Home
/
Industries
/
Government & defense
Government & defense

Where post-quantum requirements are already
reshaping acquisition.

CNSSP 15 gates new national security system acquisitions from January 2027. Executive Order 14412 also directs federal acquisition rulemaking for covered contractors, making product evidence and vendor readiness increasingly important across the supply chain.

Scope a compliance baseline
Read the mandate detail
2027
New NSS acquisitions

Must support quantum-resistant cryptography from January 1.

2030
Key establishment and equipment

Federal HVA key-establishment deadline; unsupported CNSA 2.0 equipment and services phased out.

2031
CNSA 2.0 use mandated

CNSA 2.0 algorithms required for NSS use unless otherwise noted.

2035
Full transition horizon

NSA intends all NSS to be quantum-resistant; OMB targets remaining civilian systems.

Who this binds

The flowdown reaches further than most suppliers expect

CNSSP 15 directly governs national security systems and informs the products vendors build for them. Separately, EO 14412 directed proposed FAR rules for covered contractors. Exact supplier obligations depend on the contract, system boundary and final rule text.

National security systems

NSM-10 and the CNSA 2.0 suite

Specified parameter sets at the top of each NIST family, with an acquisition gate that arrives first.

2027

New NSS acquisitions must be CNSA 2.0 compliant

2031

CNSA 2.0 algorithms mandated for use

2035

All NSS quantum-resistant

Federal civilian

EO 14412 and OMB M-26-15

Dated deadlines for high-value assets and high-impact systems, and a FAR rule directed for covered contractors. M-26-15 expressly excludes NSS.

2030

Key establishment on prioritized systems; TLS 1.3 support

2031

Digital signatures on prioritized systems

2035

Remaining systems

Programmes that conflate the two apply the wrong deadlines and the wrong parameter sets. Find your row below, then read the regime it points to.

If you are
What applies
What you will be asked for
An NSS operator
NSM-10 and CNSA 2.0 directly, with specified parameter sets
Evidence that ML-KEM-1024 and ML-DSA-87 are in use, not merely available
A defense prime
NSS contract terms and product requirements, where applicable
Cryptographic evidence for delivered systems and supplier coordination
A subcontractor or component supplier
Applicable flowdown or product requirements
Component-level cryptographic evidence and migration readiness
A federal civilian agency
EO 14412 and OMB M-26-15
Automated inventory methods and progress against 2030, 2031 and 2035 phases
A covered civilian contractor
FAR rulemaking directed under EO 14412
Requirements will depend on the final rule and contract clauses
A commercial vendor with federal customers
Customer procurement and assurance requirements
Product cryptography, roadmap and evidence suitable for review

Two regimes, not one.

National security systems are governed by NSM-10 and the CNSA 2.0 suite. Federal civilian agencies are governed by Executive Order 14412 and OMB Memorandum M-26-15, which expressly excludes national security systems. Programmes that conflate the two apply the wrong deadlines and the wrong parameter sets.

The CNSA 2.0 algorithm suite

Higher parameter sets than the commercial baseline

National security systems are specified at the top of each NIST family. A commercial deployment of ML-KEM-768 does not satisfy an NSS requirement for ML-KEM-1024.

KEY ESTABLISHMENT

ML-KEM-1024

FIPS 203 at the highest parameter set. Category 5.

SIGNATURES

ML-DSA-87

FIPS 204 at the highest parameter set.

SYMMETRIC

AES-256

Grover halves effective strength, so 256-bit is the floor.

HASHING

SHA-384 / 512

SHA-256 is not sufficient under the suite.

FIRMWARE SIGNING

LMS / XMSS

Stateful hash-based signatures (SP 800-208) for software and firmware. The earliest CNSA 2.0 milestones apply here first.

What makes this sector harder

Accreditation boundaries, air gaps and long-lived platforms

Accreditation

Accredited enclaves

Systems inside an authorization boundary cannot accept arbitrary agents or unscheduled scans. Discovery has to work within an existing ATO, which means read-only, documented and scoped collection.

Connectivity

Disconnected environments

Air-gapped and classified networks cannot phone home. Collection needs to run locally and export evidence through an approved transfer path rather than a cloud API.

Asset lifetime

Platform lifetimes

Weapons systems, avionics and ground infrastructure stay in service for decades. Cryptography embedded in a platform fielded today will still be running well past 2035.

A platform fielded in 2027 with a thirty-year service life is a 2057 cryptography problem being decided now.

Evidence for the reviewer

What an assessor actually asks for

Compliance conversations in this sector turn on traceability. The question is never only what you found, but how you know and when you last checked.

Scope statement

What was in the boundary, what was excluded and why.

Collection method

How each record was obtained, with sensor and timestamp.

Coverage confidence

What the method cannot see, stated rather than implied.

Change history

What moved since the last assessment, and who approved it.

Build the inventory before the attestation request arrives

Start with one accredited boundary or one delivered system and produce a record a reviewer will accept.