Post-Quantum Cryptography for Defense and Military.
NSA CNSA 2.0 requires National Security Systems to complete post-quantum migration by 2033. CMMC 2.0 mandates cryptographic controls for defense contractors handling CUI. Quantumize deploys ML-KEM (FIPS 203), ML-DSA (FIPS 204), and SLH-DSA (FIPS 205) across the defense industrial base with the audit trail primes and DoD auditors expect.
Challenges
- CUI and Classified Data Are Primary Harvest Targets: Controlled Unclassified Information, program data, acquisition documents, and technical specifications are exactly the category of data nation-state adversaries prioritize for Harvest Now, Decrypt Later collection. Defense contractors handling CUI over classically encrypted channels are building adversary archives today.
- NSA CNSA 2.0 Mandates Intermediate Milestones Now: CNSA 2.0 sets 2033 as the final deadline for National Security Systems but includes intermediate milestones beginning in 2025. Contractors that wait for the hard deadline will migrate under pressure with a shrunken pool of available expertise and no negotiating room on schedule.
- CMMC 2.0 Cryptographic Controls: CMMC Level 2 and Level 3 assessments evaluate cryptographic implementation against NIST SP 800-171 controls. Auditors are beginning to ask about post-quantum readiness planning. Contractors without a documented CBOM and migration roadmap face increasing CMMC audit risk.
- Supply Chain Cryptographic Risk: A prime contractor's own cryptographic posture is only as strong as the weakest subcontractor in its supply chain. ITAR-controlled technical data and CUI traverse the defense supply chain through dozens of tier-1 and tier-2 vendors. Quantumize surfaces supply chain cryptographic dependencies in the CBOM.
Regulatory and Policy Requirements
The defense sector faces the most aggressive post-quantum migration mandates of any vertical.
- NSA CNSA 2.0: National Security Algorithm Suite 2.0 specifies the post-quantum algorithms required for National Security Systems and sets migration deadlines starting with firmware/software signing in 2025.
- CMMC 2.0: Cybersecurity Maturity Model Certification requires defense contractors to implement cryptographic controls for CUI under NIST SP 800-171. Level 2 and Level 3 assessments will increasingly evaluate PQC readiness.
- NIST FIPS 203/204/205: The finalized NIST post-quantum standards that CNSA 2.0 mandates as the migration target for all NSS-adjacent systems.
- ITAR / EAR: International Traffic in Arms Regulations and Export Administration Regulations require cryptographic controls on technical data. Post-quantum encryption provides the forward-secure protection ITAR demands for long-lived program information.
- FAR/DFARS: Federal Acquisition Regulation and Defense Federal Acquisition Regulation Supplement incorporate cybersecurity requirements including NIST SP 800-171 compliance for contractors handling covered defense information.
How Quantumize Helps
- CUI Encryption With ML-KEM (FIPS 203): Protect Controlled Unclassified Information at rest and in transit with NIST-standardized post-quantum encryption. Envelope encryption with hardware-backed key wrapping, KMS migration tooling, and Cryptographic Recovery Packages (CRP) for disaster scenarios.
- Code Signing With ML-DSA / SLH-DSA: Sign and verify firmware, software updates, and acquisition documents with ML-DSA (FIPS 204) or SLH-DSA (FIPS 205). Post-quantum digital signatures protect provenance for records that must remain verifiable for decades meeting CNSA 2.0 firmware signing milestones.
- WORM-Locked Audit Trail for CMMC Assessments: Every cryptographic operation, key event, and access decision is logged in a tamper-evident audit trail exportable to S3 Object Lock for CMMC assessment evidence. Role-Based Access Control with Admin / Crypto Officer / User separation meets SP 800-171 access control requirements.

