Under CNSSP 11 commercial products used in NSS must be NIAP-validated against an approved protection profile, and NIAP profiles will require CNSA 2.0 consistent with NSA's published transition timelines, so a vendor learns whether its SP 800-208 implementation meets CNSA 2.0 through NIAP validation; NSA does not anticipate protection profiles performing signature generation within the target-of-evaluation boundary, only verification, so where a product only verifies signatures CAVP validation suffices. Quantum-resistant algorithms are to be implemented in NSS mission systems as NIAP-validated products or under other implementation-specific guidance, typically including CMVP-validated modules, and NSA generally approves CNSSP 11-compliant products configured correctly under CNSSP 15 and other direction.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.