crypto-sizes.tools

Post-quantum migration requirement lookup

Tell it what you are building and which mandate applies, and it returns the required post-quantum algorithm and the deadline. Sourced from NSA CNSA 2.0 and NIST — no vendor sign-up, no compliance funnel.

CNSA 2.0 timeline (current CNSSP-15 milestones)

Per the current NSA CNSA 2.0 FAQ (December 2024, v2.1).

MilestoneDate
New NSS acquisitions required to be CNSA 2.0-compliantJan 1, 2027
Equipment/services that cannot support CNSA 2.0 phased outDec 31, 2030
CNSA 2.0 algorithms mandated for useDec 31, 2031
All National Security Systems quantum-resistant (NSM-10)2035

The December 2024 FAQ replaced the earlier per-technology schedule (signing/networking "by 2030", OS/cloud "by 2033") with these CNSSP-15 dates. Sites still quoting 2033 are citing the superseded April-2024 FAQ; the current mandate date is Dec 31, 2031.

SLH-DSA is a NIST standard but is not in CNSA 2.0. For National Security Systems, CNSA 2.0 requires ML-KEM-1024 and ML-DSA-87 (plus LMS/XMSS for firmware signing). SLH-DSA (FIPS 205) is approved by NIST generally but is not on the CNSA 2.0 list — a common point of confusion.

Frequently asked questions

Sources. NSA CNSA 2.0 — Commercial National Security Algorithm Suite 2.0 (CSA Sept 2022) and the current CNSA 2.0 & Quantum Computing FAQ (December 2024, v2.1) for required algorithms and NSS deadlines; NIST FIPS 203/204/205 for the algorithm standards; NIST IR 8547 (initial public draft) for the general classical-deprecation framing (deprecate after 2030, disallow after 2035 — draft). Verify against the primary NSA/NIST documents before a compliance decision; the CNSA milestone dates here follow the Dec 2024 FAQ (v2.1); verify against it directly. Not legal advice. See the deprecation timeline →