Heads of U.S. Government departments and agencies must ensure compliance with the policy and give their unfulfilled cybersecurity requirements under it to the National Manager (Director, NSA, Cybersecurity Directorate, Cryptographic Transformation Office) consistent with NSM-10. Until they are fully compliant with CNSA 2.0 or other NSA-approved quantum-resistant algorithms, NSM-10's annual reporting on quantum-vulnerable systems continues, including new acquisitions.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.