Commercial National Security Algorithm Suite (CNSA) 2.0
Validation and product acceptance: NIAP, CAVP, CMVP and hardware-backed signing – Commercial National Security Algorithm Suite (CNSA) 2.0

Commercial National Security Algorithm Suite (CNSA) 2.0 VAL-NIAP: VAL-NIAP Commercial products validated by NIAP against protection profiles that require CNSA 2.0; verification-only TOEs need CAVP not CMVP

Under CNSSP 11 commercial products used in NSS must be NIAP-validated against an approved protection profile, and NIAP profiles will require CNSA 2.0 consistent with NSA's published transition timelines, so a vendor learns whether its SP 800-208 implementation meets CNSA 2.0 through NIAP validation; NSA does not anticipate protection profiles performing signature generation within the target-of-evaluation boundary, only verification, so where a product only verifies signatures CAVP validation suffices. Quantum-resistant algorithms are to be implemented in NSS mission systems as NIAP-validated products or under other implementation-specific guidance, typically including CMVP-validated modules, and NSA generally approves CNSSP 11-compliant products configured correctly under CNSSP 15 and other direction.

Maintained by Gerard BlokdykControl text last updated

Other controls in Validation and product acceptance: NIAP, CAVP, CMVP and hardware-backed signing – Commercial National Security Algorithm Suite (CNSA) 2.0

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.