The CSfC programme compresses the per-technology timeline into one: in 2026 NIAP updates the relevant protection profiles and CSfC adds CNSA 2.0 and software and firmware signing to the Mobile Access, Campus WLAN, Multi-Site Connectivity and Data-at-Rest capability packages and the key management annex as objective requirements; from 2027 components with CNSA 2.0 appear on the Components List; in 2028 the capability packages require CNSA 2.0 for all encryption and signing; by 2030 every registered solution has CNSA 2.0 or other post-quantum mitigations on all its layers. Key exchange moves to ML-KEM, signatures to ML-DSA, hashing to SHA-384 or SHA-512; TLS 1.3 is mandated for CSfC TLS components and EAP-TLS; CAs and CRLs move to the new algorithms, and customers should consider limiting the validity of CNSA 1.0 CA certificates to the CNSA 2.0 mandate date. The addendum states its timeline may change with vendor and customer feedback.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.