# NSA Sets Post-Quantum Cryptography Timelines

The National Security Agency is urging organizations that support National Security Systems (NSS) to prepare for migration to post-quantum cryptography (PQC) under CNSSP 15. New commercial NSS must support CNSA 2.0 algorithms by 2027, while legacy systems are scheduled for phaseout by 2030. NSA points organizations to its technical guidance and work with NIST and NIAP as migration resources; the announcement identifies no solicitation or contract award.

- Contractors supporting NSS should assess cryptographic dependencies and plan for quantum-resistant algorithms, authentication, and compliant products against the 2027 and 2030 milestones.
- Product suppliers serving national security customers may need to account for CNSA 2.0 support in product roadmaps and procurement planning; the stated dates indicate a transition requirement, not a newly announced contract opportunity.
- NSA identifies technical guidance and collaboration with NIST and NIAP as resources for organizations planning the transition.

**Jurisdictions:** federal
**Industries:** Defense & Military, Information Technology
**Topics:** Cybersecurity, Regulatory Compliance
**Published:** October 01, 2026

### Government Entities
- National Security Agency (NSA)
- National Institute of Standards and Technology (NIST)
- National Information Assurance Partnership (NIAP)
- National Cybersecurity Center of Excellence (NCCoE)

### Key Quotes
> Based on the CNSA timeline, we are postured to implement quantum-resistant algorithms across our critical systems in less than 10 years.
> — Morgan Stern, Effort Lead for Quantum Resistance at NSA

### Sources
- [
	Post-Quantum Cryptography: A Digital Armor > National Security Agency/Central Security Service > Article
](https://www.nsa.gov/Press-Room/News-Highlights/Article/Article/4615936/post-quantum-cryptography-a-digital-armor) - National Security Agency (NSA) (.gov)