Skip to main content
Category: Cryptography & Encryption

Commercial National Security Algorithm Suite 2.0

Also known as: CNSA 2.0, CNSA Suite 2.0
Simply put

CNSA 2.0 is an updated set of cryptographic algorithms selected by the National Security Agency (NSA) to protect national security systems and information. It is designed to be quantum-resistant, meaning the algorithms are intended to withstand attacks from future quantum computers that could break some cryptography in use today. It updates the earlier Commercial National Security Algorithm Suite by incorporating quantum-resistant (QR) algorithms.

Formal definition

CNSA 2.0 is the suite of quantum-resistant (QR) cryptographic algorithms approved by the NSA for use on National Security Systems (NSS), used in operations such as secure communications, classified information exchange, and authentication. According to NSA guidance, the suite specifies approved algorithms along with their functions and specifications, and includes timelines for adoption, for example, guidance indicating that new software and firmware use CNSA 2.0 signing algorithms by 2025. As the successor to the original CNSA Suite, CNSA 2.0 is scoped to systems protecting national security information rather than general federal civilian systems; practitioners should note that adoption timelines and algorithm specifications are set by the NSA and should be verified against the current authoritative NSA publications, as guidance in this area continues to evolve.

Why it matters

The cryptography that protects much of today's sensitive communications relies on mathematical problems that are computationally infeasible for classical computers to solve. A sufficiently capable quantum computer could, in the future, break certain public-key algorithms in widespread use, exposing data that adversaries may be collecting and storing now to decrypt later. CNSA 2.0 matters because it represents the NSA's designated path toward quantum-resistant (QR) cryptography for the systems that protect national security information, addressing a threat that is anticipated rather than merely theoretical from a planning standpoint.

For organizations operating National Security Systems (NSS), CNSA 2.0 is significant because it establishes not only approved algorithms but also adoption expectations that are tied to timelines. NSA guidance indicates, for example, that new software and firmware are expected to use CNSA 2.0 signing algorithms by 2025. Because cryptographic transitions are slow and touch hardware, firmware, and software across long-lived defense systems, understanding these timelines early is essential to avoid procurement and integration bottlenecks.

Practitioners should treat CNSA 2.0 as guidance scoped specifically to national security systems rather than a blanket requirement for federal civilian systems, and should recognize that this area continues to evolve. Algorithm specifications and adoption timelines are set by the NSA and should be verified against current authoritative NSA publications rather than relied upon from secondary summaries.

Who it's relevant to

National Security System owners and operators
Organizations that operate National Security Systems are the primary audience for CNSA 2.0, since the suite is scoped to systems that protect national security information rather than general federal civilian systems. These owners and operators need to understand which QR algorithms are approved and how adoption timelines apply to their systems.
Defense product and firmware vendors
Vendors developing software and firmware for defense and national security applications are directly affected by CNSA 2.0 adoption expectations, including guidance indicating that new software and firmware use CNSA 2.0 signing algorithms by 2025. Because cryptographic changes touch long-lived hardware and firmware, these vendors should verify current NSA specifications when planning product roadmaps.
Cryptographic and security engineers
Engineers responsible for implementing secure communications, classified information exchange, and authentication in national security contexts need CNSA 2.0's approved algorithms, functions, and specifications to design quantum-resistant systems. They should treat NSA publications as the authoritative source, since specifications and timelines in this area continue to evolve.
Compliance and program management staff supporting NSS
Compliance officers and program managers overseeing systems that protect national security information use CNSA 2.0 guidance to track adoption timelines and confirm that approved algorithms are in place. Because guidance is maintained by the NSA and continues to change, these staff should verify requirements against current authoritative NSA publications rather than secondary summaries.

Inside CNSA 2.0

Commercial National Security Algorithm Suite 2.0
CNSA 2.0 is the algorithm suite issued by the National Security Agency (NSA) that specifies cryptographic algorithms approved for protecting National Security Systems (NSS). It represents the successor to CNSA 1.0 and is oriented toward quantum-resistant (post-quantum) cryptography. Applicability is generally limited to NSS and their operators, and readers should verify current scope against the governing NSA guidance.
Post-Quantum Cryptography (PQC) Focus
A central element of CNSA 2.0 is the transition toward cryptographic algorithms designed to resist attacks from cryptographically relevant quantum computers. This distinguishes it from CNSA 1.0, which relied on classical public-key algorithms considered vulnerable to future quantum attack. Specific algorithm selections should be confirmed against the current authoritative NSA text.
Issuing Authority and Scope
CNSA 2.0 is maintained by the NSA and applies primarily to National Security Systems rather than to federal civilian systems governed under FISMA or to CUI protection requirements. It is a distinct authority from NIST's post-quantum cryptography standardization work, though the two efforts are related; practitioners should not treat NSA guidance and NIST publications as interchangeable.
Transition Timelines
CNSA 2.0 is generally associated with a phased set of timelines encouraging or requiring adoption of quantum-resistant algorithms across different technology categories. Because specific dates and milestones are subject to revision, the reader should verify current effective timelines against the applicable NSA source rather than relying on any fixed figure.
Relationship to CNSA 1.0
CNSA 2.0 supersedes and updates the earlier CNSA 1.0 suite. The two should not be conflated: CNSA 1.0 defines the earlier set of approved classical algorithms, while CNSA 2.0 shifts emphasis toward post-quantum resistance. Coexistence and migration expectations between the two may apply during transition periods.

Common questions

Answers to the questions practitioners most commonly ask about CNSA 2.0.

Is CNSA 2.0 the same as CNSA 1.0 with new algorithm choices?
No. CNSA 2.0 is a distinct suite that reorients cryptographic requirements toward quantum-resistant (post-quantum) algorithms, whereas the earlier suite is centered on classical public-key algorithms that are considered vulnerable to a future cryptographically relevant quantum computer. Treating them as interchangeable is a common mistake; the two suites reflect different threat assumptions and specify different algorithm families. Confirm the current algorithm requirements and any transition expectations against the authoritative NSA guidance, as details may evolve across updates.
Does CNSA 2.0 apply to all federal systems, including civilian agency and general CUI systems under FISMA?
Not automatically. CNSA is guidance associated with national security systems (NSS), and its applicability is scoped accordingly rather than being a general FISMA baseline for civilian agency systems or ordinary CUI environments. Requirements for federal civilian systems and for CUI protection generally derive from separate authorities and control sets, and post-quantum migration guidance for those environments may come through different channels. Readers should verify whether their system is designated an NSS and confirm the governing requirements against the applicable authoritative sources.
Where do we begin when preparing our systems for CNSA 2.0 alignment?
A common practical starting point is developing a cryptographic inventory that identifies where and how public-key and other affected cryptography is used across systems, products, and communications. This inventory generally supports later prioritization and migration planning. This entry does not prescribe a specific tooling or methodology; confirm inventory and migration expectations against current NSA guidance and your authorizing official's direction, and note that approaches may differ by system and mission.
How does CNSA 2.0 relate to the post-quantum standards being developed elsewhere?
CNSA 2.0 references quantum-resistant cryptography, and its implementation is generally expected to align with standardized post-quantum algorithms. Standardization and profiling of specific algorithms occur through separate processes, so the precise algorithms, parameters, and standards referenced may be updated over time. This entry does not fix particular algorithm identifiers; verify the exact algorithms, standards, and any conformance requirements against the current authoritative publications before making implementation decisions.
What should acquisition and vendor management teams consider regarding CNSA 2.0?
In many implementations, organizations address post-quantum readiness through procurement by asking vendors about support for quantum-resistant algorithms and their migration roadmaps for products and services. The specific contractual language, timelines, and any mandated requirements are outside the scope of this entry and depend on the governing authorities and your contracting terms. Confirm whether and how CNSA 2.0-related expectations flow down to suppliers with your contracting and security authorities, as these details are subject to change.
How should we handle the transition period while systems still rely on classical cryptography?
Migration to quantum-resistant cryptography is generally treated as a phased effort rather than an instantaneous switch, so organizations often maintain interim protections and plan for cryptographic agility so algorithms can be updated as guidance matures. This entry does not specify transition deadlines or milestones; any effective dates, sequencing, or mandatory timelines should be verified against the current NSA guidance and coordinated with your authorizing official. Note also that a completed migration does not by itself constitute authorization or continuous monitoring obligations, which remain governed by the applicable process.

Common misconceptions

CNSA 2.0 applies broadly to all federal systems and to CUI protection.
CNSA 2.0 is issued by the NSA and generally applies to National Security Systems, not to federal civilian systems under FISMA or to CUI safeguarding requirements. Those environments follow other authorities, and applicability should be confirmed against the governing guidance for the specific system category.
CNSA 2.0 and NIST's post-quantum cryptography standards are the same thing.
CNSA 2.0 is maintained by the NSA for NSS, while NIST conducts its own post-quantum cryptography standardization. Although the efforts are related and may reference overlapping algorithm families, they are distinct authorities with distinct scopes and should not be treated as interchangeable.
Adopting a quantum-resistant algorithm from CNSA 2.0 is a one-time configuration change.
Migration to post-quantum cryptography is generally a phased, ongoing process involving inventory, planning, and validation across systems. Compliance with an algorithm selection is not equivalent to achieving a fully secure or fully migrated posture, and transition timelines are subject to revision.

Best practices

Confirm whether the systems in question qualify as National Security Systems before applying CNSA 2.0, since its scope generally does not extend to FISMA civilian systems or CUI-only environments.
Consult the current authoritative NSA guidance for CNSA 2.0 to verify approved algorithms and transition timelines, rather than relying on prior versions or third-party summaries that may be outdated.
Distinguish CNSA 2.0 obligations from NIST post-quantum cryptography standardization work, and document which authority governs each requirement to avoid conflating the two.
Build and maintain a cryptographic inventory to identify where classical CNSA 1.0-era algorithms are in use and to plan a phased migration toward quantum-resistant algorithms.
Treat post-quantum migration as an ongoing program with defined milestones rather than a single configuration change, and verify effective dates against the applicable governing text.
Coordinate migration planning with authorizing officials and continuous monitoring processes, recognizing that adopting an approved algorithm supports but does not by itself constitute a complete security or authorization outcome.