The term on this page
- PQCpost-quantum cryptography
- algorithms that run on ordinary computers and are believed to resist quantum attack
Also mentioned
ML-KEMML-KEMModule-Lattice-based Key Encapsulation MechanismModule-Lattice-Based Key-Encapsulation Mechanism, the NIST-standardized post-quantum KEM derived from CRYSTALS-Kyber and specified in FIPS 203.Read the full entry (new tab), ML-DSAML-DSAModule-Lattice-based Digital Signature AlgorithmModule-Lattice-Based Digital Signature Algorithm, the NIST-standardized post-quantum signature scheme derived from CRYSTALS-Dilithium and specified in FIPS 204.Read the full entry (new tab), FIPSFIPSFederal Information Processing StandardFederal Information Processing Standards, publicly announced standards developed by NIST for use in U.S. government computer systems, including cryptographic algorithms and modules.Read the full entry (new tab), NISTNISTNational Institute of Standards and TechnologyThe U.S. National Institute of Standards and Technology, the agency that develops and publishes cryptographic standards, including the FIPS series and post-quantum algorithms.Read the full entry (new tab), CNSACNSACommercial National Security Algorithm SuiteThe Commercial National Security Algorithm Suite 2.0, the NSA's mandated algorithm set for US National Security Systems.Read the full entry (new tab) are defined in the glossary.
Read this first
On 1 October 2026, the NSA launched a post-quantum cryptography resource hub for the Department of War, National Security Systems and the Defense Industrial Base. It puts two near-term gates in one place: starting in 2027, all new commercial NSS must be capable of supporting quantum-resistant algorithms, while legacy systems that cannot support them are to be phased out by 2030. The announcement does not create a general mandate for commercial IT, and support is not the same as exclusive CNSA 2.0 use.
The new NSA Post-Quantum Cryptography Resource Hub is more than a reading list. It is an audience marker. The page is written for organizations that own, operate or supply national-security systems, and it places the 2027 acquisition gate beside the 2030 legacy-system gate before linking explainers, technical guidance and Defense Industrial Base services.
The accompanying NSA press release attributes those dates to Committee on National Security Systems Policy 15. It also ties the work to Executive Order 14412, which requires annual reporting on PQC migration for agencies operating NSS. The useful change is not a newly invented deadline. It is that the NSA now presents the policy, implementation resources and supplier audience as one operational programme.
Three different gates must not be collapsed
| Gate | What it requires | What it does not prove |
|---|---|---|
| 2027 support | New commercial NSS can support quantum-resistant algorithms | That every operational path already uses only CNSA 2.0 |
| 2030 phaseout | Legacy systems unable to support quantum-resistant algorithms leave the estate | That every remaining protocol has reached its final exclusive-use milestone |
| CNSA 2.0 waves | System categories move to the mandated algorithms on their published schedules | That a product-level PQC checkbox satisfies every protocol, validation and interoperability requirement |
Capability is the first distinction. A product can expose ML-KEM-1024 and ML-DSA-87 while still using classical cryptography in a protocol profile, certificate chain, recovery path or firmware-signing workflow. The refreshed CNSA 2.0 reference now records the 2027 and 2030 gates beside its algorithm and system-category timeline instead of treating them as interchangeable.
Retirement is the second distinction. The announcement says systems that cannot support quantum-resistant algorithms are to be phased out by 2030. That is a hardware, firmware and supplier-lifecycle test, not just a configuration target. A device with a fixed trust anchor, an unreplaceable secure element or no supported upgrade path can fail the 2030 gate even if a gateway in front of it negotiates a post-quantum connection.
This is not a mandate for every commercial system
The wording covers commercial products used as National Security Systems and the vendors that supply them. It does not turn every private-sector server into an NSS, and it does not replace the separate federal and NIST timelines collected on the PQC deadlines page. Scope must be established before the date is applied.
What a supplier must be able to show
- The exact CNSA 2.0 algorithms and parameter sets implemented, not a generic post-quantum label.
- Which protocols, certificate paths, code-signing chains and recovery mechanisms actually use those algorithms.
- Whether the cryptographic module and product configuration have the validations required by the receiving programme.
- How trust anchors, firmware and long-lived hardware can be upgraded if a protocol or implementation changes.
- Interoperability and negative-test evidence from the delivered build, including downgrade and rollback behavior.
- A retirement plan for components that cannot cross the 2030 capability boundary.
Those answers start with a cryptographic inventory that records products, protocols, modules, certificates and ownership. An inventory of algorithm names alone is too shallow: it cannot show whether an NSS acquisition is PQC-capable end to end or whether one fixed component prevents the legacy system from being upgraded.
What the new hub still leaves open
The hub does not publish a complete approved-product catalogue, a new cryptographic module validation shortcut or a universal protocol profile. It also does not make quantum key distribution an alternative to the software migration. One of its recommended resources states that the NSA does not recommend QKD or quantum cryptography for NSS as of June 2026. Vendors still have to map each requirement to the applicable CNSA 2.0 profile and acquisition language.
Executive Order 14412 keeps National Security Systems on a separate reporting track from federal High Value Assets and high-impact civilian systems. Its Section 4 deadlines explicitly exclude NSS, while Section 5 requires the NSA to report NSS migration status annually. Treating the NSA hub as a replacement for the civilian federal timeline would therefore erase the boundary the order itself preserves.
The practical consequence arrives before 2027
A system delivered in 2027 has to be designed, validated, procured and integrated before the calendar turns. Program offices should put the capability question into acceptance criteria now, and suppliers should connect every claim to an artifact that can survive an audit. A migration plan should separately track capability, active use and retirement so that passing one gate cannot hide failure at another.
The resource hub makes the near-term sequence easier to read: buy systems that can cross the quantum-resistant boundary, remove the ones that cannot, then complete the system-specific CNSA 2.0 waves. The dates were not born on October 1. What changed is that the NSA has given NSS owners and the Defense Industrial Base one public place to work from, close enough to the 2027 gate that procurement evidence now matters more than awareness.
References
- NSA announces post-quantum cryptography measures, published 1 October 2026.
- NSA Post-Quantum Cryptography Resource Hub, the new implementation and guidance collection for DOW, NSS and DIB organizations.
- CNSA 2.0 and Quantum Computing FAQ, the NSA algorithm selections and transition schedule.
- Executive Order 14412, including the separate NSS reporting requirement in Section 5(c).
- FIPS 203 and FIPS 204, the final ML-KEM and ML-DSA standards used by CNSA 2.0.