NSA Guidance for Transition to Quantum-Resistant Cryptography
Evidence request list. 29 controls, 29 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Algorithm Migration
Deploy hybrid solutions combining classical and quantum-resistant algorithms during transition period
- Hybrid deployment evidence on TLS and IKE
- CNSA 2.0 algorithm selection records
- RSA and ECC deprecation roadmap
- Compatibility test results
- Hybrid not deployed on all critical channels
- RSA deprecation timeline missing
- CNSA 2.0 not preferred in product selection
Prefer CNSA 2.0 algorithms when configuring systems during transition period
- Hybrid deployment evidence on TLS and IKE
- CNSA 2.0 algorithm selection records
- RSA and ECC deprecation roadmap
- Compatibility test results
- Hybrid not deployed on all critical channels
- RSA deprecation timeline missing
- CNSA 2.0 not preferred in product selection
NSA stops approving new systems using RSA, Diffie-Hellman, and ECC for key establishment by 2025
- Hybrid deployment evidence on TLS and IKE
- CNSA 2.0 algorithm selection records
- RSA and ECC deprecation roadmap
- Compatibility test results
- Hybrid not deployed on all critical channels
- RSA deprecation timeline missing
- CNSA 2.0 not preferred in product selection
Architecture
Design systems for cryptographic agility so that algorithms can be replaced without major refactoring, supporting present and future CNSA 2.0 updates.
- Cryptographic agility design standards
- Architecture decision records referencing agility
- Code review checklists for cryptographic agility
- Library wrapper documentation
- Cryptographic algorithms hardcoded in source
- No abstraction layer for cryptographic operations
- Legacy applications outside agility programme
Assurance
Run a structured testing and validation programme that confirms migrated systems operate correctly, securely, and within performance budgets.
- Migration test plan
- Functional, performance, and security test results
- Defect logs and remediation records
- Independent assessment reports
- Performance testing skipped
- Independent assessment not budgeted
- Defects deferred without compensating control
After migration, perform independent assurance activities to confirm CNSA 2.0 algorithms are operating correctly across in scope systems and to identify residual risks.
- Independent assurance report
- Residual risk register entries
- Remediation plan and tracking
- Sign off by authorising official
- Assurance limited to documentation review
- Residual risks not tracked to closure
- Sign off delayed past deadline
Cloud
Coordinate with cloud service providers to ensure shared responsibility activities support CNSA 2.0 algorithm transition for storage, transport, and identity services.
- Cloud provider roadmap documentation
- Configuration evidence for cloud services
- Shared responsibility mapping for cryptographic controls
- Provider attestation letters
- Provider managed keys outside customer control
- Cloud native services lacking algorithm options
- Multi cloud strategies without aligned roadmap
Communications
Communicate migration progress, risks, and decisions to executive stakeholders, oversight bodies, and operational teams on a defined cadence.
- Programme status reports
- Steering committee minutes
- Risk dashboards
- Stakeholder communications archive
- Oversight bodies not briefed regularly
- Operational staff unaware of timeline
- Risk reporting hidden in technical detail
Cryptographic Inventory and Discovery
Conduct comprehensive inventory of all cryptographic assets, protocols, and algorithms currently in use
- Cryptographic asset inventory output from discovery tool
- Post-Cryptography-vulnerable classification of cryptographic uses
- Data classification mapping for migration priority
- Inventory governance procedure
- Inventory missing embedded cryptographic uses
- Discovery not run on legacy systems
- Classification of long-life data incomplete
Identify systems relying on quantum-vulnerable cryptography particularly for digital signatures and key exchange
- Cryptographic asset inventory output from discovery tool
- Post-Cryptography-vulnerable classification of cryptographic uses
- Data classification mapping for migration priority
- Inventory governance procedure
- Inventory missing embedded cryptographic uses
- Discovery not run on legacy systems
- Classification of long-life data incomplete
Classify data based on sensitivity and longevity to prioritize migration of long-lived secrets
- Cryptographic asset inventory output from discovery tool
- Post-Cryptography-vulnerable classification of cryptographic uses
- Data classification mapping for migration priority
- Inventory governance procedure
- Inventory missing embedded cryptographic uses
- Discovery not run on legacy systems
- Classification of long-life data incomplete
Decommissioning
Decommission legacy cryptographic algorithms, keys, and infrastructure once migration is complete, with documented destruction and revocation records.
- Decommissioning plan
- Key destruction records
- Certificate revocation lists
- Inventory updates removing legacy assets
- Legacy keys retained in escrow without policy
- Old certificates not revoked
- Inventory not updated post decommission
Federal Compliance
Federal agencies must begin PQC migration and mitigate most quantum risk by 2035 per NSM-10
- NSM-10 compliance attestation
- TLS 1.3 enforcement evidence across services
- Post-Cryptography-safe product category mappings
- Compliance reporting to OMB
- TLS 1.2 still negotiated on key endpoints
- NSM-10 reporting not submitted
- Product categories not mapped to PQC inventory
Adopt TLS 1.3 or successor protocol by January 2, 2030 as required
- NSM-10 compliance attestation
- TLS 1.3 enforcement evidence across services
- Post-Cryptography-safe product category mappings
- Compliance reporting to OMB
- TLS 1.2 still negotiated on key endpoints
- NSM-10 reporting not submitted
- Product categories not mapped to PQC inventory
CISA and NSA to publish list of quantum-safe product categories by December 1, 2025
- NSM-10 compliance attestation
- TLS 1.3 enforcement evidence across services
- Post-Cryptography-safe product category mappings
- Compliance reporting to OMB
- TLS 1.2 still negotiated on key endpoints
- NSM-10 reporting not submitted
- Product categories not mapped to PQC inventory
Identity
Migrate identity federation, smart card credentials, and authentication tokens to CNSA 2.0 supported algorithms in coordination with relying parties.
- Identity architecture documentation
- Token and credential inventory
- Updated federation metadata
- Relying party readiness assessment
- Smart card middleware not updated
- Federation partners outside roadmap
- Token vendors lacking compatible firmware
Inventory
Discover and inventory all cryptographic assets including libraries, protocols, keys, certificates, and embedded uses across the organisation as foundation for next-generation algorithm transition.
- Cryptographic discovery tool configuration
- Inventory output by system, application, and device
- Coverage assessment reports
- Inventory review cadence record
- Discovery limited to network traffic, missing application code
- Embedded device cryptography not catalogued
- Third party SaaS not assessed
Key Management
Modernise key management systems and hardware security modules to support CNSA 2.0 algorithms, key sizes, and lifecycle management requirements.
- HSM inventory with firmware versions
- Vendor commitments for firmware updates
- Key lifecycle management procedures
- Test results for new key types
- HSM end of life with no replacement path
- Key ceremonies not updated for new algorithms
- Backup HSMs not in scope
Network Security
Migrate network devices including routers, firewalls, VPN concentrators, and load balancers to support CNSA 2.0 algorithms for control plane and data plane operations.
- Network device inventory
- Firmware update plan
- Configuration baselines
- Test results for updated devices
- Legacy devices with no firmware upgrade path
- Management protocol cryptography not updated
- Test environment not representative
OT and Embedded
Plan transition for operational technology, industrial control systems, and embedded devices that have longer lifecycles and constrained update paths.
- OT and ICS asset inventory
- Lifecycle plan with replacement schedule
- Compensating control documentation
- Vendor roadmap statements
- OT vendors with no roadmap
- Compensating controls undefined
- Risk acceptance not signed by authorising official
PKI
Update public key infrastructure to support CNSA 2.0 signature algorithms across certificate authorities, registration authorities, and relying parties.
- Certificate authority configuration evidence
- Updated certificate policy and certification practice statement
- Relying party readiness assessment
- Test certificates issued and validated
- Subordinate CAs not updated
- Certificate policy not revised
- Relying parties unable to process new signature algorithms
Pilot Programme
Conduct pilot implementations of CNSA 2.0 algorithms in representative environments to validate functionality, performance, and operational impact.
- Pilot test plan with scope and success criteria
- Pilot results reports
- Performance and interoperability metrics
- Lessons learned document
- Pilots run in non representative environments
- Success criteria not defined
- Lessons learned not fed into broader programme
Programme Governance
Establish a formal CNSA 2.0 migration roadmap with executive sponsorship, scope, timeline, and budget covering all NSS and supporting systems.
- Migration programme charter signed by executive sponsor
- Scope statement identifying systems in CNSA 2.0 migration roadmap
- Budget plan with allocations by fiscal year
- Stakeholder register
- Programme scoped only to central IT
- Lack of executive sponsor
- Budget not aligned to milestone delivery
Records
Identify data that requires long retention and apply CNSA 2.0 algorithms or re encryption strategies to address the harvest now decrypt later risk.
- Retention schedule reference
- Data classification records
- Re encryption project plan
- Approval records for residual risk
- Archive storage outside re encryption plan
- Off site or tape archives forgotten
- Vendor escrow data not addressed
Risk Assessment
Assess and prioritise systems for migration based on data sensitivity, retention period, exposure, and protection lifetime requirements.
- Risk assessment methodology document
- Prioritisation matrix scoring each system
- Data lifetime analysis showing retention requirements
- Approval records for prioritisation outcome
- Data lifetime requirements not documented
- Mission critical systems deprioritised due to vendor readiness
- Risk scoring without input from data owners
Software Engineering
Refactor application code to use updated cryptographic libraries that support CNSA 2.0 algorithms, replacing deprecated functions and ensuring backwards compatibility where required.
- Code inventory of cryptographic function calls
- Refactor work orders and code review records
- Updated unit and integration test coverage
- Library version tracking
- Static analysis not run for cryptographic API usage
- Refactor backlog not prioritised by risk
- Vendor supplied code outside refactor scope
Supply Chain
Engage product and service vendors to obtain CNSA 2.0 migration roadmap commitments and integrate them into procurement and renewal planning.
- Vendor questionnaire responses on CNSA 2.0 readiness
- Vendor product roadmap documentation
- Updated contracts including transition clauses
- Vendor risk assessments
- Vendor roadmaps not collected centrally
- Open source dependencies excluded from engagement
- No exit plan for vendors lacking roadmap
Transition Operations
Where approved, define and operate hybrid algorithm strategies that combine legacy and next-generation algorithm transition components to maintain interoperability during migration.
- Hybrid algorithm architecture document
- Approval records by authorising official
- Configuration evidence for hybrid mode
- Sunset plan with cutover dates
- Hybrid mode lacks documented sunset
- No monitoring of which algorithm is selected per session
- Hybrid mode applied to systems where pure CNSA 2.0 is feasible
Workforce
Develop and deliver training and capability building for engineering, security, procurement, and operations teams on next-generation algorithm transition activities.
- Curriculum and learning pathways
- Attendance and completion records
- Capability assessment results
- Continuing education plan
- Procurement excluded from curriculum
- Operations staff training limited to documentation review
- No refresher cadence
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the NSA Guidance for Transition to Quantum-Resistant Cryptography framework page.