- Key Takeaways
- Who Is Actually in Scope
- The Approved Algorithm Suite
- The Timeline, Category by Category
- NIAP Validation Is Not the Same as FIPS Validation
- Why the Validation Backlog Is the Real Deadline
- What Shows Up in Procurement Language and RFPs
- How CNSA 2.0 Relates to CMMC
- A Practical Evidence Checklist
- What We'd Actually Recommend
- How Encryption Consulting Can Help
- The Deadline That Actually Constrains You
- Frequently Asked Questions
Quick answer: CNSA 2.0 compliance for defense contractors runs on two tracks that most vendors underestimate: the NSA’s algorithm and timeline requirements (ML-KEM-1024 and ML-DSA-87, with a January 1, 2027 acquisition gate), and the validation infrastructure behind them (NIAP Protection Profile validation plus CMVP/FIPS 140-3 certification, both carrying multi-month to multi-year queues). A contractor that starts validation work after an RFP lands is already too late for the 2027 gate. This guide covers who is in scope, what “compliant” actually requires as evidence, and how the timeline interacts with CMMC.
Every defense contractor conversation about post-quantum cryptography eventually collapses into one question: what do we actually have to prove, to whom, and by when. CNSA 2.0 answers the algorithm question clearly, and our general CNSA 2.0 overview covers the full algorithm suite and NSA transition timeline in depth. It is far less clear, in most vendor and prime-contractor planning, what compliance means procedurally, how validation timelines interact with the acquisition gate, and how CNSA 2.0 relates to the other compliance programs, like CMMC, that defense contractors are simultaneously tracking.
This guide is written for the compliance, engineering, and program leads inside prime contractors and their suppliers who need to convert CNSA 2.0 from a policy document into an evidence package.
Key Takeaways
- CNSA 2.0 requires ML-KEM-1024 for key establishment and ML-DSA-87 for signatures, with a January 1, 2027 acquisition gate for new National Security System procurements.
- Compliance is not self-attested. It runs through NIAP Protection Profile validation and CMVP (FIPS 140-3) certification, both administered independently of each other.
- The requirement cascades through the supply chain: prime contractors, sub-tier suppliers, and any commercial vendor whose component ends up in an NSS environment are all in scope.
- CMVP validation has averaged more than 500 days from submission to an active certificate, which makes the practical deadline for starting validation work mid-2026 at the latest for the 2027 gate.
- CMMC and CNSA 2.0 are separate programs administered by different parts of the Department of War and the NSA. The Department’s July 2026 suspension of CMMC Phase II does not change the CNSA 2.0 timeline.
Who Is Actually in Scope
CNSA 2.0 is formally mandatory for National Security Systems, the systems that handle classified information or support military, defense, and intelligence functions. It is not, by itself, a binding legal requirement on the general commercial sector. That distinction matters less in practice than it sounds, because the requirement cascades.
- Federal agencies and the military services operating NSS are the primary bound parties, governed directly by CNSSP 15 and National Security Memorandum 10.
- Prime contractors delivering systems into NSS environments must demonstrate CNSA 2.0 compliance for the complete delivered system, not just the components they build in-house.
- Sub-tier suppliers providing any component, module, or piece of code that ends up inside a system delivered to an NSS environment are in scope, because a prime’s compliance claim is only as strong as its supply chain.
- Commercial vendors with federal customers increasingly see CNSA 2.0 algorithms referenced as a forward-looking requirement in procurement language, even on contracts that will never touch a classified network, because buyers are using it as a proxy for cryptographic maturity.
The practical rule: if a component could plausibly end up inside a classified or NSS-scoped system three, four, or five contract layers downstream, treat it as in scope now rather than waiting for a direct request.
The Approved Algorithm Suite
CNSA 2.0 selects specific parameter sets from NIST’s finalized post-quantum standards, not the civilian defaults.
| Algorithm | Function | NIST standard | CNSA 2.0 parameter |
|---|---|---|---|
| AES | Symmetric encryption | FIPS 197 | 256-bit keys |
| ML-KEM | Key establishment | FIPS 203 | ML-KEM-1024 |
| ML-DSA | Digital signatures (general use) | FIPS 204 | ML-DSA-87 |
| SHA-2 | Hashing | FIPS 180-4 | SHA-384 or SHA-512 |
| LMS / XMSS | Firmware and software signing | NIST SP 800-208 | LMS with SHA-256 preferred |
Two exclusions catch contractors off guard. SLH-DSA (FIPS 205) is not part of the CNSA 2.0 suite despite being a finalized NIST standard, and multi-tree signature variants like HSS and XMSSMT are explicitly disallowed even though they are related to the approved LMS and XMSS schemes. A product built around either will not clear NSS procurement regardless of its NIST validation status.
The Timeline, Category by Category
CNSA 2.0 does not set a single deadline. It sets a support-and-prefer date and an exclusive-use date for each technology category, and the categories most relevant to defense contractors carry the tightest windows.
| Category | Support and prefer by | Exclusive use by |
|---|---|---|
| Software and firmware signing | Immediate | 2030 |
| Web browsers, servers, cloud services | Immediate | 2033 |
| Traditional networking equipment (VPNs, routers) | 2026 | 2030 |
| Operating systems | 2027 | 2033 |
| Constrained devices and large PKI systems | 2030 | 2033 |
| Custom applications and legacy systems | N/A | 2033 |
Layered on top of every category is the January 1, 2027 acquisition gate: from that date, new NSS acquisitions must support CNSA 2.0 algorithms by default, exceptions aside. For a contractor bidding on a multi-year program, the acquisition gate, not the category exclusive-use date, is usually the binding constraint, because a product that cannot demonstrate compliance at bid time does not get the chance to comply later.
NIAP Validation Is Not the Same as FIPS Validation
This is the single most common compliance gap. FIPS 140-3 validation, administered through CMVP, confirms a cryptographic module correctly implements its algorithms. It is necessary, but it is not sufficient for NSS use on its own. NSA guidance under CNSSP 11 additionally requires NIAP validation against an approved Protection Profile that incorporates CNSA 2.0 algorithms, configured correctly per CNSSP 15. A contractor holding an active FIPS 140-3 certificate can still fail an NSS procurement review if the product has not separately cleared NIAP validation.
The two processes run on independent timelines with different evidence requirements, which means they need to start in parallel, well ahead of an anticipated award, not sequentially after a contract is in hand.
Why the Validation Backlog Is the Real Deadline
CMVP (FIPS 140-3) validation has averaged well over 500 days from submission to an active certificate, and the testing infrastructure for post-quantum algorithms specifically is newer and less predictable than the classical-algorithm path it is layered onto. A module submitted in mid-2026 should not be expected to hold an active certificate before the January 2027 acquisition gate takes effect. Contractors evaluating a vendor, or being evaluated themselves, need to move past “do you support CNSA 2.0 algorithms” and ask exactly where in the CMVP and NIAP queues a specific certificate sits, and what date the vendor projects for an active certificate, not just algorithm support in a lab environment.
What Shows Up in Procurement Language and RFPs
Contracting officers are already writing CNSA 2.0 requirements into evaluation criteria ahead of the 2027 gate. A vendor without a credible validation timeline is typically disqualified before technical merit is scored at all. Expect procurement language to request, at minimum:
- Which CNSA 2.0 algorithms and parameter sets the product supports, by name and version.
- Current FIPS 140-3 (CMVP) and NIAP validation status, with certificate numbers where available, or a dated projection where validation is pending.
- A documented waiver history for any component not yet compliant, including submission date and remediation plan.
- A hybrid-transition plan for any product still relying on CNSA 1.0 algorithms during the migration window.
- Evidence that sub-tier components carry their own compliance documentation, not just an attestation from the prime.
How CNSA 2.0 Relates to CMMC
CNSA 2.0 and the Cybersecurity Maturity Model Certification program are frequently discussed together, but they are administered separately and defense contractors should not conflate their timelines or their scope. CNSA 2.0 is an NSA-led requirement governing cryptographic algorithms for National Security Systems. CMMC is a Department of War program verifying that contractors handling Federal Contract Information and Controlled Unclassified Information meet NIST SP 800-171 security controls.
On July 13, 2026, the Department of War suspended CMMC Phase II, the third-party C3PAO assessment requirement that had been scheduled to take effect on November 10, 2026, and launched a CMMC Reform Task Force to review the program. Phase I self-assessment requirements, DFARS 252.204-7012, and NIST SP 800-171 compliance obligations remain in force during that review. The suspension paused the third-party assessment mechanism, not the underlying obligation to protect covered defense information, and it has no bearing on CNSA 2.0’s January 2027 acquisition gate. Contractors should continue validation work against both tracks independently rather than treating the CMMC pause as license to slow down CNSA 2.0 preparation.
A Practical Evidence Checklist
What a contracting officer or a prime’s compliance team will actually ask to see:
- Algorithm inventory: every cryptographic module in the product, the algorithm and parameter set each one uses, and whether each is CNSA 1.0, CNSA 2.0, or hybrid.
- Validation status: current FIPS 140-3/CMVP certificate numbers and NIAP Protection Profile validation status, or a dated projection for each pending item.
- Waiver documentation: any active waiver request, its submission date, and the remediation plan attached to it.
- Sub-tier attestation: compliance documentation from every supplier whose component is included in the delivered system.
- Hybrid transition plan: for any component still shipping CNSA 1.0 algorithms, a dated plan for when CNSA 2.0 becomes preferred, then exclusive.
Building this package after an RFP lands is the most common way contractors lose bids they were technically qualified to win. It needs to exist in parallel with product development, not as a response to a solicitation.
What We’d Actually Recommend
Treat January 1, 2027 as the deadline that matters operationally, not 2030 or 2033. Working backward from CMVP’s 500-plus day average, any product that has not entered the validation queue by now is already racing the acquisition gate. Start NIAP and CMVP validation in parallel rather than sequentially, build the evidence checklist as a living document alongside product development rather than a bid-response scramble, and push sub-tier suppliers for their own compliance documentation early, since a prime’s certification is only as credible as its weakest supplier link. Keep CNSA 2.0 and CMMC tracked as genuinely separate workstreams; conflating them, especially during CMMC’s current reform review, risks either program slipping.
How Encryption Consulting Can Help
Passing NSS procurement review comes down to the evidence checklist above, and building that evidence starts with an accurate answer to a question most contractors cannot confidently give: which cryptographic modules in your product use which algorithm, at what parameter set, and how far along is each one in NIAP or CMVP validation. CBOM Secure builds and maintains exactly that inventory, tagging every module as CNSA 1.0, CNSA 2.0, or hybrid and tracking it against your sub-tier suppliers’ own compliance documentation, so the algorithm-inventory line item in a proposal response is a report you can generate, not a scramble.
From that inventory, our PQC Advisory Services build the validation and readiness roadmap: sequencing NIAP and CMVP submissions against the January 2027 acquisition gate, structuring a hybrid-transition plan that holds up under contracting officer review, and preparing the documentation package a prime contractor’s compliance team will actually ask for.
Where hardware is the compliance gap, our HSM Services assess current HSM firmware against CNSA 2.0 parameter sets and plan the refresh path where older modules cannot support ML-KEM-1024 or ML-DSA-87. And where the product involves certificate issuance, CertSecure Manager manages classical, hybrid, and CNSA 2.0-parameter certificates from a single policy plane, giving you one place to demonstrate compliance across an entire certificate estate rather than system by system.
The Deadline That Actually Constrains You
CNSA 2.0’s algorithm requirements are settled and well documented. What trips up defense contractors is the compliance machinery behind them: two independent validation processes with long queues, a supply chain that inherits the requirement whether or not it deals with the government directly, and a parallel CMMC program whose current reform review creates real risk of conflating two separate deadlines. The organizations that clear the January 2027 acquisition gate cleanly are the ones already building their evidence package now, not the ones waiting for an RFP to tell them what to prove.
Frequently Asked Questions
Does CNSA 2.0 apply to a company that only supplies a small component to a defense prime?
Yes, if that component ends up inside a system delivered to a National Security System environment. A prime contractor must demonstrate CNSA 2.0 compliance for the complete delivered system, which cascades the requirement to every sub-tier supplier regardless of contract size.
Is FIPS 140-3 validation enough to be CNSA 2.0 compliant?
No. FIPS 140-3 (CMVP) validates the cryptographic module itself. NSS use additionally requires NIAP validation against an approved Protection Profile, configured correctly per CNSSP 15. Both are needed; neither substitutes for the other.
What is the most urgent CNSA 2.0 deadline for defense contractors?
January 1, 2027, when new NSS acquisitions must support CNSA 2.0 algorithms by default. Given that CMVP validation alone averages more than 500 days, contractors targeting this gate needed to be in the validation queue well before mid-2026.
Does the CMMC Phase II suspension affect CNSA 2.0 requirements?
No. CMMC and CNSA 2.0 are separate programs administered by different parts of the Department of War and the NSA. The Department’s July 2026 suspension of CMMC Phase II paused third-party CMMC assessments pending a reform review; it has no effect on the CNSA 2.0 timeline or the January 2027 acquisition gate.
Which algorithms does CNSA 2.0 exclude that NIST otherwise approves?
SLH-DSA (FIPS 205) is a finalized NIST standard but is not part of the CNSA 2.0 suite. Multi-tree signature variants like HSS and XMSSMT are also explicitly disallowed, even though they are related to the approved LMS and XMSS schemes.
- Key Takeaways
- Who Is Actually in Scope
- The Approved Algorithm Suite
- The Timeline, Category by Category
- NIAP Validation Is Not the Same as FIPS Validation
- Why the Validation Backlog Is the Real Deadline
- What Shows Up in Procurement Language and RFPs
- How CNSA 2.0 Relates to CMMC
- A Practical Evidence Checklist
- What We'd Actually Recommend
- How Encryption Consulting Can Help
- The Deadline That Actually Constrains You
- Frequently Asked Questions
