Skip to content

Which standard satisfies which obligation

A cross-reference from the thing you are required to do — post-quantum migration, phishing-resistant MFA, modern password policy, validated crypto — to the specific standard that defines how to do it.

LeadershipWorking6 min· Updated Jul 22, 2026

Obligations and standards are not the same thing. A regulation or contract tells you an outcome ("use phishing-resistant MFA," "migrate to post-quantum cryptography"); a standard tells you the concrete algorithm, protocol, or policy that meets it. This is the cross-reference between the two, so an auditor's question maps to a document you can point at.

Post-quantum migration

  • **Obligation: use post-quantum algorithms.** → NIST **FIPS 203** (ML-KEM), **FIPS 204** (ML-DSA), **FIPS 205** (SLH-DSA) define the approved algorithms.
  • **Obligation: national-security systems go quantum-safe on schedule.** → NSA **CNSA 2.0** sets the algorithm suite and timeline (toward 2033/2035).
  • **Obligation (US federal): inventory and prioritize cryptographic systems.** → **OMB M-23-02** and **NSM-10** mandate it; NIST **IR 8547** describes the transition; CISA guidance describes the how.
  • **Obligation: carry PQC in real protocols.** → **IETF** RFCs/drafts (hybrid TLS 1.3, IKEv2, X.509 via LAMPS).

Authentication and identity

  • **Obligation: modern password policy.** → NIST **SP 800-63B** (8-char minimum, 15+ recommended, screening, no forced rotation or composition rules).
  • **Obligation: phishing-resistant MFA** (e.g. US federal zero trust under **OMB M-22-09**). → **FIDO2/WebAuthn** (W3C + FIDO Alliance) or PKI/PIV-based authenticators.
  • **Obligation: assurance-level-appropriate authenticators.** → **SP 800-63B** authenticator assurance levels (AAL1–3).

Validated cryptography

  • **Obligation: use validated cryptographic modules** (common in federal and regulated contexts). → **FIPS 140-3** module validation, which now covers implementations of the PQC algorithms as they are added to the approved list.
  • **Obligation: general security-controls framework** (SOC 2, ISO/IEC 27001). → map crypto controls to **NIST SP 800-53** / **ISO/IEC 27001 Annex A**, citing the specific algorithm standards above as evidence.
From the audit floor

Keep the evidence trail two-layered

For each obligation, record both the outcome standard (what you must achieve) and the implementation standard (the FIPS/RFC/spec you used). "We use phishing-resistant MFA (M-22-09) implemented with FIDO2/WebAuthn" is auditable; "we use MFA" is not.