Product
Technology
What is the threat
Existing solutions
⁠CyberRidge technology explained
Use cases
Resources
NewsWhite papers
Product UpdatesBlog
Company
Contact
Home
Product
Technology
Use cases
Company
Resources
News
White papers
Product updates
Blog
Get in touch

CNSA 2.0 Deadlines and What Government and Defense Contractors Must Do to Comply

What CNSA 2.0 requires when each deadline lands, and where it stops short of protecting data already moving across fiber.

CNSA 2.0 is the National Security Agency's post-quantum algorithm suite and migration timeline for National Security Systems, first issued in September 2022. From January 1, 2027, new National Security System acquisitions are expected to be CNSA 2.0 compliant, which makes 2027 the first deadline most contractors will feel. Meeting that deadline will require improving the strength of the algorithms protecting a connection. It does not address whether the connection can be recorded while the migration is still underway. Software and firmware signing and traditional networking equipment must comply with CNSA 2.0 by 2030, with web and cloud services, operating systems, and constrained devices following by 2033. What the mandate governs is the strength of the algorithms protecting a connection.

‍

Complying with CNSA 2.0 means replacing the cryptography in your systems with the algorithms the NSA has approved. On a category-by-category schedule, the approved list is short and deliberately narrow: ML-KEM-1024 for key establishment, ML-DSA-87 for digital signatures, AES-256 for symmetric encryption, SHA-384 or SHA-512 for hashing, and LMS or XMSS for firmware signing. For anyone building or operating systems that handle national-security data, the question is which security requirement hits its date first.

‍

What is CNSA 2.0?

CNSA 2.0 is the NSA's list of quantum-resistant algorithms for National Security Systems, plus the schedule for adopting them. It replaces CNSA 1.0, the RSA and elliptic-curve suite in policy today, and covers classified and defense-related systems only. Civilian agencies and private enterprises follow Executive Order 14412, which sets post-quantum key establishment for federal high-value assets by December 31, 2030 and signatures by December 31, 2031. That order excludes National Security Systems, routing them to CNSA 2.0 instead.

‍

Both tracks answer the same problem. A cryptographically relevant quantum computer can break the key exchange that establishes a session, meaning RSA and Diffie-Hellman can be compromised, rather than if AES-256 is used to encrypt the payload. An adversary recording a session today captures the payload and theΒ  key encryption; break the encryption with a cryptographically ready quantum computer,and the payload opens. That is the harvest-now-decrypt-later problem, and it is why deadlines are set against data encrypted by weaker algorithms.

‍

The deadlines, category by category

The date that forces action is January 1, 2027, when CNSA 2.0 becomes a procurement gate for new National Security System acquisitions. Defense acquisition cycles run 18 to 36 months, so products designed today will be delivered after that gate closes.

‍

After that, the schedule runs by product category. Software and firmware signing and traditional networking equipment such as VPNs and routers must use CNSA 2.0 exclusively by 2030. Web and cloud services, operating systems, large PKI, constrained devices, custom applications, and legacy equipment have until 2033. The NSA expects most transitions to be complete by 2033, ahead of the 2035 goal set by National Security Memorandum 10.

‍

Two further dates reach contractors directly. The Department of War Post-Quantum Cryptography Strategy, released June 23, 2026, requires every DoW system to support post-quantum cryptography by the end of 2030 and use it by the end of 2031. The strategy commits to extending cryptographic requirements across the defense industrial base, including updates to CMMC. EO 14412 separately directs the Federal Acquisition Regulation(FAR) Council to propose a rule requiring covered contractors to comply with NIST's post-quantum standards by December 31, 2030.

‍

What contractors have to do

Start with a cryptographic inventory. You cannot schedule a migration without knowing which keyss, libraries, and protocols use RSA or elliptic-curve algorithms, and where they are used. A November 2025 DoW CIO memorandum already requires defense contractors to inventory and report cryptography across systems holding department data.

‍

FIPS validation deserves its own line item, separate from algorithm support. National Security System products need FIPS 140-3 validated modules, and validation queues run long.

‍

Crypto-agility matters just as much as any single migration. The list has already narrowed once: the NSA excluded SLH-DSA even though NIST standardized it and civilian agencies may use it. Systems that can swap algorithms without re-architecture will survive the next revision. In practice, that means building on standard interfaces for key management and cryptographic operations rather than hard-coding one specific algorithm into applications and infrastructure. When NSA guidance changes again, replacing an approved algorithm with another is a configuration change rather than a complete redesign.

‍

What the mandate does not cover

CNSA 2.0 raises the strength of the algorithms protecting a link. It does nothing about whether the link can be recorded at all. A fiber tap does not care which key exchange runs above it; it captures the light.

‍

Recorded traffic is protected only by the assumption that the cryptography cannot be broken for as long as the data stays sensitive, which for defense material is often decades. Symmetric encryption, specifically AES-256, is what protects the payload of a session, and it already meets the bar for post-quantum resistance under CNSA 2.0. What the migration timeline changes is the key exchange that establishes that session, not the payload cipher itself. Timelines running to 2033 mean years of traffic will still cross the network under the current key exchange before CNSA 2.0-approved algorithms are the only ones in use, and any of that traffic recorded now carries that older, weaker encryption with it..

‍

As for encryptions protecting the payload, Cryptanalytic capabilities that work to effectively weaken encryption algorithms keep advancing across quantum, classical, and now AI-assisted methods. Anthropic's Frontier Red Team, for example, used Claude Mythos Preview in July 2026 to improve a classical attack on a reduced-round research variant of AES-128, running 200 to 800 times faster than the previous best result. The result does not break full AES-128 or AES-256 and has no production impact, but shows AI is now a working tool in cryptanalytic research generally. And regardless of algorithm strength, keys can be lost, stolen, exposed through a compromised endpoint, or implemented incorrectly, in each case, potentially exposing the data.

What Is Harvest Now, Decrypt Later, and How Can Organizations Protect Against It? Learn why HNDL is already a present-day threat and what a layered defense against it looks like.

‍

Where photonic layer security fits

The vulnerability of encryption algorithms risks the security of both the key exchange and the payload cipher. Maintaining resilience therefore necessitates an additional layer of security that is agnostic to cryptographic advances. This is where CyberRidge’s technology becomes crucial - protecting the data at the optical layer rather than the algorithm layer. Using Photonic Layer Security, it spreads the signal across a wide optical band, encodes it with keys embedded in the light itself, and buries it beneath generated optical noise, so no signal peak an attacker could lock onto appears on the fiber. The result is unrecoverable data. The patented technology has been published in peer-reviewed research.

‍

Attribute Detail Why it matters for a CNSA 2.0 program
Layer of operation Layer 1, the optical transmission itself Protects data crossing the network during the multi-year transition to CNSA 2.0-approved algorithms.
Protection method Signal spread across the spectrum and buried below the noise floor; optical keys embedded in the light and rotated continuously Removes the recording that a harvest-now-decrypt-later attacker depends on
Relationship to PQC Complementary. Does not interfere with PQC-compliant algorithms such as ML-KEM, ML-DSA, and SLH-DSA; Carmel operates at Layer 1, beneath where those algorithms run.
Interoperability Works over existing fiber and DWDM, standard 100GbE client interfaces, validated with EDFA and Raman amplification Avoids the dedicated key-distribution fiber that QKD requires
Deployment Four-week phased sequence. Fits inside procurement cycles already compressed by the 2027 deadline
Commercial model Purchase per link pair, or subscription per protected link; Net cost offsets line card hardware already in the network budget

‍

Wondering how this compares with the alternatives? How Do You Implement Post-Quantum Encryption for Data-in-Transit? walks through the PQC rollout and where photonic layer security fits alongside it.

‍

Practical takeaways

Treat January 1st, 2027, as the working deadline rather than 2030 or 2033, because procurement eligibility is decided at the point of acquisition. Inventory your cryptography, confirm FIPS 140-3 validation paths for every module you depend on, and design for algorithm replacement rather than a single migration. Then ask a separate question about your most sensitive links: if that traffic were recorded today, would the migration scheduled for 2035 protect it? Where the answer is no, the exposure sits at the physical layer.

‍

Assessing which of your links carry data with a long confidentiality lifetime? Visit CyberRidge.

‍

FAQs

Q: Does deploying CyberRidge's Carmel platform make an organization CNSA 2.0 compliant?

‍

A: No. CNSA 2.0 compliance requires using specific NSA-approved algorithms such as ML-KEM-1024 and ML-DSA-87 in FIPS 140-3 validated modules, and Carmel operates at Layer 1 rather than at the algorithm layer. However, should the cryptographic keys fall into the wrong hands or be implemented incorrectly, CyberRidge provides a complementary layer of security that ensures no traffic can be recorded off the fiber at all.

‍

Q: Does CyberRidge replace post-quantum cryptography or work alongside it?

‍

A: It works alongside it. Post-quantum cryptography protects the key exchange at the digital layer, while CyberRidge's Photonic Layer Security operates at the optical transmission layer beneath it. CyberRidge positions Carmel as complementary to post-quantum migration, not as a substitute for it.

‍

Q: How is CyberRidge different from QKD for defense networks?

‍

A: QKD distributes keys using quantum mechanics but the payload still travels as a recordable signal, so harvest-now-decrypt-later still works β€” and it generally needs a dedicated quantum channel or dark fibre. Carmel works differently: the light itself carries no recoverable signal, and key exchange rides in-band inside that protected channel, with forward secrecy. No separate key-distribution channel, no new fibre. QKD protects the keys; CyberRidge removes the recording.Β 

‍

Q: Does CyberRidge's Carmel add latency to a protected link?

‍

A: CyberRidge reports no added latency beyond the propagation delay of the fiber itself and has been highly performant in infrastructure over a 205 km coherent link.

‍

Q: Will Carmel work with existing DWDM equipment and amplifiers?

‍

A: Yes, according to CyberRidge. Carmel is stated to operate over existing fiber with no modifications to DWDM equipment, alongside any vendor's optical transport, with support for up to five alien wavelengths and compatibility with EDFA and Raman amplification. Its current shipping specification is a 100 Gb/s uplink over links up to 100 km unamplified.

‍

Q: How long does a CyberRidge deployment take compared with a PQC migration?

‍

A: Deployment typically takes a four-week phased sequence: parallel deployment in week one, testing and validation in weeks two and three, and full cutover in week four. Post-quantum migration across a large estate is measured in years, which is why CNSA 2.0 dates run to 2030 and 2033. These deployment figures are company-reported.

‍

Q: Is CyberRidge established enough for defense procurement?

‍

A: CyberRidge was named a Cool Vendor in Gartner's Cool Vendors in Data Security 2025 report, was selected by the European Innovation Council from approximately 1,400 Horizon Europe applicants, and was a finalist in the 2026 SC Awards for Best Emerging Technology. Its Photonic Layer Security method has been published in peer-reviewed optical engineering academic literature.Β 

Be post quantum ready before its too late

Get in touch
Post-Quantum Optical Security for Data-in-Transit
General
HomeProductTechnologyUse casesCompanyInsights
Contact
Get in touchinfo@cyber-ridge.comLinkedin
Legal
PrivacyTOCAccessibility statement
CyberRidge 2026. All rights reservd
Site by Streetlight