NSA will not require hybrid solutions for security and says not to use a hybrid or other non-standardised quantum-resistant solution on NSS mission systems except where NSA specifically recommends one for standardisation or interoperability; limited purchase and use for research and planning toward CNSA 2.0 is encouraged, but such solutions will not be built into deployable solutions. The named exception is IKEv2, where NSA's profile keeps a CNSA 1.0 initial key establishment fortified by an ML-KEM-1024 exchange. Hybrids that add a symmetric key under established standards (RFC 8773, RFC 8784) may be appropriate in specialised applications. NSA's January 2025 presentation adds that PKI moves by coexistence (separate RSA, ECDSA and ML-DSA certificates in one ecosystem), not by composite certificates carrying both.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.