from cryptographic requirements applicable to federal civilian or CUI-bearing systems under other authorities.

Why it matters

CNSA defines the cryptographic algorithms the NSA has approved for protecting National Security Systems (NSS), so it directly governs which encryption, key establishment, digital signature, and hashing methods are permissible for securing classified and other sensitive national security data. For organizations that build, operate, or supply components for NSS, using algorithms outside the approved suite can mean a system does not meet baseline cryptographic requirements, regardless of how otherwise robust its security posture may be. This makes CNSA a foundational reference point rather than an optional best practice for the systems it covers.

The significance of CNSA has increased with the introduction of CNSA 2.0, which the evidence describes as the suite of quantum-resistant (QR) algorithms approved for NSS use. The motivation is the anticipated threat posed by cryptographically relevant quantum computers, which could undermine classical public-key cryptography. Because migration to quantum-resistant algorithms is a substantial engineering effort that touches protocols, hardware, and long-lived data, planning against CNSA 2.0 guidance is a forward-looking concern for programs whose data must remain protected well into the future.

A common and consequential mistake is assuming CNSA requirements apply uniformly across all federal systems. CNSA governs national security systems and is distinct from the cryptographic requirements applicable to federal civilian systems or CUI-bearing systems under other authorities. Equally important, the evidence provided here does not include the complete algorithm list, specific transition timelines, or version-specific parameters; treating any secondhand summary as authoritative is risky, and practitioners should confirm current approved algorithms and migration requirements against official NSA CNSA 2.0 guidance and any protocol-specific profiles.

Who it's relevant to

National Security System owners and authorizing officials
Organizations that own or authorize National Security Systems must ensure the cryptography deployed aligns with the NSA-approved CNSA suite for the relevant functions. CNSA governs NSS specifically and is distinct from cryptographic requirements applicable to federal civilian or CUI-bearing systems under other authorities, so scope should be confirmed before applying it.
Defense and NSS contractors and product vendors
Suppliers building encryption, communications, or authentication capabilities intended for national security use need to confirm their products implement CNSA-approved algorithms, including planning for CNSA 2.0 quantum-resistant algorithms where applicable. The complete algorithm list and version-specific parameters should be verified against authoritative NSA CNSA 2.0 guidance rather than secondhand summaries.
Cryptographic engineers and protocol implementers
Engineers integrating cryptography into protocols such as SSH should reference the applicable CNSA 2.0 profiles, which designate specific algorithms and their functions and use cases within a given protocol. Because transition timelines and parameters are not fully captured in summary form, implementers should track the current protocol-specific profiles and NSA guidance directly.
Security and migration planners preparing for quantum-resistant transitions
Teams responsible for long-term data protection and post-quantum readiness should treat CNSA 2.0 as the reference for quantum-resistant algorithms approved for NSS use, given the anticipated threat from cryptographically relevant quantum computers. Migration is a substantial effort, and specific timelines and requirements must be confirmed against official NSA CNSA 2.0 guidance.

Inside CNSA

Purpose and Scope
The Commercial National Security Algorithm Suite (CNSA) is a set of cryptographic algorithms selected by the National Security Agency (NSA) for use in protecting National Security Systems (NSS). It is intended to guide the selection of commercially available cryptography for systems that handle classified and other national security information, and its scope is generally distinct from the FIPS-validated cryptography emphasized for federal civilian systems under FISMA.
Issuing Authority
CNSA is maintained and published by the NSA, acting in its role over National Security Systems, rather than by NIST. Practitioners should not conflate CNSA guidance with the NIST-issued standards (such as the FIPS series) that anchor much of federal civilian and DoD RMF cryptographic implementation, though the underlying algorithms may overlap in some cases.
Algorithm Categories
CNSA generally addresses categories of cryptographic function such as symmetric encryption, hashing, digital signatures, and key establishment. The specific algorithms and parameter sizes designated within each category are defined in the current NSA-published suite, which the reader should verify against the applicable authoritative version rather than assuming a fixed list.
Applicability to National Security Systems
CNSA is oriented toward NSS and classified or national security contexts. Its applicability to a given system depends on that system's categorization and the governing authority; civilian agency systems under FISMA and many CUI-focused requirements follow their own cryptographic guidance, which may differ from CNSA.
Evolving Guidance and Successor Direction
NSA cryptographic guidance evolves over time, including direction toward algorithms intended to address future threats. The specific suite designated as current, and any successor or revised guidance, should be confirmed against NSA's current authoritative publications rather than treated as static.

Common questions

Answers to the questions practitioners most commonly ask about CNSA.

Is CNSA the same thing as NSA's Suite B cryptography?
No. CNSA is the successor to Suite B and should not be treated as interchangeable with it. The National Security Agency announced CNSA in part to move away from the Suite B framing and to signal a transition path toward quantum-resistant cryptography. While there is overlap in the classes of algorithms involved, referring to current requirements as 'Suite B' is outdated; you should verify the applicable CNSA version and its specified algorithms and parameters against current NSA guidance.
Does using CNSA-approved algorithms mean my system is approved to protect classified national security information?
Not by itself. CNSA specifies algorithms and parameters intended for protecting national security systems, but algorithm selection is only one element. Approval to protect classified information depends on the full authorization process for national security systems, including appropriate keying material, certified implementations, and applicable NSA and system-owner requirements. Compliance with a cryptographic suite is not equivalent to authorization, and you should confirm the specific requirements with the responsible authority.
Which version of CNSA applies to my system, and how do I confirm it?
CNSA has been issued in more than one version as NSA advances its quantum-readiness objectives, so the applicable algorithms and parameters depend on which version governs your system. Rather than assuming a particular set of algorithms, identify the version referenced by your governing guidance or system owner and verify the current authoritative text from NSA, because the specified algorithms and required parameters may change across revisions.
Does CNSA apply to my system if it does not handle classified national security information?
CNSA is oriented toward national security systems and the protection of national security information. Federal civilian systems under FISMA and many CUI-focused requirements generally look to NIST cryptographic standards and validation programs rather than to CNSA directly. Before applying CNSA to a system outside the national security space, confirm whether your governing authority actually requires it, as scope boundaries differ across defense, civilian, and national security contexts.
How does CNSA relate to NIST-approved cryptography and FIPS validation?
CNSA and NIST cryptographic guidance address overlapping algorithm families but serve different authorities and audiences, with CNSA focused on national security systems. Meeting CNSA does not automatically satisfy a FIPS validation requirement, and a FIPS-validated module does not automatically meet CNSA specifications. Where both apply, treat them as separate requirements to be confirmed independently against current NSA and NIST sources.
What should implementers plan for regarding CNSA and the transition toward quantum-resistant cryptography?
A stated purpose of CNSA is to prepare national security systems for a transition to quantum-resistant cryptography. Implementers should generally plan for cryptographic agility so that algorithms and parameters can be updated as newer CNSA versions are issued, and should avoid assuming that a current configuration will remain compliant indefinitely. Verify the specific migration timelines and required algorithms with current NSA guidance, as these details evolve across revisions.

Common misconceptions

CNSA and NIST cryptographic standards are the same thing and can be used interchangeably.
CNSA is issued by the NSA for National Security Systems, whereas the NIST FIPS and SP series guide much of federal civilian and DoD RMF cryptography. While algorithms may overlap, the issuing authorities, scope, and intended systems differ, and practitioners should not assume one automatically satisfies obligations tied to the other.
Meeting CNSA requirements is required for all federal or DoD systems.
CNSA is oriented toward National Security Systems and national security or classified contexts. Whether it applies to a given system depends on that system's categorization and governing authority; many civilian FISMA systems and CUI-focused environments follow different cryptographic guidance.
The CNSA algorithm list is fixed and does not need to be rechecked.
NSA cryptographic guidance evolves, including revisions and direction toward algorithms addressing future threats. The current designated suite, its parameters, and any successor guidance should be verified against NSA's current authoritative publications.

Best practices

Confirm whether the system in question is a National Security System before assuming CNSA applies, since applicability depends on the system's categorization and governing authority.
Verify the specific algorithms and parameter sizes against the current NSA-published CNSA guidance rather than relying on a remembered or fixed list.
Distinguish CNSA (issued by NSA for NSS) from NIST-issued FIPS and SP cryptographic standards, and do not assume compliance with one satisfies obligations under the other.
Track NSA updates and any successor or revised cryptographic direction, treating the designated suite as subject to change over time.
For civilian FISMA systems or CUI-focused environments, confirm the applicable cryptographic requirements separately, as they may differ from CNSA.
Consult the current authoritative NSA publications and coordinate with the responsible authorizing authority before making implementation or procurement decisions based on CNSA.