The asymmetric algorithm for digital signatures in any use case, including software and firmware signing, is ML-DSA (FIPS 204), previously CRYSTALS-Dilithium, at ML-DSA-87 to protect information up to TOP SECRET, as CNSSP 15 Annex B lists it among the general purpose algorithms; only ML-DSA as specified in FIPS 204 is compliant. HashML-DSA, the pre-hash mode of FIPS 204, is not allowed at present because it offers nothing the CNSA hash functions combined with ML-DSA-87 do not; FN-DSA (Falcon) is not expected to be added, being more susceptible to implementation errors; SLH-DSA (SPHINCS+) is not part of CNSA and not approved for any NSS use (FAQ). Annex B note c adds that software signing infrastructures that are highly distributed, high volume or virtualised and may not be able to meet NIST SP 800-208 should make sure they transition to ML-DSA-87. Annex A dates FIPS 204 to 24 August 2023, the draft; the final standard was published in August 2024.
This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.