NSA (1 Oct): post-quantum cryptography measures for NSS — CNSA 2.0 for new commercial NSS by 2027; legacy phase-out by 2030
NSA press release (1 October 2026) announces expanded post-quantum cryptography (PQC) initiatives for National Security Systems (NSS), the Department of War, and the Defense Industrial Base, aligned with Executive Order 14412 and CNSSP-15. Starting in 2027, all new commercial NSS must support quantum-resistant (CNSA 2.0) algorithms; legacy systems that cannot support quantum-resilient algorithms are to be phased out by 2030. NSA highlights adversary “harvest now, decrypt later” and “trust now, exploit later” risks and points stakeholders to Cybersecurity Collaboration Center DIB services and Zero Trust implementation guidelines. Distinct from desk cloudflare-pq-ca-mtc-20260929 (public CA / Merkle Tree Certificates). Primary: NSA press release 1 Oct 2026.
- Product
- NSA post-quantum cryptography transition guidance for National Security Systems (not a product CVE)
- Versions
- n/a — policy/timeline: new commercial NSS quantum-resistant capable from 2027; unsupported legacy phase-out by 2030 (per NSA 1 Oct 2026)
- Exploited in Australia?
- unknown
- Patch to
- No CVE. NSS/DIB and aligned enterprises: inventory crypto (TLS, VPN, code-signing, PKI); plan CNSA 2.0 / NIST PQC migration before 2027 new-system gate and 2030 legacy sunset; prefer standardized PQC over QKD for NSS unless limitations are overcome (NSA guidance). AU orgs: same crypto-inventory discipline alongside ACSC guidance.
Primary: NSA — Post-Quantum Cryptography Measures for NSS (1 Oct 2026) · Vendor: NSA — Post-Quantum Cybersecurity Resources hub · NSA — Post-Quantum Cryptography: A Digital Armor (resource)
