To keep NSS interoperable, departments and agencies must use NSA-approved public standards-based cryptographic protocols, following NSA's protocol guidance such as RFC 9206 (CNSA suite for IPsec) and RFC 9151 (CNSA suite profile for TLS and DTLS 1.2 and 1.3), which still apply but need updating for the CNSA 2.0 algorithms. Any other cryptographic algorithm in an NSS needs approval from NSA Encryption Production and Solutions, and NSA may approve other algorithms for specific requirements with their own restrictions.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.