Commercial National Security Algorithm Suite (CNSA) 2.0
The suite: approved algorithms, parameters and what is not approved – Commercial National Security Algorithm Suite (CNSA) 2.0

Commercial National Security Algorithm Suite (CNSA) 2.0 ALG-SHA3: ALG-SHA3 SHA3-384 or SHA3-512 allowed only for internal hardware integrity processes

CNSSP 15 Annex B allows SHA3-384 or SHA3-512 (FIPS 202) for internal hardware functionality only, such as boot-up integrity checks; note b explains that, at a vendor's discretion, for internal components of a hardware system that do not interoperate outside the vendor's environment, SHA3-384 or SHA3-512 may be used as part of a system's integrity-checking process such as secure boot, beside SHA-384 and SHA-512. NSA allows this to speed the move of vendor-internal processes that rely on a hash to the new post-quantum signatures with minimal disruption, and nowhere else.

Maintained by Gerard BlokdykControl text last updated

Other controls in The suite: approved algorithms, parameters and what is not approved – Commercial National Security Algorithm Suite (CNSA) 2.0

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.