Commercial National Security Algorithm Suite (CNSA) 2.0
The suite: approved algorithms, parameters and what is not approved – Commercial National Security Algorithm Suite (CNSA) 2.0

Commercial National Security Algorithm Suite (CNSA) 2.0 ALG-DSA: ALG-DSA ML-DSA-87 (FIPS 204) for digital signatures in any use case; HashML-DSA, FN-DSA and SLH-DSA are not approved

The asymmetric algorithm for digital signatures in any use case, including software and firmware signing, is ML-DSA (FIPS 204), previously CRYSTALS-Dilithium, at ML-DSA-87 to protect information up to TOP SECRET, as CNSSP 15 Annex B lists it among the general purpose algorithms; only ML-DSA as specified in FIPS 204 is compliant. HashML-DSA, the pre-hash mode of FIPS 204, is not allowed at present because it offers nothing the CNSA hash functions combined with ML-DSA-87 do not; FN-DSA (Falcon) is not expected to be added, being more susceptible to implementation errors; SLH-DSA (SPHINCS+) is not part of CNSA and not approved for any NSS use (FAQ). Annex B note c adds that software signing infrastructures that are highly distributed, high volume or virtualised and may not be able to meet NIST SP 800-208 should make sure they transition to ML-DSA-87. Annex A dates FIPS 204 to 24 August 2023, the draft; the final standard was published in August 2024.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • PRIMITIVES Choose the recommended post-quantum and symmetric primitives and parameters

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in The suite: approved algorithms, parameters and what is not approved – Commercial National Security Algorithm Suite (CNSA) 2.0

Query this from an agent

The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.