
The Most Urgent Quantum Threat
Government and defense organizations face the most acute quantum computing threat of any sector. Nation-state adversaries have both the motivation and the resources to build or acquire cryptographically relevant quantum computers (CRQCs). They also have the storage capacity and operational patience to execute harvest-now, decrypt-later campaigns at scale, capturing encrypted classified and sensitive communications today with the intent to decrypt them when quantum computing matures.
This is not a theoretical concern. Intelligence agencies worldwide are known to intercept and store encrypted communications as a matter of routine signals intelligence. The value of government and defense data, often classified for 25 years or more, means that data captured today could still be highly sensitive when a CRQC becomes operational. The U.S. government has recognized this urgency through a series of executive directives, memoranda, and agency guidance documents that mandate migration to post-quantum cryptography.
NSA CNSA 2.0: The Algorithm Suite
In September 2022, the National Security Agency (NSA) announced the Commercial National Security Algorithm Suite 2.0 (CNSA 2.0), replacing the original CNSA 1.0 suite. CNSA 2.0 defines the specific post-quantum algorithms that National Security Systems (NSS) must adopt. These requirements apply to all systems that process, store, or transmit classified or otherwise sensitive national security information.
The CNSA 2.0 algorithm requirements are:
| Function | Algorithm | Standard | Notes |
|---|---|---|---|
| Key Establishment | ML-KEM-1024 | FIPS 203 | NIST Security Level 5 (256-bit equivalent) |
| Digital Signatures | ML-DSA-87 | FIPS 204 | NIST Security Level 5 (256-bit equivalent) |
| Software/Firmware Signing | LMS or XMSS | SP 800-208 | Stateful hash-based signatures |
| Symmetric Encryption | AES-256 | FIPS 197 | Quantum-resistant at 128-bit post-quantum security |
| Hashing | SHA-384 or SHA-512 | FIPS 180-4 | Minimum 384-bit output for quantum resistance |
The selection of ML-KEM-1024 and ML-DSA-87 at NIST Security Level 5 reflects the government's requirement for the highest available security margin. Level 5 algorithms are designed to be at least as hard to break as AES-256, providing maximum protection against both classical and quantum attacks.
The inclusion of LMS and XMSS for software and firmware signing is notable. These stateful hash-based signature schemes, specified in NIST SP 800-208, rely on the security of hash functions alone, making them among the most conservative and well-understood post-quantum signature algorithms available. Their statefulness (each signing key can only produce a limited number of signatures, and state must be carefully managed) makes them suitable for firmware signing where the signing device is controlled and the number of signatures is predictable.
CNSA 2.0 Migration Timeline
NSA has published specific deadlines for CNSA 2.0 adoption across different system categories:
| System Category | Requirement | Deadline |
|---|---|---|
| Software and firmware signing | LMS or XMSS | 2025 |
| Web browsers and servers | ML-KEM-1024 | 2025 |
| Traditional networking equipment | ML-KEM-1024, ML-DSA-87 | 2030 |
| Operating systems | Full CNSA 2.0 suite | 2030 |
| Niche equipment and custom applications | Full CNSA 2.0 suite | 2033 |
| All National Security Systems | Complete migration | 2033 |
These dates are not aspirational targets. They are requirements. Systems that do not meet these deadlines will not be authorized to operate on National Security Systems. The 2025 deadline for software signing and web infrastructure is already upon us, making immediate action necessary for affected systems.
Federal Policy Framework
The CNSA 2.0 requirements exist within a broader framework of executive directives and policy memoranda that mandate federal action on post-quantum cryptography.
Executive Order 14028 (May 12, 2021)
Executive Order 14028, "Improving the Nation's Cybersecurity," was signed by President Biden on May 12, 2021. While not exclusively focused on quantum threats, it established the foundation for the federal government's cybersecurity modernization effort. The order directed agencies to adopt zero trust architectures, improve supply chain security, and modernize their encryption practices. It created the urgency and institutional mechanisms that subsequent quantum-specific directives built upon.
National Security Memorandum NSM-10 (May 4, 2022)
NSM-10, "Promoting United States Leadership in Quantum Computing While Mitigating Risks to Vulnerable Cryptographic Systems," was signed on May 4, 2022. This memorandum directly addresses the quantum cryptographic threat and includes several concrete mandates:
- Federal agencies must inventory all cryptographic systems, identifying those that are vulnerable to quantum attack
- Agencies must prioritize the transition of vulnerable systems to quantum-resistant cryptography
- The Director of National Intelligence and the Secretary of Defense must identify systems at highest risk
- Agencies must develop migration plans with timelines aligned to NIST standards
NSM-10 made the quantum cryptographic threat an explicit priority for every federal agency, not just defense and intelligence organizations.
OMB Memorandum M-23-02 (November 2022)
OMB M-23-02, "Migrating to Post-Quantum Cryptography," implements NSM-10 by requiring federal agencies to submit a cryptographic inventory to CISA and the National Cyber Director. This inventory must identify all systems using public-key cryptography, the specific algorithms in use, and the data protection requirements of each system. The memorandum establishes the operational framework for the government-wide migration to post-quantum cryptography.
CISA Post-Quantum Cryptography Guidance
The Cybersecurity and Infrastructure Security Agency (CISA) has published guidance to help federal agencies and critical infrastructure operators prepare for the post-quantum transition. CISA's recommendations include inventorying cryptographic dependencies, prioritizing high-value assets, testing post-quantum algorithms in existing infrastructure, and developing migration roadmaps. CISA has emphasized that organizations should not wait for a quantum computer to arrive before beginning their migration.
Classified vs. Unclassified Requirements
The requirements for classified and unclassified systems differ in both urgency and specifics:
Classified Systems (NSS)
National Security Systems are governed directly by CNSA 2.0 and must use the specific algorithms and security levels mandated by NSA. These systems require ML-KEM-1024 (not ML-KEM-512 or ML-KEM-768) and ML-DSA-87 (not ML-DSA-44 or ML-DSA-65). There is no discretion in algorithm selection: Level 5 is the minimum. Compliance is enforced through the certification and accreditation process, and non-compliant systems lose their Authorization to Operate (ATO).
Unclassified Federal Systems (Non-NSS)
Non-NSS federal systems are governed by NIST standards (FIPS 203, FIPS 204) and OMB policy. These systems have more flexibility in algorithm selection. ML-KEM-512 (Security Level 1) is acceptable for many use cases, while ML-KEM-768 (Security Level 3) and ML-KEM-1024 (Security Level 5) are recommended for higher-sensitivity data. The migration timeline is driven by OMB M-23-02 rather than CNSA 2.0, but the direction is the same: migrate to post-quantum cryptography as soon as practical.
Defense Industrial Base
Defense contractors and suppliers who handle Controlled Unclassified Information (CUI) under DFARS 252.204-7012 and CMMC are increasingly expected to align with post-quantum standards. While CNSA 2.0 does not directly bind contractors for unclassified work, contract requirements are expected to evolve as the government's own migration progresses. Organizations in the defense supply chain that adopt post-quantum encryption early position themselves for future contract compliance requirements.
How QNSQY Aligns with Government Requirements
QNSQY implements the full spectrum of algorithms required by CNSA 2.0 and NIST post-quantum standards:
ML-KEM-1024 (FIPS 203, Security Level 5)
QNSQY supports ML-KEM at all three NIST security levels: ML-KEM-512, ML-KEM-768, and ML-KEM-1024. For government and defense use cases requiring CNSA 2.0 compliance, ML-KEM-1024 provides the mandated Security Level 5 key encapsulation. All ML-KEM operations are hybridized with X25519, providing defense-in-depth: an attacker must break both the post-quantum and classical key exchange to recover the encryption key.
ML-DSA-87 (FIPS 204, Security Level 5)
Digital signatures use ML-DSA at the required security level. ML-DSA-87 provides Security Level 5 signatures for document authentication, audit log integrity, and chain-of-custody verification. Like key encapsulation, all ML-DSA signatures are hybridized with Ed25519.
LMS Stateful Hash-Based Signatures (SP 800-208)
QNSQY's Business tier includes LMS signature support as specified in NIST SP 800-208, meeting the CNSA 2.0 requirement for software and firmware signing. LMS signatures are based solely on hash function security, making them one of the most conservative post-quantum signature schemes available. QNSQY manages the stateful signing key lifecycle to prevent the critical error of key reuse, which would compromise the security of stateful signature schemes.
AES-256-GCM (FIPS 197)
All symmetric encryption uses AES-256-GCM, meeting the CNSA 2.0 requirement for AES-256 symmetric encryption. AES-256-GCM provides both confidentiality and authentication in a single operation, protecting against both eavesdropping and data tampering.
Air-Gapped Operation
For defense and classified environments, air-gapped operation is not optional. QNSQY's CLI enforces network isolation at the kernel level using Linux seccomp-bpf system call filtering. All network-related system calls are blocked with a KillProcess action, meaning that even a compromised library loaded into the QNSQY process cannot establish a network connection. File content, encryption keys, and passwords never leave the machine under any circumstances.
This architecture is critical for defense use cases where data must remain within a physically controlled environment. QNSQY can operate on fully air-gapped workstations with no network connectivity whatsoever. The only network access permitted is to the billing API, and this access is unnecessary on machines with offline license activation.
Audit Trail and SIEM Integration
Government security policies require comprehensive audit trails for all cryptographic operations. QNSQY logs every encryption, decryption, key generation, signature, and verification operation with tamper-evident integrity protection. Audit logs can be exported in standard formats for integration with Security Information and Event Management (SIEM) platforms, supporting continuous monitoring requirements under federal cybersecurity frameworks.
Migration Planning for Government Organizations
The NSM-10 and OMB M-23-02 framework provides a structured approach to post-quantum migration. Practical implementation follows these phases:
Phase 1: Cryptographic Inventory
As required by OMB M-23-02, agencies must identify all systems using public-key cryptography. This includes not just obvious encryption tools, but also TLS termination points, VPN concentrators, code signing infrastructure, PKI systems, database encryption, and email security gateways. QNSQY's scan command can identify classical cryptographic artifacts in file systems, helping organizations discover where vulnerable algorithms are in use.
Phase 2: Risk Prioritization
Not all systems face equal quantum risk. Prioritize based on:
- Data classification level. Classified and sensitive data faces the highest harvest-now, decrypt-later risk.
- Data retention period. Systems storing data with long-term classification (10+ years) are at greater risk than systems processing transient data.
- Adversary capability. Systems processing data targeted by nation-state adversaries should migrate first.
- CNSA 2.0 deadline category. Systems in the 2025 deadline category (web, software signing) require immediate action.
Phase 3: File-Level Encryption Migration
The fastest path to protecting existing data at rest is re-encrypting it with post-quantum algorithms. QNSQY's batch encryption capability allows organizations to re-encrypt large volumes of files using ML-KEM-1024 + X25519 + AES-256-GCM without changes to existing storage infrastructure. This can be performed on air-gapped systems with no network connectivity, making it suitable for classified environments.
Phase 4: Infrastructure Migration
Migrating network infrastructure (TLS, VPN, PKI) to post-quantum algorithms is a longer-term effort that depends on vendor support and interoperability testing. In the interim, encrypting files at the application layer before transmission provides quantum-resistant protection regardless of the transport layer's algorithm support.
CNSA 2.0 requires LMS/XMSS for software and firmware signing and ML-KEM-1024 for web browsers and servers by 2025. Organizations subject to these requirements should already be in implementation, not still in the assessment phase.
Additional Algorithms for Specialized Use Cases
Beyond the core CNSA 2.0 requirements, QNSQY's Business tier provides additional post-quantum algorithms for specialized government and defense scenarios:
- HQC (Code-Based KEM): HQC-128, HQC-192, and HQC-256 provide an alternative post-quantum key encapsulation mechanism based on error-correcting codes rather than lattices. This algorithmic diversity means that if a breakthrough affects lattice-based schemes, organizations have an alternative that relies on a fundamentally different mathematical problem.
- FN-DSA (Falcon): FN-DSA-512 and FN-DSA-1024 provide compact post-quantum signatures based on the NTRU lattice problem. Smaller signature sizes compared to ML-DSA make FN-DSA suitable for bandwidth-constrained environments.
- Threshold Encryption: M-of-N encryption using Shamir secret sharing ensures that no single individual can decrypt sensitive data alone. This supports separation-of-duty requirements common in defense environments, where multiple authorized individuals must cooperate to access classified material.
The Strategic Imperative
For government and defense organizations, migrating to post-quantum cryptography is not a technology upgrade. It is a strategic imperative driven by the physics of quantum computing and the operational realities of signals intelligence. The policy framework (EO 14028, NSM-10, OMB M-23-02, CNSA 2.0) reflects the U.S. government's assessment that the quantum threat is real, imminent enough to require action now, and consequential enough to warrant mandatory compliance timelines.
Organizations that treat these deadlines as soft targets risk losing their Authorization to Operate, failing contract compliance requirements, and most critically, exposing national security information to adversary decryption once CRQCs become operational. The algorithms are standardized. The tools are available. The deadlines are published. What remains is execution.
Related Articles
- Post-Quantum Encryption for Healthcare and HIPAA
- Post-Quantum Cryptography for Financial Services
- How to Implement PQC in Your Organization
- LMS: Hash-Based Stateful Signatures Explained
CNSA 2.0 Compliant Encryption
QNSQY supports ML-KEM-1024, ML-DSA-87, LMS, and AES-256-GCM with air-gapped operation for defense environments.
Try QNSQYSources
- Commercial National Security Algorithm Suite 2.0 (CNSA 2.0) (NSA, September 2022)
- CNSA 2.0 Frequently Asked Questions (NSA, September 2022)
- Executive Order 14028: Improving the Nation's Cybersecurity (The White House, May 12, 2021)
- National Security Memorandum NSM-10 (The White House, May 4, 2022)
- OMB Memorandum M-23-02: Migrating to Post-Quantum Cryptography (OMB, November 2022)
- Post-Quantum Cryptography (CISA)
- FIPS 203: Module-Lattice-Based Key-Encapsulation Mechanism Standard (NIST, August 2024)
- FIPS 204: Module-Lattice-Based Digital Signature Standard (NIST, August 2024)
- NIST SP 800-208: Recommendation for Stateful Hash-Based Signature Schemes (NIST, October 2020)
Originally published at quantumsequrity.com/blog/pqc-government-defense.