From 1 January 2027, unless excepted through public messaging on nsa.gov, a protection profile or a capabilities package, or waived through the waiver process, CNSA 2.0 algorithms are required in every new product and service that provides cryptographic protection for users or for updates. NIAP Policy Letter 33 (31 August 2026, held in cnsa-2/) carries the same date onto the NIAP Product Compliant List and into contracts.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.