Commercial National Security Algorithm Suite (CNSA) 2.0
The suite: approved algorithms, parameters and what is not approved – Commercial National Security Algorithm Suite (CNSA) 2.0

Commercial National Security Algorithm Suite (CNSA) 2.0 ALG-SHA: ALG-SHA SHA-384 or SHA-512 as the general-purpose hash; no SHA-3 or SHAKE for general use

The Secure Hash Algorithm (FIPS 180-4) computes condensed representations of information using SHA-384 or SHA-512 to protect information up to TOP SECRET, as CNSSP 15 Annex B lists them among the general purpose algorithms; SHA-384 remains sufficient and SHA-512 is added for designers who prefer it for performance, subject to interoperability; adding SHA-512 is the only change from CNSA 1.0 among the hash and cipher entries. SHA-3 and SHAKE are not approved as general-purpose hash algorithms for NSS: Annex B note a states that algorithms using SHA3 as a component (the policy names LMS and ML-KEM) do not make SHA3 an approved hash function, so their use is limited to where an approved algorithm's standard prescribes them and to internal hardware processes; truncated hashes such as SHA-256/192 are acceptable within the algorithm that incorporates them.

Maintained by Gerard BlokdykControl text last updated

Other controls in The suite: approved algorithms, parameters and what is not approved – Commercial National Security Algorithm Suite (CNSA) 2.0

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.