# NSA Sets Post-Quantum Cryptography Requirements

The National Security Agency is advancing a post-quantum cryptography transition for National Security Systems (NSS): new commercial NSS must be capable of supporting CNSA 2.0 algorithms starting in 2027, while legacy systems that cannot support them are scheduled for phaseout by 2030 under CNSSP 15. NSA is developing transition resources and identifies work with NIST and NIAP as support for implementation. The signals announce no solicitation, contract award, or funding amount, but establish milestones relevant to suppliers serving NSS, the Department of War, and the Defense Industrial Base.

- Contractors should inventory cryptographic dependencies and assess whether products and system roadmaps can support quantum-resistant algorithms and crypto-agility by the 2027 milestone.
- Organizations with legacy NSS should account for the planned 2030 phaseout in modernization and replacement planning; the signals do not specify a procurement schedule or funding source.
- The discussion distinguishes capability from active deployment: the 2027 requirement is described as requiring new systems to be capable of supporting PQC, not necessarily that PQC is enabled or in use. NSA’s identified technical resources and NIST/NIAP work are relevant migration references.

**Jurisdictions:** federal
**Industries:** Defense & Military, Information Technology
**Topics:** Cybersecurity, Regulatory Compliance
**Published:** October 02, 2026

### Government Entities
- National Security Agency (NSA)
- National Institute of Standards and Technology (NIST)
- National Information Assurance Partnership (NIAP)
- Committee on National Security Systems (CNSS)
- Department of War (DOW)

### Key Quotes
> Based on the CNSA timeline, we are postured to implement quantum-resistant algorithms across our critical systems in less than 10 years.
> — Morgan Stern, Effort Lead for Quantum Resistance at NSA

> The requirement sounds really weak: “all new commercial NSS must be capable of supporting quantum-resistant algorithms.” Not using PQC, not existing companies, just “capable of supporting.”
> — Commenter

### Sources
- [
	Post-Quantum Cryptography: A Digital Armor > National Security Agency/Central Security Service > Article
](https://www.nsa.gov/Press-Room/News-Highlights/Article/Article/4615936/post-quantum-cryptography-a-digital-armor) - National Security Agency (NSA) (.gov)
- [NSA to Develop PQC Resources for National Security Systems](https://www.executivegov.com/articles/nsa-post-quantum-cryptography-resources) - ExecutiveGov
- [
	NSA Announces Post-Quantum Cryptography Measures to Safeguard National Security Systems Against Quantum Computing Threats > National Security Agency/Central Security Service > Press Release View
](https://www.nsa.gov/Press-Room/Press-Releases-Statements/Press-Release-View/Article/4615285/nsa-announces-post-quantum-cryptography-measures-to-safeguard-national-security/) - NSA