For digital signatures of software and firmware, CNSSP 15 Annex B lists the stateful hash-based signatures of NIST SP 800-208 as algorithms allowed in specific applications: the Leighton-Micali Signature (LMS) and the eXtended Merkle Signature Scheme (XMSS), all parameters appropriate to protect up to TOP SECRET, with LMS-SHA-256/192 recommended (the XMSS row repeats the LMS recommendation, apparently a copy slip in the table). The multi-tree HSS and XMSS-MT are not allowed (FAQ). To avoid weakening the signatures every SP 800-208 requirement must be met, including state management (a one-time key is never used twice) and signing in hardware such as an HSM, with backup flows that transfer keys between modules preventing state reuse. Annex B note d expects NSS hardware vendors who must move firmware signatures to quantum-resistant ones before ML-DSA-87 is available, to meet NSM-10 transition requirements, to rely on SP 800-208 signature validation to protect firmware. These algorithms were chosen because NIST had standardised them with CAVP validation available and firmware validation is the most urgent use case, often locked in for the life of a system.
This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.