Commercial National Security Algorithm Suite (CNSA) 2.0
Validation and product acceptance: NIAP, CAVP, CMVP and hardware-backed signing – Commercial National Security Algorithm Suite (CNSA) 2.0

Commercial National Security Algorithm Suite (CNSA) 2.0 VAL-SIGN: VAL-SIGN NSS signers use CMVP-validated hardware per SP 800-208 with no waiver; verifiers need CAVP-validated code

Signature verification is expected to be performed by code validated under NIST's Cryptographic Algorithm Validation Program, and a product that only verifies signatures needs CAVP testing alone; code sources that are NSS must produce signatures according to SP 800-208, which requires hardware validated under the Cryptographic Module Validation Program or other NSA guidance, and waivers will not be granted for this; signers that are not themselves NSS are expected to use code of the same development and operational quality as validated code, that is, code that could pass CAVP testing.

Maintained by Gerard BlokdykControl text last updated

Other controls in Validation and product acceptance: NIAP, CAVP, CMVP and hardware-backed signing – Commercial National Security Algorithm Suite (CNSA) 2.0

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.