Skip to content

Evidence request lists

NSA Guidance for Transition to Quantum-Resistant Cryptography

Evidence request list. 29 controls, 29 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Algorithm Migration

QRCM-3.1
Hybrid Solution Deployment (2025-2030)

Deploy hybrid solutions combining classical and quantum-resistant algorithms during transition period

Artefacts an auditor will ask for
  • Hybrid deployment evidence on TLS and IKE
  • CNSA 2.0 algorithm selection records
  • RSA and ECC deprecation roadmap
  • Compatibility test results
Where this commonly fails
  • Hybrid not deployed on all critical channels
  • RSA deprecation timeline missing
  • CNSA 2.0 not preferred in product selection
QRCM-3.2
CNSA 2.0 Algorithm Preference

Prefer CNSA 2.0 algorithms when configuring systems during transition period

Artefacts an auditor will ask for
  • Hybrid deployment evidence on TLS and IKE
  • CNSA 2.0 algorithm selection records
  • RSA and ECC deprecation roadmap
  • Compatibility test results
Where this commonly fails
  • Hybrid not deployed on all critical channels
  • RSA deprecation timeline missing
  • CNSA 2.0 not preferred in product selection
QRCM-3.3
RSA/ECC Deprecation

NSA stops approving new systems using RSA, Diffie-Hellman, and ECC for key establishment by 2025

Artefacts an auditor will ask for
  • Hybrid deployment evidence on TLS and IKE
  • CNSA 2.0 algorithm selection records
  • RSA and ECC deprecation roadmap
  • Compatibility test results
Where this commonly fails
  • Hybrid not deployed on all critical channels
  • RSA deprecation timeline missing
  • CNSA 2.0 not preferred in product selection

Architecture

QRMIG-07
Cryptographic Agility

Design systems for cryptographic agility so that algorithms can be replaced without major refactoring, supporting present and future CNSA 2.0 updates.

Artefacts an auditor will ask for
  • Cryptographic agility design standards
  • Architecture decision records referencing agility
  • Code review checklists for cryptographic agility
  • Library wrapper documentation
Where this commonly fails
  • Cryptographic algorithms hardcoded in source
  • No abstraction layer for cryptographic operations
  • Legacy applications outside agility programme

Assurance

QRMIG-16
Testing and Validation Programme

Run a structured testing and validation programme that confirms migrated systems operate correctly, securely, and within performance budgets.

Artefacts an auditor will ask for
  • Migration test plan
  • Functional, performance, and security test results
  • Defect logs and remediation records
  • Independent assessment reports
Where this commonly fails
  • Performance testing skipped
  • Independent assessment not budgeted
  • Defects deferred without compensating control
QRMIG-19
Post Migration Assurance

After migration, perform independent assurance activities to confirm CNSA 2.0 algorithms are operating correctly across in scope systems and to identify residual risks.

Artefacts an auditor will ask for
  • Independent assurance report
  • Residual risk register entries
  • Remediation plan and tracking
  • Sign off by authorising official
Where this commonly fails
  • Assurance limited to documentation review
  • Residual risks not tracked to closure
  • Sign off delayed past deadline

Cloud

QRMIG-11
Cloud Service Transition

Coordinate with cloud service providers to ensure shared responsibility activities support CNSA 2.0 algorithm transition for storage, transport, and identity services.

Artefacts an auditor will ask for
  • Cloud provider roadmap documentation
  • Configuration evidence for cloud services
  • Shared responsibility mapping for cryptographic controls
  • Provider attestation letters
Where this commonly fails
  • Provider managed keys outside customer control
  • Cloud native services lacking algorithm options
  • Multi cloud strategies without aligned roadmap

Communications

QRMIG-17
Communication and Stakeholder Reporting

Communicate migration progress, risks, and decisions to executive stakeholders, oversight bodies, and operational teams on a defined cadence.

Artefacts an auditor will ask for
  • Programme status reports
  • Steering committee minutes
  • Risk dashboards
  • Stakeholder communications archive
Where this commonly fails
  • Oversight bodies not briefed regularly
  • Operational staff unaware of timeline
  • Risk reporting hidden in technical detail

Cryptographic Inventory and Discovery

QRCM-1.1
Cryptographic Asset Inventory

Conduct comprehensive inventory of all cryptographic assets, protocols, and algorithms currently in use

Artefacts an auditor will ask for
  • Cryptographic asset inventory output from discovery tool
  • Post-Cryptography-vulnerable classification of cryptographic uses
  • Data classification mapping for migration priority
  • Inventory governance procedure
Where this commonly fails
  • Inventory missing embedded cryptographic uses
  • Discovery not run on legacy systems
  • Classification of long-life data incomplete
QRCM-1.2
Quantum-Vulnerable Identification

Identify systems relying on quantum-vulnerable cryptography particularly for digital signatures and key exchange

Artefacts an auditor will ask for
  • Cryptographic asset inventory output from discovery tool
  • Post-Cryptography-vulnerable classification of cryptographic uses
  • Data classification mapping for migration priority
  • Inventory governance procedure
Where this commonly fails
  • Inventory missing embedded cryptographic uses
  • Discovery not run on legacy systems
  • Classification of long-life data incomplete
QRCM-1.3
Data Classification for Migration

Classify data based on sensitivity and longevity to prioritize migration of long-lived secrets

Artefacts an auditor will ask for
  • Cryptographic asset inventory output from discovery tool
  • Post-Cryptography-vulnerable classification of cryptographic uses
  • Data classification mapping for migration priority
  • Inventory governance procedure
Where this commonly fails
  • Inventory missing embedded cryptographic uses
  • Discovery not run on legacy systems
  • Classification of long-life data incomplete

Decommissioning

QRMIG-20
Decommissioning of Legacy Cryptography

Decommission legacy cryptographic algorithms, keys, and infrastructure once migration is complete, with documented destruction and revocation records.

Artefacts an auditor will ask for
  • Decommissioning plan
  • Key destruction records
  • Certificate revocation lists
  • Inventory updates removing legacy assets
Where this commonly fails
  • Legacy keys retained in escrow without policy
  • Old certificates not revoked
  • Inventory not updated post decommission

Federal Compliance

QRCM-4.1
NSM-10 Compliance

Federal agencies must begin PQC migration and mitigate most quantum risk by 2035 per NSM-10

Artefacts an auditor will ask for
  • NSM-10 compliance attestation
  • TLS 1.3 enforcement evidence across services
  • Post-Cryptography-safe product category mappings
  • Compliance reporting to OMB
Where this commonly fails
  • TLS 1.2 still negotiated on key endpoints
  • NSM-10 reporting not submitted
  • Product categories not mapped to PQC inventory
QRCM-4.2
TLS 1.3 Adoption

Adopt TLS 1.3 or successor protocol by January 2, 2030 as required

Artefacts an auditor will ask for
  • NSM-10 compliance attestation
  • TLS 1.3 enforcement evidence across services
  • Post-Cryptography-safe product category mappings
  • Compliance reporting to OMB
Where this commonly fails
  • TLS 1.2 still negotiated on key endpoints
  • NSM-10 reporting not submitted
  • Product categories not mapped to PQC inventory
QRCM-4.3
Quantum-Safe Product Categories

CISA and NSA to publish list of quantum-safe product categories by December 1, 2025

Artefacts an auditor will ask for
  • NSM-10 compliance attestation
  • TLS 1.3 enforcement evidence across services
  • Post-Cryptography-safe product category mappings
  • Compliance reporting to OMB
Where this commonly fails
  • TLS 1.2 still negotiated on key endpoints
  • NSM-10 reporting not submitted
  • Product categories not mapped to PQC inventory

Identity

QRMIG-12
Identity Federation and Smart Cards

Migrate identity federation, smart card credentials, and authentication tokens to CNSA 2.0 supported algorithms in coordination with relying parties.

Artefacts an auditor will ask for
  • Identity architecture documentation
  • Token and credential inventory
  • Updated federation metadata
  • Relying party readiness assessment
Where this commonly fails
  • Smart card middleware not updated
  • Federation partners outside roadmap
  • Token vendors lacking compatible firmware

Inventory

QRMIG-02
Cryptographic Asset Discovery

Discover and inventory all cryptographic assets including libraries, protocols, keys, certificates, and embedded uses across the organisation as foundation for next-generation algorithm transition.

Artefacts an auditor will ask for
  • Cryptographic discovery tool configuration
  • Inventory output by system, application, and device
  • Coverage assessment reports
  • Inventory review cadence record
Where this commonly fails
  • Discovery limited to network traffic, missing application code
  • Embedded device cryptography not catalogued
  • Third party SaaS not assessed

Key Management

QRMIG-09
Key Management Modernisation

Modernise key management systems and hardware security modules to support CNSA 2.0 algorithms, key sizes, and lifecycle management requirements.

Artefacts an auditor will ask for
  • HSM inventory with firmware versions
  • Vendor commitments for firmware updates
  • Key lifecycle management procedures
  • Test results for new key types
Where this commonly fails
  • HSM end of life with no replacement path
  • Key ceremonies not updated for new algorithms
  • Backup HSMs not in scope

Network Security

QRMIG-13
Network Device Transition

Migrate network devices including routers, firewalls, VPN concentrators, and load balancers to support CNSA 2.0 algorithms for control plane and data plane operations.

Artefacts an auditor will ask for
  • Network device inventory
  • Firmware update plan
  • Configuration baselines
  • Test results for updated devices
Where this commonly fails
  • Legacy devices with no firmware upgrade path
  • Management protocol cryptography not updated
  • Test environment not representative

OT and Embedded

QRMIG-14
Operational Technology

Plan transition for operational technology, industrial control systems, and embedded devices that have longer lifecycles and constrained update paths.

Artefacts an auditor will ask for
  • OT and ICS asset inventory
  • Lifecycle plan with replacement schedule
  • Compensating control documentation
  • Vendor roadmap statements
Where this commonly fails
  • OT vendors with no roadmap
  • Compensating controls undefined
  • Risk acceptance not signed by authorising official

PKI

QRMIG-08
Public Key Infrastructure Update

Update public key infrastructure to support CNSA 2.0 signature algorithms across certificate authorities, registration authorities, and relying parties.

Artefacts an auditor will ask for
  • Certificate authority configuration evidence
  • Updated certificate policy and certification practice statement
  • Relying party readiness assessment
  • Test certificates issued and validated
Where this commonly fails
  • Subordinate CAs not updated
  • Certificate policy not revised
  • Relying parties unable to process new signature algorithms

Pilot Programme

QRMIG-05
Pilot Implementation

Conduct pilot implementations of CNSA 2.0 algorithms in representative environments to validate functionality, performance, and operational impact.

Artefacts an auditor will ask for
  • Pilot test plan with scope and success criteria
  • Pilot results reports
  • Performance and interoperability metrics
  • Lessons learned document
Where this commonly fails
  • Pilots run in non representative environments
  • Success criteria not defined
  • Lessons learned not fed into broader programme

Programme Governance

QRMIG-01
Migration Programme Establishment

Establish a formal CNSA 2.0 migration roadmap with executive sponsorship, scope, timeline, and budget covering all NSS and supporting systems.

Artefacts an auditor will ask for
  • Migration programme charter signed by executive sponsor
  • Scope statement identifying systems in CNSA 2.0 migration roadmap
  • Budget plan with allocations by fiscal year
  • Stakeholder register
Where this commonly fails
  • Programme scoped only to central IT
  • Lack of executive sponsor
  • Budget not aligned to milestone delivery

Records

QRMIG-15
Records Retention and Long Lived Data

Identify data that requires long retention and apply CNSA 2.0 algorithms or re encryption strategies to address the harvest now decrypt later risk.

Artefacts an auditor will ask for
  • Retention schedule reference
  • Data classification records
  • Re encryption project plan
  • Approval records for residual risk
Where this commonly fails
  • Archive storage outside re encryption plan
  • Off site or tape archives forgotten
  • Vendor escrow data not addressed

Risk Assessment

QRMIG-03
Prioritisation and Risk Assessment

Assess and prioritise systems for migration based on data sensitivity, retention period, exposure, and protection lifetime requirements.

Artefacts an auditor will ask for
  • Risk assessment methodology document
  • Prioritisation matrix scoring each system
  • Data lifetime analysis showing retention requirements
  • Approval records for prioritisation outcome
Where this commonly fails
  • Data lifetime requirements not documented
  • Mission critical systems deprioritised due to vendor readiness
  • Risk scoring without input from data owners

Software Engineering

QRMIG-10
Application Code Refactor

Refactor application code to use updated cryptographic libraries that support CNSA 2.0 algorithms, replacing deprecated functions and ensuring backwards compatibility where required.

Artefacts an auditor will ask for
  • Code inventory of cryptographic function calls
  • Refactor work orders and code review records
  • Updated unit and integration test coverage
  • Library version tracking
Where this commonly fails
  • Static analysis not run for cryptographic API usage
  • Refactor backlog not prioritised by risk
  • Vendor supplied code outside refactor scope

Supply Chain

QRMIG-04
Vendor Engagement and Roadmaps

Engage product and service vendors to obtain CNSA 2.0 migration roadmap commitments and integrate them into procurement and renewal planning.

Artefacts an auditor will ask for
  • Vendor questionnaire responses on CNSA 2.0 readiness
  • Vendor product roadmap documentation
  • Updated contracts including transition clauses
  • Vendor risk assessments
Where this commonly fails
  • Vendor roadmaps not collected centrally
  • Open source dependencies excluded from engagement
  • No exit plan for vendors lacking roadmap

Transition Operations

QRMIG-06
Hybrid Algorithm Strategy

Where approved, define and operate hybrid algorithm strategies that combine legacy and next-generation algorithm transition components to maintain interoperability during migration.

Artefacts an auditor will ask for
  • Hybrid algorithm architecture document
  • Approval records by authorising official
  • Configuration evidence for hybrid mode
  • Sunset plan with cutover dates
Where this commonly fails
  • Hybrid mode lacks documented sunset
  • No monitoring of which algorithm is selected per session
  • Hybrid mode applied to systems where pure CNSA 2.0 is feasible

Workforce

QRMIG-18
Training and Capability Building

Develop and deliver training and capability building for engineering, security, procurement, and operations teams on next-generation algorithm transition activities.

Artefacts an auditor will ask for
  • Curriculum and learning pathways
  • Attendance and completion records
  • Capability assessment results
  • Continuing education plan
Where this commonly fails
  • Procurement excluded from curriculum
  • Operations staff training limited to documentation review
  • No refresher cadence
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the NSA Guidance for Transition to Quantum-Resistant Cryptography framework page.