Where post-quantum requirements are already reshaping acquisition.
CNSSP 15 gates new national security system acquisitions from January 2027. Executive Order 14412 also directs federal acquisition rulemaking for covered contractors, making product evidence and vendor readiness increasingly important across the supply chain.
Must support quantum-resistant cryptography from January 1.
Federal HVA key-establishment deadline; unsupported CNSA 2.0 equipment and services phased out.
CNSA 2.0 algorithms required for NSS use unless otherwise noted.
NSA intends all NSS to be quantum-resistant; OMB targets remaining civilian systems.
The flowdown reaches further than most suppliers expect
CNSSP 15 directly governs national security systems and informs the products vendors build for them. Separately, EO 14412 directed proposed FAR rules for covered contractors. Exact supplier obligations depend on the contract, system boundary and final rule text.
NSM-10 and the CNSA 2.0 suite
Specified parameter sets at the top of each NIST family, with an acquisition gate that arrives first.
New NSS acquisitions must be CNSA 2.0 compliant
CNSA 2.0 algorithms mandated for use
All NSS quantum-resistant
EO 14412 and OMB M-26-15
Dated deadlines for high-value assets and high-impact systems, and a FAR rule directed for covered contractors. M-26-15 expressly excludes NSS.
Key establishment on prioritized systems; TLS 1.3 support
Digital signatures on prioritized systems
Remaining systems
Programmes that conflate the two apply the wrong deadlines and the wrong parameter sets. Find your row below, then read the regime it points to.
Two regimes, not one.
National security systems are governed by NSM-10 and the CNSA 2.0 suite. Federal civilian agencies are governed by Executive Order 14412 and OMB Memorandum M-26-15, which expressly excludes national security systems. Programmes that conflate the two apply the wrong deadlines and the wrong parameter sets.
Higher parameter sets than the commercial baseline
National security systems are specified at the top of each NIST family. A commercial deployment of ML-KEM-768 does not satisfy an NSS requirement for ML-KEM-1024.
ML-KEM-1024
FIPS 203 at the highest parameter set. Category 5.
ML-DSA-87
FIPS 204 at the highest parameter set.
AES-256
Grover halves effective strength, so 256-bit is the floor.
SHA-384 / 512
SHA-256 is not sufficient under the suite.
LMS / XMSS
Stateful hash-based signatures (SP 800-208) for software and firmware. The earliest CNSA 2.0 milestones apply here first.
Accreditation boundaries, air gaps and long-lived platforms
Accredited enclaves
Systems inside an authorization boundary cannot accept arbitrary agents or unscheduled scans. Discovery has to work within an existing ATO, which means read-only, documented and scoped collection.
Disconnected environments
Air-gapped and classified networks cannot phone home. Collection needs to run locally and export evidence through an approved transfer path rather than a cloud API.
Platform lifetimes
Weapons systems, avionics and ground infrastructure stay in service for decades. Cryptography embedded in a platform fielded today will still be running well past 2035.
A platform fielded in 2027 with a thirty-year service life is a 2057 cryptography problem being decided now.
What an assessor actually asks for
Compliance conversations in this sector turn on traceability. The question is never only what you found, but how you know and when you last checked.
Scope statement
What was in the boundary, what was excluded and why.
Collection method
How each record was obtained, with sensor and timestamp.
Coverage confidence
What the method cannot see, stated rather than implied.
Change history
What moved since the last assessment, and who approved it.
Build the inventory before the attestation request arrives
Start with one accredited boundary or one delivered system and produce a record a reviewer will accept.

