Back to Frameworks

NSA Guidance for Transition to Quantum-Resistant Cryptography

United States (National Security Agency)
v2023
23 domains
29 controls

The NSA provides guidance for migrating to quantum‑resistant cryptography, including the Commercial National Security Algorithm Suite (CNSA) Suite 2.0 (2022), the "Quantum Computing and Post‑Quantum Cryptography FAQ" (2022), and the formal "NSA Guidance for Transition to Quantum‑Resistant Cryptography" (2023). These documents outline recommended algorithms, migration timelines, and implementation considerations for U.S. government and industry partners.

Unverified

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (23)

Algorithm Migration

3 controls
Controls in the Algorithm Migration domain of NSA Guidance for Transition to Quantum-Resistant Cryptography3 controls
CodeTitle
QRCM-3.1Hybrid Solution Deployment (2025-2030)
QRCM-3.2CNSA 2.0 Algorithm Preference
QRCM-3.3RSA/ECC Deprecation

Architecture

1 controls
Controls in the Architecture domain of NSA Guidance for Transition to Quantum-Resistant Cryptography1 controls
CodeTitle
QRMIG-07Cryptographic Agility

Assurance

2 controls
Controls in the Assurance domain of NSA Guidance for Transition to Quantum-Resistant Cryptography2 controls
CodeTitle
QRMIG-16Testing and Validation Programme
QRMIG-19Post Migration Assurance

Cloud

1 controls
Controls in the Cloud domain of NSA Guidance for Transition to Quantum-Resistant Cryptography1 controls
CodeTitle
QRMIG-11Cloud Service Transition

Communications

1 controls
Controls in the Communications domain of NSA Guidance for Transition to Quantum-Resistant Cryptography1 controls
CodeTitle
QRMIG-17Communication and Stakeholder Reporting

Cryptographic Inventory and Discovery

3 controls
Controls in the Cryptographic Inventory and Discovery domain of NSA Guidance for Transition to Quantum-Resistant Cryptography3 controls
CodeTitle
QRCM-1.1Cryptographic Asset Inventory
QRCM-1.2Quantum-Vulnerable Identification
QRCM-1.3Data Classification for Migration

Decommissioning

1 controls
Controls in the Decommissioning domain of NSA Guidance for Transition to Quantum-Resistant Cryptography1 controls
CodeTitle
QRMIG-20Decommissioning of Legacy Cryptography

Federal Compliance

3 controls
Controls in the Federal Compliance domain of NSA Guidance for Transition to Quantum-Resistant Cryptography3 controls
CodeTitle
QRCM-4.1NSM-10 Compliance
QRCM-4.2TLS 1.3 Adoption
QRCM-4.3Quantum-Safe Product Categories

Identity

1 controls
Controls in the Identity domain of NSA Guidance for Transition to Quantum-Resistant Cryptography1 controls
CodeTitle
QRMIG-12Identity Federation and Smart Cards

Inventory

1 controls
Controls in the Inventory domain of NSA Guidance for Transition to Quantum-Resistant Cryptography1 controls
CodeTitle
QRMIG-02Cryptographic Asset Discovery

Key Management

1 controls
Controls in the Key Management domain of NSA Guidance for Transition to Quantum-Resistant Cryptography1 controls
CodeTitle
QRMIG-09Key Management Modernisation

Migration Planning

0 controls

Transitioning to post-quantum cryptography

Network Security

1 controls
Controls in the Network Security domain of NSA Guidance for Transition to Quantum-Resistant Cryptography1 controls
CodeTitle
QRMIG-13Network Device Transition

OT and Embedded

1 controls
Controls in the OT and Embedded domain of NSA Guidance for Transition to Quantum-Resistant Cryptography1 controls
CodeTitle
QRMIG-14Operational Technology

PKI

1 controls
Controls in the PKI domain of NSA Guidance for Transition to Quantum-Resistant Cryptography1 controls
CodeTitle
QRMIG-08Public Key Infrastructure Update

Pilot Programme

1 controls
Controls in the Pilot Programme domain of NSA Guidance for Transition to Quantum-Resistant Cryptography1 controls
CodeTitle
QRMIG-05Pilot Implementation

Programme Governance

1 controls
Controls in the Programme Governance domain of NSA Guidance for Transition to Quantum-Resistant Cryptography1 controls
CodeTitle
QRMIG-01Migration Programme Establishment

Records

1 controls
Controls in the Records domain of NSA Guidance for Transition to Quantum-Resistant Cryptography1 controls
CodeTitle
QRMIG-15Records Retention and Long Lived Data

Risk Assessment

1 controls
Controls in the Risk Assessment domain of NSA Guidance for Transition to Quantum-Resistant Cryptography1 controls
CodeTitle
QRMIG-03Prioritisation and Risk Assessment

Software Engineering

1 controls
Controls in the Software Engineering domain of NSA Guidance for Transition to Quantum-Resistant Cryptography1 controls
CodeTitle
QRMIG-10Application Code Refactor

Supply Chain

1 controls
Controls in the Supply Chain domain of NSA Guidance for Transition to Quantum-Resistant Cryptography1 controls
CodeTitle
QRMIG-04Vendor Engagement and Roadmaps

Transition Operations

1 controls
Controls in the Transition Operations domain of NSA Guidance for Transition to Quantum-Resistant Cryptography1 controls
CodeTitle
QRMIG-06Hybrid Algorithm Strategy

Workforce

1 controls
Controls in the Workforce domain of NSA Guidance for Transition to Quantum-Resistant Cryptography1 controls
CodeTitle
QRMIG-18Training and Capability Building

Your Compliance Coverage

If you comply with NSA Guidance for Transition to Quantum-Resistant Cryptography, you already cover:

Maps to 81 other frameworks

29 total controls
SLSA
5 source controls mapped|2 target controls covered
17%
SIG (Shared Assessments)
5 source controls mapped|3 target controls covered
17%
OWASP SAMM
5 source controls mapped|2 target controls covered
17%
ISO/SAE 21434
5 source controls mapped|6 target controls covered
17%
ISO/IEC 27010:2015
5 source controls mapped|3 target controls covered
17%
ISO 27043
5 source controls mapped|6 target controls covered
17%
TISAX - Trusted Information Security Assessment Exchange
4 source controls mapped|1 target controls covered
14%
Sigstore - Software Artifact Signing and Verification
4 source controls mapped|2 target controls covered
14%
NIST SP 800-53 Rev 5
4 source controls mapped|4 target controls covered
14%
NIST SP 800-190
4 source controls mapped|2 target controls covered
14%
AWS Well-Architected Security Pillar
4 source controls mapped|2 target controls covered
14%
Azure Security Benchmark
4 source controls mapped|2 target controls covered
14%
ISO 27017
4 source controls mapped|2 target controls covered
14%
ISO 27018
4 source controls mapped|2 target controls covered
14%
BSI IT-Grundschutz
4 source controls mapped|2 target controls covered
14%
CISA Cross-Sector Cybersecurity Performance Goals (CPG) 2.0
4 source controls mapped|4 target controls covered
14%
Virginia CDPA
3 source controls mapped|1 target controls covered
10%
Uruguay DPL
3 source controls mapped|1 target controls covered
10%
Texas Data Privacy Act
3 source controls mapped|1 target controls covered
10%
Taiwan PDPA
3 source controls mapped|1 target controls covered
10%
Secure by Design: A Guide for Manufacturers (CISA)
3 source controls mapped|1 target controls covered
10%
FTC GLBA Safeguards Rule (16 CFR Part 314)
3 source controls mapped|1 target controls covered
10%
FIDO2 / WebAuthn
3 source controls mapped|1 target controls covered
10%
10%
ASD Strategies to Mitigate Cyber Security Incidents
3 source controls mapped|1 target controls covered
10%
APRA CPS 234
3 source controls mapped|1 target controls covered
10%
ISO/IEC 27400:2022
3 source controls mapped|1 target controls covered
10%
PCI SSF
3 source controls mapped|1 target controls covered
10%
ISO/IEC 27011:2024
3 source controls mapped|1 target controls covered
10%
NIST AI Risk Management Framework (AI RMF 1.0)
3 source controls mapped|1 target controls covered
10%
APPI
3 source controls mapped|1 target controls covered
10%
NIST SP 800-171A Rev 3 - Assessing CUI Security Requirements
3 source controls mapped|3 target controls covered
10%
AS9100D:2016 - Quality Management Systems for Aviation, Space, and Defence
3 source controls mapped|1 target controls covered
10%
ISO 27005
3 source controls mapped|1 target controls covered
10%
ISO 20000-1
3 source controls mapped|1 target controls covered
10%
ISO 13485
3 source controls mapped|2 target controls covered
10%
ISO/IEC 23837 - Security Requirements for Quantum Key Distribution
3 source controls mapped|3 target controls covered
10%
ISO/IEC 29115:2023 - Entity Authentication Assurance Framework
3 source controls mapped|1 target controls covered
10%
IEC 62351 - Power Systems Communication Security
3 source controls mapped|1 target controls covered
10%
ISO 27799
3 source controls mapped|2 target controls covered
10%
FFIEC IT Examination Handbook
3 source controls mapped|1 target controls covered
10%
FBI CJIS Security Policy
3 source controls mapped|2 target controls covered
10%
PCI PIN Security
3 source controls mapped|1 target controls covered
10%
PCI P2PE
3 source controls mapped|1 target controls covered
10%
ISO/IEC 27557:2022 - Organisational Privacy Risk Management
3 source controls mapped|1 target controls covered
10%
ISO 22739:2024 - Blockchain and Distributed Ledger Technologies Vocabulary
3 source controls mapped|1 target controls covered
10%
ISO 19011
3 source controls mapped|1 target controls covered
10%
10%
ISO 31000:2018
3 source controls mapped|1 target controls covered
10%
Bahrain PDPL
3 source controls mapped|1 target controls covered
10%
MARS-E - Minimum Acceptable Risk Standards for Exchanges
3 source controls mapped|1 target controls covered
10%
3GPP 5G Security Architecture (TS 33.501)
3 source controls mapped|1 target controls covered
10%
ISO 45001:2018
1 source controls mapped|1 target controls covered
3%
ISO/IEC 42001:2023
1 source controls mapped|1 target controls covered
3%
ISO 22301:2019
1 source controls mapped|1 target controls covered
3%
ISO 22000:2018
1 source controls mapped|1 target controls covered
3%
ISO 55001:2014
1 source controls mapped|1 target controls covered
3%
ISO 37301:2021
1 source controls mapped|1 target controls covered
3%
ISO 37001:2016
1 source controls mapped|1 target controls covered
3%
ISO 50001:2018 - Energy Management Systems
1 source controls mapped|2 target controls covered
3%
ISO 27701:2019
1 source controls mapped|1 target controls covered
3%
ISO 14001:2015
1 source controls mapped|1 target controls covered
3%
ISO 9001:2015
1 source controls mapped|1 target controls covered
3%
ISO 13485:2016
1 source controls mapped|1 target controls covered
3%
ISO 14004:2016
1 source controls mapped|1 target controls covered
3%
ISO 27018:2019
1 source controls mapped|1 target controls covered
3%
ISO/IEC 38500:2024 - Governance of IT
1 source controls mapped|1 target controls covered
3%
UK AI Regulation Framework
1 source controls mapped|1 target controls covered
3%
FDA Quality Management System Regulation (QMSR)
1 source controls mapped|1 target controls covered
3%
API 1164
1 source controls mapped|1 target controls covered
3%
ISO 14064 - Greenhouse Gas Accounting and Verification (Parts 1-3)
1 source controls mapped|1 target controls covered
3%
IEC 62443
1 source controls mapped|1 target controls covered
3%
ISO 27019
1 source controls mapped|1 target controls covered
3%
21 CFR Part 211 - Current Good Manufacturing Practice
1 source controls mapped|3 target controls covered
3%
NIST SP 1800-32
1 source controls mapped|1 target controls covered
3%
IEC 60601-1 - Medical Electrical Equipment Safety
1 source controls mapped|1 target controls covered
3%

Frequently Asked Questions

What is NSA Guidance for Transition to Quantum-Resistant Cryptography?

NSA Guidance for Transition to Quantum-Resistant Cryptography is a compliance framework from United States (National Security Agency) with 23 domains and 29 controls. The NSA provides guidance for migrating to quantum‑resistant cryptography, including the Commercial National Security Algorithm Suite (CNSA) Suite 2.0 (2022), the "Quantum Computing and Post‑Quantum Cryptography FAQ" (2022), and the formal "NSA Guidance for Transition to Quantum‑Resistant Cryptography" (2023). These documents outline recommended algorithms, migration timelines, and implementation considerations for U.S. government and industry partners. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

How many controls does NSA Guidance for Transition to Quantum-Resistant Cryptography have?

NSA Guidance for Transition to Quantum-Resistant Cryptography has 29 controls organised across 23 domains. The largest domains are Algorithm Migration (3 controls), Cryptographic Inventory and Discovery (3 controls), Federal Compliance (3 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

What frameworks does NSA Guidance for Transition to Quantum-Resistant Cryptography map to?

NSA Guidance for Transition to Quantum-Resistant Cryptography maps to 81 other compliance frameworks. The top mapping partners are SLSA (17% coverage), SIG (Shared Assessments) (17% coverage), OWASP SAMM (17% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I get started with NSA Guidance for Transition to Quantum-Resistant Cryptography compliance?

Start your NSA Guidance for Transition to Quantum-Resistant Cryptography compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about NSA Guidance for Transition to Quantum-Resistant Cryptography requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 29 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 718 frameworks.

Get Started Free →

Free forever — no credit card required