Commercial National Security Algorithm Suite 2.0
CNSA 2.0 is an updated set of cryptographic algorithms selected by the National Security Agency (NSA) to protect national security systems and information. It is designed to be quantum-resistant, meaning the algorithms are intended to withstand attacks from future quantum computers that could break some cryptography in use today. It updates the earlier Commercial National Security Algorithm Suite by incorporating quantum-resistant (QR) algorithms.
CNSA 2.0 is the suite of quantum-resistant (QR) cryptographic algorithms approved by the NSA for use on National Security Systems (NSS), used in operations such as secure communications, classified information exchange, and authentication. According to NSA guidance, the suite specifies approved algorithms along with their functions and specifications, and includes timelines for adoption, for example, guidance indicating that new software and firmware use CNSA 2.0 signing algorithms by 2025. As the successor to the original CNSA Suite, CNSA 2.0 is scoped to systems protecting national security information rather than general federal civilian systems; practitioners should note that adoption timelines and algorithm specifications are set by the NSA and should be verified against the current authoritative NSA publications, as guidance in this area continues to evolve.
Why it matters
The cryptography that protects much of today's sensitive communications relies on mathematical problems that are computationally infeasible for classical computers to solve. A sufficiently capable quantum computer could, in the future, break certain public-key algorithms in widespread use, exposing data that adversaries may be collecting and storing now to decrypt later. CNSA 2.0 matters because it represents the NSA's designated path toward quantum-resistant (QR) cryptography for the systems that protect national security information, addressing a threat that is anticipated rather than merely theoretical from a planning standpoint.
For organizations operating National Security Systems (NSS), CNSA 2.0 is significant because it establishes not only approved algorithms but also adoption expectations that are tied to timelines. NSA guidance indicates, for example, that new software and firmware are expected to use CNSA 2.0 signing algorithms by 2025. Because cryptographic transitions are slow and touch hardware, firmware, and software across long-lived defense systems, understanding these timelines early is essential to avoid procurement and integration bottlenecks.
Practitioners should treat CNSA 2.0 as guidance scoped specifically to national security systems rather than a blanket requirement for federal civilian systems, and should recognize that this area continues to evolve. Algorithm specifications and adoption timelines are set by the NSA and should be verified against current authoritative NSA publications rather than relied upon from secondary summaries.
Who it's relevant to
Inside CNSA 2.0
Common questions
Answers to the questions practitioners most commonly ask about CNSA 2.0.