The Federal Mandate
US government policy establishes clear requirements for post-quantum cryptography migration across both National Security Systems and civilian federal agencies. NSA CNSA 2.0 (September 2022) and OMB M-23-02 (December 2022) together set the framework for the federal transition to post-quantum cryptography.
These directives reflect the recognition that the US government is a high-value target for nation-state adversaries conducting harvest-now-decrypt-later operations. Classified communications, national security information, and sensitive government data collected by adversaries today could be decrypted once quantum hardware matures.
NSA CNSA 2.0
NSA Commercial National Security Algorithm Suite 2.0 (CNSA 2.0), published September 2022, specifies the post-quantum algorithms required for all National Security Systems (NSS). NSS are systems that carry classified information or are otherwise designated as national security relevant by law or Executive Order.
CNSA 2.0 mandates ML-KEM-1024 for key encapsulation, ML-DSA-87 for digital signatures, SLH-DSA for code signing and additional signing contexts, and AES-256 for symmetric encryption. It sets a target year of 2033 for full transition and requires that vendors produce NSS-capable post-quantum products by 2025.
CNSA 2.0 also specifies timelines by system category. Government commercial products, software applications, and networking equipment each have specific transition timelines within the 2025-2033 window. Operators of NSS should consult the CNSA 2.0 advisory and associated NSA guidance for their specific system type.
OMB M-23-02
OMB Memorandum M-23-02 (December 2022) directs all federal civilian agencies to migrate their information systems to post-quantum cryptography. It requires agencies to inventory their cryptographic deployments, prioritize systems by risk, and develop migration plans aligned with NIST standards.
M-23-02 directed agencies to submit an initial cryptographic inventory by May 2023 and to develop an actionable migration plan. CISA was tasked with providing guidance and support for the inventory and migration process. Agencies should refer to the most current CISA guidance for current requirements and updated timelines.
M-23-02 applies to civilian federal agencies and does not supersede the NSA's authority over National Security Systems. Agencies operating systems across both civilian and NSS designations must comply with both M-23-02 and CNSA 2.0 as applicable.
Key Systems and Priorities
Government systems with long-lived classified or sensitive data are the highest-priority migration targets. Communications systems protecting data classified for decades, systems retaining personally identifiable information (PII) for years, and systems whose compromise could affect national security receive the highest migration priority.
Classified and sensitive communications
Systems protecting classified information must follow CNSA 2.0 requirements and NSA guidance. Transitions require NSA-approved cryptographic products.
Federal PKI
The Federal Public Key Infrastructure, including the Federal Bridge CA and agency CAs, must be migrated to support ML-DSA or hybrid certificate issuance. This affects every federal system that relies on TLS and certificate authentication.
Agency TLS infrastructure
Internet-facing and internal TLS configurations must be updated to support hybrid and then pure post-quantum key exchange. This is typically the most tractable early migration step.
Procurement and supply chain
Federal procurement requirements should mandate post-quantum readiness in new technology acquisitions. Supply-chain software used by agencies must be assessed for cryptographic dependencies.
Contractor and Supply Chain Implications
Federal contractors who handle government information or operate government systems may be subject to post-quantum requirements through contract terms, CMMC requirements, or FISMA obligations. Contractors should assess whether their cryptographic implementations meet the standards required by their government customers.
Software and hardware in the federal supply chain must be reviewed for post-quantum readiness. Agencies should engage vendors about their post-quantum roadmaps as part of standard procurement due diligence.

