NSA Guidance for Transition to Quantum-Resistant Cryptography
NSA transition positions: hybrids, quantum alternatives, pre-shared keys, CSfC, PKI and roots of trust – NSA Guidance for Transition to Quantum-Resistant Cryptography

NSA Guidance for Transition to Quantum-Resistant Cryptography Q-HYBRID: Q-HYBRID No hybrid or non-standardised quantum-resistant solution on NSS mission systems outside NSA's named exceptions

NSA will not require hybrid solutions for security and says not to use a hybrid or other non-standardised quantum-resistant solution on NSS mission systems except where NSA specifically recommends one for standardisation or interoperability; limited purchase and use for research and planning toward CNSA 2.0 is encouraged, but such solutions will not be built into deployable solutions. The named exception is IKEv2, where NSA's profile keeps a CNSA 1.0 initial key establishment fortified by an ML-KEM-1024 exchange. Hybrids that add a symmetric key under established standards (RFC 8773, RFC 8784) may be appropriate in specialised applications. NSA's January 2025 presentation adds that PKI moves by coexistence (separate RSA, ECDSA and ML-DSA certificates in one ecosystem), not by composite certificates carrying both.

Maintained by Gerard BlokdykControl text last updated

Other controls in NSA transition positions: hybrids, quantum alternatives, pre-shared keys, CSfC, PKI and roots of trust – NSA Guidance for Transition to Quantum-Resistant Cryptography

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.